使用Fargate配置GitLab Runner时任务出现连接拒绝错误求助
GitLab Runner on Fargate: SSH Connection Refused Error
我在使用Fargate配置GitLab Runner时,作业执行失败,核心错误为SSH连接容器22端口被拒绝。完整错误日志如下:
Running with gitlab-runner 15.10.0 (456e3482) on fargate-test PgRZ6fgw, system ID: s_c1c033e2a2fd Resolving secrets 00:00 Preparing the "custom" executor INFO[2023-03-26T12:58:08Z] Starting fargate PID=9267 version="0.2.0 (933d940)" INFO[2023-03-26T12:58:08Z] Executing the command PID=9267 command=config_exec Using Custom executor with driver fargate 0.2.0 (933d940)... INFO[2023-03-26T12:58:08Z] Starting fargate PID=9272 version="0.2.0 (933d940)" INFO[2023-03-26T12:58:08Z] Executing the command PID=9272 command=prepare_exec INFO[2023-03-26T12:58:14Z] Starting new Fargate task PID=9272 command=prepare_exec INFO[2023-03-26T12:58:15Z] Persisting data that will be used by other commands PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6" INFO[2023-03-26T12:58:15Z] Waiting Fargate task to be ready PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6" INFO[2023-03-26T12:59:27Z] Persisting data that will be used by other commands PID=9272 command=prepare_exec taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6" Preparing environment 00:00 INFO[2023-03-26T12:59:27Z] Starting fargate PID=9288 version="0.2.0 (933d940)" INFO[2023-03-26T12:59:27Z] Executing the command PID=9288 command=run_exec stage=prepare_script INFO[2023-03-26T12:59:27Z] Reading file content PID=9288 command=run_exec file=/tmp/custom-executor3231873110/script3500602707/script. stage=prepare_script INFO[2023-03-26T12:59:27Z] Fetching task data from metadata storage PID=9288 command=run_exec stage=prepare_script INFO[2023-03-26T12:59:27Z] Executing script in the task container PID=9288 command=run_exec stage=prepare_script taskARN="arn:aws:ecs:us-east-1:028824297233:task/test-cluster/7cc6d38e062d4dadb955b2ac642ee2e6" ERRO[2023-03-26T12:59:27Z] Application execution failed PID=9288 error="executing the script on the remote host: executing script on container with IP \"10.251.80.122\": connecting to server: connecting to server \"10.251.80.122:22\" as user \"root\": dial tcp 10.251.80.122:22: connect: connection refused" ERROR: Job failed (system failure): prepare environment: exit status 2. Check https://docs.gitlab.com/runner/shells/index.html#shell-profile-loading for more information
解决思路
检查容器镜像是否包含SSH服务
GitLab Runner的Fargate驱动依赖SSH连接容器执行脚本,确保你的自定义镜像中已安装openssh-server(例如Debian/Ubuntu用apt install openssh-server,RHEL/CentOS用yum install openssh-server)。确认SSH服务在容器内正常启动
手动启动同镜像的Fargate任务,通过ECS Exec进入容器,执行ps aux | grep sshd检查服务是否运行。若未启动,需在Dockerfile中添加启动配置:- Debian/Ubuntu:
RUN systemctl enable sshd && service ssh start(或在entrypoint脚本中启动) - 轻量镜像(如Alpine)需额外生成主机密钥:
ssh-keygen -A
- Debian/Ubuntu:
验证网络与安全组配置
- 确保GitLab Runner所在资源与作业任务在同一VPC内,或通过VPC peering连通。
- 作业任务的安全组需开放22端口的入站流量,允许Runner所在的安全组/IP段访问。
检查GitLab Runner Fargate驱动配置
- 确认
config.toml中ssh_user参数正确,若镜像不允许root SSH,需改为有权限的用户。 - 配置正确的SSH密钥:确保Runner拥有容器的SSH私钥,且容器的
~/.ssh/authorized_keys已添加对应公钥,优先使用密钥登录而非密码。
- 确认
调整容器SSH配置
修改容器内/etc/ssh/sshd_config:- 设置
PermitRootLogin yes(或without-password若用密钥) - 开启
PasswordAuthentication yes(仅测试环境使用,生产环境不推荐) - 确保
ListenAddress 0.0.0.0,允许所有IP访问SSH服务
- 设置
内容的提问来源于stack exchange,提问作者methz
相关产品推荐
相关产品推荐

