You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Action部署Lightsail容器报错:已创建服务仍提示需创建

Lightsail容器部署报错:"You must create a container service before retrieving container registry login credentials" 排查方案

问题背景

通过GitHub Action向Amazon Lightsail部署容器时,明明已创建容器服务,却收到错误提示:

You must create a container service before retrieving container registry login credentials.

怀疑与权限相关,但无法定位问题,以下是相关配置、日志及IAM权限:

相关配置片段

- name: Release to Amazon Lightsail
        env:
          CONTAINER_SERVICE_NAME: ${{ env.ENVIRONMENT }}-${{ env.SERVICE_NAME }}-cs
        run: |
          echo "Releasing to Amazon Lightsail"

          docker pull $ORG_NAME/$SERVICE_NAME:$GITHUB_SHA

          echo "Uploading docker image to $CONTAINER_SERVICE_NAME"

          # upload the docker image for this pipeline
          aws --debug lightsail push-container-image \
            --service-name $CONTAINER_SERVICE_NAME  \
            --label ${{ env.SERVICE_NAME }}-latest  \
            --image $ORG_NAME/$SERVICE_NAME:$GITHUB_SHA

报错日志

Run echo "Releasing to Amazon Lightsail"
Releasing to Amazon Lightsail
61388d167c4340ec7054e7e7a64bcd897e407a9d: Pulling from ***/slackbot
[ lots of pulling and downloading ]
Digest: sha256:0d4f0cce97751a1f4ef5dfc5731ad09c2d7762f3c307215269cffccbdb655d79
Status: Downloaded newer image for ***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d
docker.io/***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d
Uploading docker image to production-slackbot-cs
2023-07-14 22:10:53,018 - MainThread - awscli.clidriver - DEBUG - CLI version: aws-cli/2.13.0 Python/3.11.4 Linux/5.15.0-1041-azure exe/x86_64.ubuntu.22
2023-07-14 22:10:53,018 - MainThread - awscli.clidriver - DEBUG - Arguments entered to CLI: ['--debug', 'lightsail', 'push-container-image', '--service-name', 'production-slackbot-cs', '--label', 'slackbot-latest', '--image', '***/slackbot:61388d167c4340ec7054e7e7a64bcd897e407a9d']
...
InvalidInputException: You must create a container service before retrieving container registry login credentials.
{
  RespMetadata: {
    StatusCode: 400,
    RequestID: "94ad92e5-de73-4e00-aff1-a99a8ca74b45"
  },
  Message_: "You must create a container service before retrieving container registry login credentials."
}
2023-07-14 22:10:55,355 - MainThread - awscli.clidriver - DEBUG - Exception caught in main()
Traceback (most recent call last):
  File "awscli/clidriver.py", line 460, in main
  File "awscli/clidriver.py", line 595, in __call__
  File "awscli/customizations/commands.py", line 205, in __call__
  File "awscli/customizations/lightsail/push_container_image.py", line 65, in _run_main
  File "subprocess.py", line 571, in run
subprocess.CalledProcessError: Command '['lightsailctl', '--plugin', '--input-stdin']' returned non-zero exit status 1.

Command '['lightsailctl', '--plugin', '--input-stdin']' returned non-zero exit status 1.
Error: Process completed with exit code 255.

IAM权限配置

{
            "Effect": "Allow",
            "Action": [
                "lightsail:GetContainerImages",
                "lightsail:GetContainerAPIMetadata",
                "lightsail:CreateContainerService",
                "lightsail:CreateContainerServiceRegistryLogin",
                "lightsail:GetContainerServices",
                "lightsail:GetContainerServiceDeployments",
                "lightsail:GetContainerServicePowers"
            ],
            "Resource": "*"
        },
{
            "Effect": "Allow",
            "Action": [
                "lightsail:CreateContainerServiceDeployment",
                "lightsail:DeleteContainerService",
                "lightsail:RegisterContainerImage",
                "lightsail:UpdateContainerService"
            ],
            "Resource": [my ARN]
        },

排查与解决步骤

1. 验证容器服务的存在性与名称匹配

  • 登录Lightsail控制台,确认production-slackbot-cs容器服务确实存在,检查名称是否有拼写错误(大小写、连字符、前缀后缀是否一致)
  • 在本地或GitHub Action中手动执行aws lightsail get-container-services --service-name production-slackbot-cs,确认能返回有效服务信息,排查是否是环境变量CONTAINER_SERVICE_NAME传递错误导致名称不匹配

2. 补全IAM权限

  • 当前权限中缺少lightsail:GetContainerService(单数形式),虽然已有复数的GetContainerServices,但push-container-image操作可能需要单独的单数权限,将其添加到第一个权限块的Action列表中
  • 确认第二个权限块中的Resource ARN格式正确,应为arn:aws:lightsail:<你的区域>:<AWS账号ID>:container-service/production-slackbot-cs,确保ARN指向正确的容器服务
  • 临时给IAM角色添加lightsail:*权限测试,确认是否是权限缺失导致的问题,测试通过后再按需收紧权限

3. 修复Lightsail CLI插件问题

  • GitHub Action环境中的lightsailctl插件可能版本老旧或未正确安装,在部署步骤前添加以下命令安装最新插件:
    curl https://s3.us-west-2.amazonaws.com/lightsailctl/latest/linux-amd64/lightsailctl -o lightsailctl
    chmod +x lightsailctl
    sudo mv lightsailctl /usr/local/bin/
    
  • 检查AWS CLI版本,报错中使用的是2.13.0,可尝试升级到最新版本,在Action中添加:
    sudo apt-get update && sudo apt-get install awscli -y
    

4. 指定正确的AWS区域

  • Lightsail容器服务是区域级资源,若CLI默认区域与服务所在区域不匹配,会导致无法找到服务。在aws命令中添加--region <你的区域>参数,或在环境变量中设置AWS_DEFAULT_REGION=<你的区域>

内容的提问来源于stack exchange,提问作者Mishap

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 01:57:03