多容器应用部署至ElasticBeanstalk失败求助
Let’s break down the most likely issues and actionable fixes for your deployment failure—since your ECR images are pushing successfully, the problem is almost certainly in how Elastic Beanstalk interacts with those images or your deployment artifacts.
1. Unresolved Variables in Dockerrun.aws.json
The biggest red flag here is that your Dockerrun.aws.json uses placeholder variables like ${AWS_ACCOUNT_ID} and ${APPLICATION_NAME}. Elastic Beanstalk does not automatically parse or replace these variables—it will try to pull an image literally named ${AWS_ACCOUNT_ID}.dkr.ecr.${AWS_REGION}.amazonaws.com/${APPLICATION_NAME}-client:latest, which doesn’t exist in your ECR registry.
Fix: Replace Variables in CodeBuild
Add commands to your buildspec.yml’s post_build phase to substitute these placeholders with actual values from your CodeBuild environment variables:
post_build: commands: - echo Build completed on `date` - echo Pushing the Docker image.... - aws ecr get-login-password --region $AWS_DEFAULT_REGION | docker login --username AWS --password-stdin $AWS_ACCOUNT_ID.dkr.ecr.$AWS_DEFAULT_REGION.amazonaws.com - docker-compose --file=docker-compose-prod.yml push # Add these variable replacement commands - sed -i "s/\${AWS_ACCOUNT_ID}/$AWS_ACCOUNT_ID/g" Dockerrun.aws.json - sed -i "s/\${AWS_REGION}/$AWS_DEFAULT_REGION/g" Dockerrun.aws.json - sed -i "s/\${APPLICATION_NAME}/$APPLICATION_NAME/g" Dockerrun.aws.json
Note: If you’re using a macOS-based CodeBuild image, use sed -i '' instead of sed -i (the empty string bypasses the backup file requirement).
2. Mismatched Image Tags/Repositories
Double-check that your docker-compose-prod.yml defines images with the exact same ECR paths and tags as what’s in your Dockerrun.aws.json. For example, your client service should look like this:
services: client: build: ./client image: ${AWS_ACCOUNT_ID}.dkr.ecr.${AWS_DEFAULT_REGION}.amazonaws.com/${APPLICATION_NAME}-client:latest # Other service config...
If the image names don’t match between your compose file and Dockerrun, Beanstalk won’t find the correct images in ECR.
3. Missing ECR Permissions for Elastic Beanstalk Instances
Your Elastic Beanstalk EC2 instances need explicit permission to pull images from ECR. By default, the aws-elasticbeanstalk-ec2-role (the IAM role attached to your Beanstalk instances) may not have this access.
Fix: Update the Instance Role
- Go to the IAM Console and locate the
aws-elasticbeanstalk-ec2-role(or your custom instance role). - Attach the managed policy
AmazonEC2ContainerRegistryReadOnlyto the role. - For more restrictive access, create a custom policy that allows
ecr:GetDownloadUrlForLayer,ecr:BatchGetImage, andecr:BatchCheckLayerAvailabilityfor your specific ECR repositories.
4. Verify Elastic Beanstalk Platform Configuration
Ensure your Beanstalk environment is using the Multi-container Docker platform (not the single-container Docker platform). You can confirm this in the Beanstalk console under Environment > Configuration > Platform.
5. Check Deployment Logs for Exact Errors
To get to the root cause quickly, review detailed logs:
- In the CodeDeploy console, check the deployment failure details for specific error messages.
- In the Elastic Beanstalk console, go to Environment > Logs > Request Logs > Full Logs. Download and search for keywords like "pull image failed", "unauthorized", or "container exit" to pinpoint the issue.
内容的提问来源于stack exchange,提问作者Krishna Nandakumar

