You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform挂载EFS到ECS Fargate报错:No such file or directory

问题:ECS Fargate挂载EFS卷时报“No such file or directory”容器无法启动

错误信息

Resourceinitializationerror: failed to invoke EFS utils commands to set up EFS volumes: stderr: b'mount.nfs4: mounting :/assets failed, reason given by server: No such file or directory' : unsuccessful EFS utils command execution; code: 32

已确认信息

  • 网络配置正常(移除安全组会触发网络相关错误)
  • Docker镜像已安装amazon-efs-utils工具,安装命令如下:
RUN apt-get update && \
    apt-get -y install git binutils && \
    git clone https://github.com/aws/efs-utils && \
    cd efs-utils && \
    ./build-deb.sh && \
    apt-get -y install ./build/amazon-efs-utils*deb

RUN wget https://bootstrap.pypa.io/pip/3.5/get-pip.py -O /tmp/get-pip.py  && \
    python3 /tmp/get-pip.py && \
    pip3 install botocore

核心问题原因

你创建了EFS访问点(aws_efs_access_point)来定义/assets和/shared目录,但在ECS任务定义的EFS卷配置中,直接指定root_directory = "/assets"而非使用访问点。EFS文件系统默认根目录为空,/assets和/shared目录本身并不存在——访问点的creation_info仅在通过访问点挂载时才会自动创建目标目录,直接指定路径挂载不会触发自动创建逻辑。

解决方案

修改ECS任务定义中的EFS卷配置,改用访问点挂载,移除直接指定root_directory的配置:

修改后的任务定义卷配置

resource "aws_ecs_task_definition" "backend_task_definition" {
  ...

  container_definitions = jsonencode(
    [
      {
        ...
        mountPoints = [
          {
            sourceVolume  = "assets"
            containerPath = "/app/assets"
            readOnly      = false
          },
          {
            sourceVolume  = "shared"
            containerPath = "/app/shared"
            readOnly      = false
          }
        ]
        volumesFrom = []
        ...
      }
    ]
  )

  volume {
    name = "assets"

    efs_volume_configuration {
      file_system_id     = aws_efs_file_system.persistent.id
      access_point_id    = aws_efs_access_point.assets_access_point.id
      # 移除root_directory,使用访问点定义的根目录
    }
  }

  volume {
    name = "shared"

    efs_volume_configuration {
      file_system_id     = aws_efs_file_system.persistent.id
      access_point_id    = aws_efs_access_point.shared_access_point.id
      # 移除root_directory,使用访问点定义的根目录
    }
  }
  ...
}

可选验证点

  • 确认EFS挂载目标所在的private_subnets与ECS服务使用的public_subnets路由连通(默认VPC配置通常已包含此路由)
  • 确认EFS访问点的权限配置(owner_gid、owner_uid、permissions)与容器运行用户权限匹配,避免后续读写权限问题

内容的提问来源于stack exchange,提问作者chenny

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 13:31:12