You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Fargate配置GitLab Runner时任务出现连接拒绝错误求助

GitLab Runner on Fargate: SSH Connection Refused Error

我在使用Fargate配置GitLab Runner时,作业执行失败,核心错误为SSH连接容器22端口被拒绝。完整错误日志如下:

Running with gitlab-runner 15.10.0 (456e3482)
on fargate-test PgRZ6fgw, system ID: s_c1c033e2a2fd
Resolving secrets
00:00
Preparing the "custom" executor
INFO[2023-03-26T12:58:08Z] Starting fargate                              PID=9267 version="0.2.0 (933d940)"
INFO[2023-03-26T12:58:08Z] Executing the command                         PID=9267 command=config_exec
Using Custom executor with driver fargate 0.2.0 (933d940)...
INFO[2023-03-26T12:58:08Z] Starting fargate                              PID=9272 version="0.2.0 (933d940)"
INFO[2023-03-26T12:58:08Z] Executing the command                         PID=9272 command=prepare_exec
INFO[2023-03-26T12:58:14Z] Starting new Fargate task                     PID=9272 command=prepare_exec
INFO[2023-03-26T12:58:15Z] Persisting data that will be used by other commands  PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6"
INFO[2023-03-26T12:58:15Z] Waiting Fargate task to be ready              PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6"
INFO[2023-03-26T12:59:27Z] Persisting data that will be used by other commands  PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6"
Preparing environment
00:00
INFO[2023-03-26T12:59:27Z] Starting fargate                              PID=9288 version="0.2.0 (933d940)"
INFO[2023-03-26T12:59:27Z] Executing the command                         PID=9288 command=run_exec stage=prepare_script
INFO[2023-03-26T12:59:27Z] Reading file content                          PID=9288 command=run_exec file=/tmp/custom-executor3231873110/script3500602707/script. stage=prepare_script
INFO[2023-03-26T12:59:27Z] Fetching task data from metadata storage      PID=9288 command=run_exec stage=prepare_script
INFO[2023-03-26T12:59:27Z] Executing script in the task container        PID=9288 command=run_exec stage=prepare_script taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6"
ERRO[2023-03-26T12:59:27Z] Application execution failed                  PID=9288 error="executing the script on the remote host: executing script on container with IP \"10.251.80.122\": connecting to server: connecting to server \"10.251.80.122:22\" as user \"root\": dial tcp 10.251.80.122:22: connect: connection refused"
ERROR: Job failed (system failure): prepare environment: exit status 2. Check https://docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information

解决思路

  • 检查容器镜像是否包含SSH服务
    GitLab Runner的Fargate驱动依赖SSH连接容器执行脚本,确保你的自定义镜像中已安装openssh-server(例如Debian/Ubuntu用apt install openssh-server,RHEL/CentOS用yum install openssh-server)。

  • 确认SSH服务在容器内正常启动
    手动启动同镜像的Fargate任务,通过ECS Exec进入容器,执行ps aux | grep sshd检查服务是否运行。若未启动,需在Dockerfile中添加启动配置:

    • Debian/Ubuntu:RUN systemctl enable sshd && service ssh start(或在entrypoint脚本中启动)
    • 轻量镜像(如Alpine)需额外生成主机密钥:ssh-keygen -A
  • 验证网络与安全组配置

    • 确保GitLab Runner所在资源与作业任务在同一VPC内,或通过VPC peering连通。
    • 作业任务的安全组需开放22端口的入站流量,允许Runner所在的安全组/IP段访问。
  • 检查GitLab Runner Fargate驱动配置

    • 确认config.toml中ssh_user参数正确,若镜像不允许root SSH,需改为有权限的用户。
    • 配置正确的SSH密钥:确保Runner拥有容器的SSH私钥,且容器的~/.ssh/authorized_keys已添加对应公钥,优先使用密钥登录而非密码。
  • 调整容器SSH配置
    修改容器内/etc/ssh/sshd_config:

    • 设置PermitRootLogin yes(或without-password若用密钥)
    • 开启PasswordAuthentication yes(仅测试环境使用,生产环境不推荐)
    • 确保ListenAddress 0.0.0.0,允许所有IP访问SSH服务

内容的提问来源于stack exchange,提问作者methz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 19:25:00