You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Fargate容器挂载EFS后写入数据不持久问题求助

问题:Fargate容器挂载EFS访问点后写入数据无法持久化

我有一个配置了AWS EFS访问点的Fargate容器,卷似乎已正常挂载,但写入其中的数据无法持久化。

  • 无论向驱动器写入多少数据,其总大小始终仅为6.00 KiB。
  • 我可以确认卷已正确挂载,因为修改访问点的posixUser会相应改变容器内文件夹的所有权。

因此,容器可以读取并挂载文件系统,但写入挂载卷的操作不会对EFS卷产生影响。

我已尝试切换加密设置、修改用户、变更任务和执行角色,且已获得2049和22端口的权限。过去5天我一直在查看容器日志并反复重新部署。

CDK代码示例

import * as cdk from 'aws-cdk-lib'
import * as ec2 from 'aws-cdk-lib/aws-ec2'
import * as ecs from 'aws-cdk-lib/aws-ecs'
import * as efs from 'aws-cdk-lib/aws-efs'
import * as logs from 'aws-cdk-lib/aws-logs'

export class BaseStack extends cdk.Stack {
  constructor(scope: cdk.App, id: string, environment: Record<string, string>, props?: cdk.StackProps) {
    super(scope, id, props)

    const vpc = new ec2.Vpc(this, `${id}-Vpc`, {
      natGateways: 0,
      maxAzs: 2,
      enableDnsHostnames: true,
      enableDnsSupport: true,
    })

    const securityGroup = new ec2.SecurityGroup(this, `${id}-security-group`, {
      vpc,
      allowAllOutbound: true,
    })

    const cluster = new ecs.Cluster(this, `${id}-Cluster`, {
      vpc,
    })

    const fileSystem = new efs.FileSystem(this, `${id}-FileSystem`, {
      vpc,
      encrypted: true,
      performanceMode: efs.PerformanceMode.MAX_IO,
      lifecyclePolicy: efs.LifecyclePolicy.AFTER_7_DAYS,
      removalPolicy: cdk.RemovalPolicy.RETAIN,
    })

    fileSystem.connections.addSecurityGroup(securityGroup)
    fileSystem.connections.allowInternally(ec2.Port.tcp(22))
    fileSystem.connections.allowInternally(ec2.Port.tcp(2049))

    const accessPoint = new efs.AccessPoint(this, `${id}-AccessPoint`, {
      fileSystem,
      path: '/data',
      createAcl: {
        ownerGid: '999', // Dockerfile中创建的用户
        ownerUid: '999', // Dockerfile中创建的用户
        permissions: '777',
      },
      posixUser: {
        uid: '999', // Dockerfile中创建的用户
        gid: '999', // Dockerfile中创建的用户
      },
    })

    const volumeName = 'efs-data'

    const image = ecs.ContainerImage.fromAsset('../services/whatsapp-listener', {
      file: './deployment/Dockerfile',
    })

    const taskDefinition = new ecs.TaskDefinition(this, `${id}-TaskDefinition`, {
      family: `${id}-TaskDefinition`,
      memoryMiB: `512`,
      cpu: `256`,
      compatibility: ecs.Compatibility.EC2_AND_FARGATE,
      networkMode: ecs.NetworkMode.AWS_VPC,
    })

    taskDefinition.addVolume({
      name: volumeName,
      efsVolumeConfiguration: {
        fileSystemId: fileSystem.fileSystemId,
        transitEncryption: 'ENABLED',
        authorizationConfig: {
          accessPointId: accessPoint.accessPointId,
        },
      },
    })

    const logGroup = new logs.LogGroup(this, `${id}-ContainerLogGroup`, {
      logGroupName: `${id}-LogGroup`,
      removalPolicy: cdk.RemovalPolicy.DESTROY,
      retention: logs.RetentionDays.ONE_WEEK,
    })

    const logging = new ecs.AwsLogDriver({
      logGroup,
      streamPrefix: id,
      mode: ecs.AwsLogDriverMode.NON_BLOCKING,
    })

    const container = taskDefinition.addContainer(`${id}-Container`, {
      image,
      memoryLimitMiB: 512,
      cpu: 256,
      logging,
      environment,
    })

    container.addMountPoints({
      containerPath: '/data',
      sourceVolume: volumeName,
      readOnly: false,
    })

    const service = new ecs.FargateService(this, `${id}-Service`, {
      enableExecuteCommand: true,
      taskDefinition,
      desiredCount: 1,
      cluster,
      vpcSubnets: { subnets: vpc.publicSubnets },
      securityGroups: [securityGroup],
      capacityProviderStrategies: [
        {
          capacityProvider: 'FARGATE_SPOT',
          weight: 100,
          base: 1,
        },
        {
          capacityProvider: 'FARGATE',
          weight: 1,
        },
      ],
      assignPublicIp: true,
    })
  }
}

内容的提问来源于stack exchange,提问作者zVictor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 10:17:54