Terraform ECS服务导入容器定义时端口映射丢失求助
ECS服务模块导入任务定义时端口映射丢失问题解决
问题场景
使用terraform-aws-modules的ECS服务子模块和任务定义子模块创建Fargate类型ECS服务:
任务定义子模块代码
module "ecs_container_tr_def" { source = "terraform-aws-modules/ecs/aws//modules/container-definition" version = "5.2.2" name = "test" cpu = 256 memory = 512 essential = true image = "1234567890.dkr.ecr.eu-west-2.amazonaws.com/test:latest" port_mappings = [ { containerPort = 5000 hostPort = 5000 protocol = "tcp" } ] }
ECS服务子模块代码
module "ecs_tr_service" { source = "terraform-aws-modules/ecs/aws//modules/service" version = "5.2.2" name = "test-serv" cluster_arn = var.ecs_cluster_arn cpu = 512 memory = 1024 launch_type = "FARGATE" network_mode = "awsvpc" desired_count = 1 enable_autoscaling = true autoscaling_min_capacity = 1 autoscaling_max_capacity = 1 container_definitions = { test = module.ecs_container_tr_def.container_definition } }
问题现象
terraform plan显示生成的任务定义中portMappings = []为空数组- 执行
terraform apply时报错:
module.ecs_tr_service.aws_ecs_service.this[0]: Creating... ╷ │ Error: creating ECS Service (terrareg-serv): InvalidParameterException: The container terrareg did not have a container port 5000 defined. │ │ with module.ecs_tr_service.aws_ecs_service.this[0], │ on .terraform/modules/ecs_tr_service/modules/service/main.tf line 30, in resource "aws_ecs_service" "this": │ 30: resource "aws_ecs_service" "this" {
- 但通过
terragrunt console查看任务定义子模块输出,container_definition中明确包含portMappings配置:
> module.ecs_container_tr_def.container_definition { "cpu" = 256 "environment" = tolist([]) "essential" = true "image" = "123456789.dkr.ecr.eu-west-2.amazonaws.com/test:latest" "interactive" = false "logConfiguration" = { "logDriver" = "awslogs" "options" = { "awslogs-group" = "/aws/ecs//test" "awslogs-region" = "eu-west-2" "awslogs-stream-prefix" = "ecs" } } "memory" = 512 "mountPoints" = tolist([]) "name" = "terrareg" "portMappings" = tolist([ { "containerPort" = 5000 "hostPort" = 5000 "protocol" = "tcp" }, ]) "privileged" = false "pseudoTerminal" = false "readonlyRootFilesystem" = false "startTimeout" = 30 "stopTimeout" = 120 "volumesFrom" = tolist([]) }
解决方案
问题根源在于Fargate模式下不允许显式设置hostPort为非0值,当任务定义子模块中指定hostPort = 5000时,ECS服务子模块在处理任务定义时会自动丢弃整个端口映射配置。
修改任务定义子模块的port_mappings配置,移除hostPort字段或将其设置为0:
修改后的任务定义代码
module "ecs_container_tr_def" { source = "terraform-aws-modules/ecs/aws//modules/container-definition" version = "5.2.2" name = "test" cpu = 256 memory = 512 essential = true image = "1234567890.dkr.ecr.eu-west-2.amazonaws.com/test:latest" port_mappings = [ { containerPort = 5000 protocol = "tcp" # Fargate模式下无需设置hostPort,或设为0 # hostPort = 0 } ] }
重新执行terraform plan即可看到portMappings已正确包含在任务定义中,terraform apply也能正常完成。
另外,若需要为服务配置负载均衡端口映射,需在ECS服务子模块中单独设置load_balancer参数,而非依赖容器的端口映射配置。
内容的提问来源于stack exchange,提问作者alexis
相关产品推荐
相关产品推荐

