You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS CodeBuild推送Docker镜像至ECR失败,请求排查

问题:AWS CodeBuild推送Docker镜像到ECR失败,exit status 1

我正尝试通过AWS CodeBuild的buildspec文件构建一条流水线,用于构建多容器微服务的Docker镜像并推送至ECR。已开启CodeBuild的特权模式,流水线能够完成AWS登录、镜像构建与打标签操作,但在执行docker push命令时失败,报错信息如下:

[Container] 2023/02/21 17:45:38 Command did not exit successfully docker push $REPOSITORY_URL/service1:$TAG exit status 1
[Container] 2023/02/21 17:45:38 Phase complete: POST_BUILD State: FAILED
[Container] 2023/02/21 17:45:38 Phase context status code: COMMAND_EXECUTION_ERROR Message: Error while executing command: docker push $REPOSITORY_URL/service1:$TAG. Reason: exit status 1

我的docker-compose.yaml文件内容如下:

version: '3.4'

services:
  service1:
    image: service1
    build:
      context: .
      dockerfile: Service1.API/Dockerfile

  service2:
    image: service2
    build:
      context: .
      dockerfile: service2.API/Dockerfile

我的buildspec文件内容如下:

version: 0.2

phases:
  install:
    runtime-versions:
      docker: latest
  pre_build:
    commands:
      # 镜像标签包含日期、时间和CodeCommit版本前缀
      - TAG="$(date +%Y-%m-%d.%H.%M.%S).$(echo $CODEBUILD_RESOLVED_SOURCE_VERSION | head -c 8)"
      # 检查AWS CLI版本        
      - echo "Checking AWS CLI Version..."
      - aws --version
      # 登录ECR镜像仓库 
      - echo "Logging in to Amazon ECR..."
      - $(aws ecr get-login --no-include-email --region us-east-1)
  build:
    commands:
      - echo "Docker build started on `date`"
      - echo "Building the Docker images..."
      - docker-compose -f docker-compose.yml build
      - echo Tagging the Docker images...
      - docker tag service1:latest $REPOSITORY_URL/service1:$TAG
      - docker tag service2:latest $REPOSITORY_URL/service2:$TAG
  post_build:
    commands:
      # 推送镜像到ECR仓库
      - echo "Docker build completed on `date`"
      - echo "Pushing the Docker images to Amazon ECR..."
      - docker push $REPOSITORY_URL/service1:$TAG
      - docker push $REPOSITORY_URL/service2:$TAG
      - echo "Docker Push to ECR Repository Completed -  $REPOSITORY_URL:$TAG"          
      # 生成后续流水线可用的构件文件
      - echo "Writing the image details to a file..."
      - echo {"service1":"$REPOSITORY_URL/service1:$TAG","service2":"$REPOSITORY_URL/service2:$TAG"} > build.json
artifacts:
  files:
    - build.json
    - manifests/*

我已为CodeBuild服务角色附加了必要的权限策略,策略内容如下:

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Action": [
                "ecr:BatchCheckLayerAvailability",
                "ecr:BatchGetImage",
                "ecr:CompleteLayerUpload",
                "ecr:GetDownloadUrlForLayer",
                "ecr:InitiateLayerUpload",
                "ecr:PutImage",
                "ecr:UploadLayerPart",
                "ecr:SetRepositoryPolicy",
                "ecr:DescribeImages",
                "ecr:DescribeRepositories",
                "ecr:ListImages",
                "ecr:DeleteRepositoryPolicy",
                "ecr:GetRepositoryPolicy",
                "ecr:GetAuthorizationToken"
            ],
            "Effect": "Allow",
            "Resource": "arn:aws:ecr:us-east-1:<ACCOUNT_ID>:repository/dev-repo"
        },
        {
            "Action": [
                "ecr:GetAuthorizationToken"
            ],
            "Effect": "Allow",
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "ecr-public:GetAuthorizationToken",
                "sts:GetServiceBearerToken"
            ],
            "Resource": "*"
        }
    ]
}

日志错误信息不够明确,无法定位问题根源。我参考过相关问题的解决方案并调整了策略,但问题仍未解决。

内容的提问来源于stack exchange,提问作者benyusouf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 15:06:26