You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS ECS Execute-Command连接失败,已配置相关项仍报错求解决

解决ECS Exec无法连接容器的问题

问题详情

执行ECS Exec命令:

aws ecs execute-command --cluster UltimaF --task 838d773b17954bcfbbacf343fb4fea70 --container ultima --interactive --command "/bin/sh"

收到错误:

An error occurred (InvalidParameterException) when calling the ExecuteCommand operation: The execute command failed because execute command was not enabled when the task was run or the execute command agent isn’t running. Wait and try again or run a new task with execute command enabled and try again.

已验证信息:

  • 任务处于运行状态
  • 执行aws ecs describe-tasks --cluster UltimaF --tasks 838d773b17954bcfbbacf343fb4fea70返回"enableExecuteCommand": true
  • 任务角色已附加以下权限:
    • ssmmessages:CreateControlChannel
    • ssmmessages:CreateDataChannel
    • ssmmessages:OpenControlChannel
    • ssmmessages:OpenDataChannel
  • 环境:Windows系统,AWS CLI版本2.8.2

补充检测结果

通过ECS Exec检查工具得到如下提示:

----------
  Managed Agent Status
----------
     1. STOPPED (Reason: null) for "ultima" - LastStartedAt: null
----------
  Init Process Enabled (first-run-task-definition:12)
----------
     1. Disabled - "ultima" 

尝试ecs:<集群名>_<任务ID>_<容器运行时ID>格式启动会话,收到错误:

An error occurred (TargetNotConnected) when calling the StartSession operation: ecs:UltimaF_838d773b17954bcfbbacf343fb4fea70_838d773b17954bcfbbacf343fb4fea70-2587323273 is not connected.

解决步骤

1. 启用容器的Init进程

ECS Exec代理依赖容器的Init进程启动,当前ultima容器的Init进程处于禁用状态,需修改任务定义并重新部署:

  • 进入ECS控制台,找到任务定义first-run-task-definition:12
  • 编辑容器定义,为ultima容器添加init: true配置项
  • 创建新的任务定义修订版,并用该修订版启动新任务(旧任务无法动态启用Init进程)

2. 验证新任务的代理状态

新任务启动后,执行以下命令确认代理运行状态:

aws ecs describe-tasks --cluster UltimaF --tasks <新任务ID> --query 'tasks[0].containers[0].managedAgents'

确保返回结果中lastStartedAt有有效值,status为RUNNING。

3. 重新尝试连接

确认代理正常运行后,执行原连接命令(替换为新任务ID):

aws ecs execute-command --cluster UltimaF --task <新任务ID> --container ultima --interactive --command "/bin/sh"

额外排查点(若仍失败)

  • 检查任务所在VPC是否配置了SSM端点(com.amazonaws.<区域>.ssmmessages),或通过NAT网关具备公网访问权限
  • 确认任务角色的信任策略允许ECS服务承担该角色
  • 升级AWS CLI至最新版本(当前2.8.2版本较旧,可能存在兼容性问题)

内容的提问来源于stack exchange,提问作者Anatoly Bugakov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 22:35:27