GitHub Action部署Lightsail容器报错:已创建服务仍提示需创建
Lightsail容器部署报错:"You must create a container service before retrieving container registry login credentials" 排查方案
问题背景
通过GitHub Action向Amazon Lightsail部署容器时,明明已创建容器服务,却收到错误提示:
You must create a container service before retrieving container registry login credentials.
怀疑与权限相关,但无法定位问题,以下是相关配置、日志及IAM权限:
相关配置片段
- name: Release to Amazon Lightsail env: CONTAINER_SERVICE_NAME: ${{ env.ENVIRONMENT }}-${{ env.SERVICE_NAME }}-cs run: | echo "Releasing to Amazon Lightsail" docker pull $ORG_NAME/$SERVICE_NAME:$GITHUB_SHA echo "Uploading docker image to $CONTAINER_SERVICE_NAME" # upload the docker image for this pipeline aws --debug lightsail push-container-image \ --service-name $CONTAINER_SERVICE_NAME \ --label ${{ env.SERVICE_NAME }}-latest \ --image $ORG_NAME/$SERVICE_NAME:$GITHUB_SHA
报错日志
Run echo "Releasing to Amazon Lightsail" Releasing to Amazon Lightsail 61388d167c4340ec7054e7e7a64bcd897e407a9d: Pulling from ***/slackbot [ lots of pulling and downloading ] Digest: sha256:0d4f0cce97751a1f4ef5dfc5731ad09c2d7762f3c307215269cffccbdb655d79 Status: Downloaded newer image for ***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d docker.io/***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d Uploading docker image to production-slackbot-cs 2023-07-14 22:10:53,018 - MainThread - awscli.clidriver - DEBUG - CLI version: aws-cli/2.13.0 Python/3.11.4 Linux/5.15.0-1041-azure exe/x86_64.ubuntu.22 2023-07-14 22:10:53,018 - MainThread - awscli.clidriver - DEBUG - Arguments entered to CLI: ['--debug', 'lightsail', 'push-container-image', '--service-name', 'production-slackbot-cs', '--label', 'slackbot-latest', '--image', '***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d'] ... InvalidInputException: You must create a container service before retrieving container registry login credentials. { RespMetadata: { StatusCode: 400, RequestID: "94ad92e5-de73-4e00-aff1-a99a8ca74b45" }, Message_: "You must create a container service before retrieving container registry login credentials." } 2023-07-14 22:10:55,355 - MainThread - awscli.clidriver - DEBUG - Exception caught in main() Traceback (most recent call last): File "awscli/clidriver.py", line 460, in main File "awscli/clidriver.py", line 595, in __call__ File "awscli/customizations/commands.py", line 205, in __call__ File "awscli/customizations/lightsail/push_container_image.py", line 65, in _run_main File "subprocess.py", line 571, in run subprocess.CalledProcessError: Command '['lightsailctl', '--plugin', '--input-stdin']' returned non-zero exit status 1. Command '['lightsailctl', '--plugin', '--input-stdin']' returned non-zero exit status 1. Error: Process completed with exit code 255.
IAM权限配置
{ "Effect": "Allow", "Action": [ "lightsail:GetContainerImages", "lightsail:GetContainerAPIMetadata", "lightsail:CreateContainerService", "lightsail:CreateContainerServiceRegistryLogin", "lightsail:GetContainerServices", "lightsail:GetContainerServiceDeployments", "lightsail:GetContainerServicePowers" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "lightsail:CreateContainerServiceDeployment", "lightsail:DeleteContainerService", "lightsail:RegisterContainerImage", "lightsail:UpdateContainerService" ], "Resource": [my ARN] },
排查与解决步骤
1. 验证容器服务的存在性与名称匹配
- 登录Lightsail控制台,确认
production-slackbot-cs容器服务确实存在,检查名称是否有拼写错误(大小写、连字符、前缀后缀是否一致) - 在本地或GitHub Action中手动执行
aws lightsail get-container-services --service-name production-slackbot-cs,确认能返回有效服务信息,排查是否是环境变量CONTAINER_SERVICE_NAME传递错误导致名称不匹配
2. 补全IAM权限
- 当前权限中缺少
lightsail:GetContainerService(单数形式),虽然已有复数的GetContainerServices,但push-container-image操作可能需要单独的单数权限,将其添加到第一个权限块的Action列表中 - 确认第二个权限块中的Resource ARN格式正确,应为
arn:aws:lightsail:<你的区域>:<AWS账号ID>:container-service/production-slackbot-cs,确保ARN指向正确的容器服务 - 临时给IAM角色添加
lightsail:*权限测试,确认是否是权限缺失导致的问题,测试通过后再按需收紧权限
3. 修复Lightsail CLI插件问题
- GitHub Action环境中的
lightsailctl插件可能版本老旧或未正确安装,在部署步骤前添加以下命令安装最新插件:curl https://s3.us-west-2.amazonaws.com/lightsailctl/latest/linux-amd64/lightsailctl -o lightsailctl chmod +x lightsailctl sudo mv lightsailctl /usr/local/bin/ - 检查AWS CLI版本,报错中使用的是2.13.0,可尝试升级到最新版本,在Action中添加:
sudo apt-get update && sudo apt-get install awscli -y
4. 指定正确的AWS区域
- Lightsail容器服务是区域级资源,若CLI默认区域与服务所在区域不匹配,会导致无法找到服务。在
aws命令中添加--region <你的区域>参数,或在环境变量中设置AWS_DEFAULT_REGION=<你的区域>
内容的提问来源于stack exchange,提问作者Mishap
相关产品推荐
相关产品推荐

