使用Docker Compose部署至ECS Fargate时,如何引用S3中的.env文件?
问题:Docker Compose部署ECS Fargate时无法引用S3中的.env文件
我正尝试通过Docker Compose将应用部署至AWS ECS Fargate,希望能引用存储在S3中的.env文件。AWS官方说明该操作可行,但我的多次尝试均未成功。以下是我已尝试的配置模板:
some_service: image: ${ECR_IMAGE} container_name: ${CONTAINER_NAME} env_file: - value: arn:aws:s3:::project-bucket/.env type: s3
some_service: image: ${ECR_IMAGE} container_name: ${CONTAINER_NAME} environmentFiles: - value: arn:aws:s3:::project-bucket/.env type: s3
some_service: image: ${ECR_IMAGE} container_name: ${CONTAINER_NAME} env_file: arn:aws:s3:::project-bucket/.env
解决方案
正确的解决方法是使用x-aws-cloudformation配置,通过自定义CloudFormation资源指定环境文件并赋予任务执行角色对应S3权限,具体配置如下:
x-aws-cloudformation: Resources: AppTaskDefinition: Properties: ContainerDefinitions: - Image: ${ECR_IMAGE} Name: ${APP_NAME} environmentFiles: - value: arn:aws:s3:::project-bucket/.env type: s3 AppTaskExecutionRole: Properties: Policies: - PolicyName: S3ReadEnvAccess PolicyDocument: | { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject" ], "Resource": [ "arn:aws:s3:::project-bucket/*" ] }, { "Effect": "Allow", "Action": [ "s3:GetBucketLocation" ], "Resource": [ "arn:aws:s3:::project-bucket" ] } ] }
注意:
- 需通过
x-aws-cloudformation扩展字段直接定义ECS任务定义,在容器配置里用environmentFiles指定S3中.env文件的ARN- 必须给任务执行角色添加读取目标S3桶及对应对象的权限,否则ECS无法获取.env文件
内容的提问来源于stack exchange,提问作者John Sparks
相关产品推荐
相关产品推荐

