使用CloudFormation创建ECS高可用自动扩缩容组时遇到报错:Received 0 SUCCESS signal(s) out of 1. Unable to satisfy 100% MinSuccessfulInstancesPercent requirement
Hey there, let’s break down this frustrating error you’re facing when setting up your ECS high-availability Auto Scaling Group (ASG) with CloudFormation. That message means your EC2 instances aren’t sending a success signal back to CloudFormation, which is required to mark the deployment as healthy. Here are the most common fixes to get this sorted:
1. Audit Your Instance Bootstrap Script (User Data)
The first place to check is your EC2 instance’s user data—if this script fails to properly initialize the ECS agent or complete setup, the instance will never send the success signal.
- Make sure your script correctly configures and starts the ECS agent, with the right cluster name:
#!/bin/bash echo "ECS_CLUSTER=your-ecs-cluster-name" >> /etc/ecs/ecs.config systemctl enable --now ecs - SSH into one of the failed instances and check
/var/log/cloud-init-output.log—this log will show any errors in your user data script (like missing packages, typos, or failed commands).
2. Validate cfn-signal Configuration
If you’re using cfn-signal to notify CloudFormation of instance readiness, double-check these details:
- Ensure the signal command runs after all critical initialization steps (like starting the ECS agent) and uses the correct resource names:
/opt/aws/bin/cfn-signal -e $? \ --stack ${AWS::StackName} \ --resource YourAutoScalingGroupResourceName \ --region ${AWS::Region} - Confirm your instance’s IAM role has permission to call
cloudformation:SignalResource—add this to your role’s policy if it’s missing:{ "Effect": "Allow", "Action": "cloudformation:SignalResource", "Resource": "*" }
3. Adjust ASG Health Check and Success Thresholds
- If your ASG’s
MinSuccessfulInstancesPercentis set to 100% (the default), even one failing instance will block the deployment. Temporarily lower this value (e.g., to 50%) to test if instances can partially deploy, then debug the failing ones. - Verify your ASG’s health check type: If using EC2 health checks, ensure instances aren’t being marked unhealthy before they can send the signal. You might need to increase the
HealthCheckGracePeriodto give instances more time to initialize.
4. Check Instance IAM Permissions for ECS
Your EC2 instances need the right permissions to register with the ECS cluster—without this, the agent can’t connect, and the instance won’t be considered healthy:
- Attach the managed policy
AmazonEC2ContainerServiceforEC2Roleto your instance role, or define a custom policy with these permissions:{ "Effect": "Allow", "Action": [ "ecs:RegisterContainerInstance", "ecs:DeregisterContainerInstance", "ecs:DiscoverPollEndpoint" ], "Resource": "*" }
5. Verify Network Connectivity
ECS agents need to communicate with AWS’s ECS service endpoints—if your instances can’t reach these, they’ll fail to register:
- For public subnets: Ensure security groups allow outbound HTTPS (port 443) traffic to the internet.
- For private subnets: Set up a NAT Gateway or ECS VPC Endpoints to let instances access ECS services without public internet access.
- Check
/var/log/ecs/ecs-agent.logon the instance for connectivity errors like "unable to connect to ECS endpoint".
Start with checking the cloud-init and ECS agent logs—they’ll usually point you straight to the root cause. If you still hit issues, share snippets of your CloudFormation template’s ASG and user data sections, and we can dive deeper!
内容的提问来源于stack exchange,提问作者Shaik Moulali

