AWS ECS Execute-Command连接失败,已配置相关项仍报错求解决
解决ECS Exec无法连接容器的问题
问题详情
执行ECS Exec命令:
aws ecs execute-command --cluster UltimaF --task 838d773b17954bcfbbacf343fb4fea70 --container ultima --interactive --command "/bin/sh"
收到错误:
An error occurred (InvalidParameterException) when calling the ExecuteCommand operation: The execute command failed because execute command was not enabled when the task was run or the execute command agent isn’t running. Wait and try again or run a new task with execute command enabled and try again.
已验证信息:
- 任务处于运行状态
- 执行
aws ecs describe-tasks --cluster UltimaF --tasks 838d773b17954bcfbbacf343fb4fea70返回"enableExecuteCommand": true - 任务角色已附加以下权限:
ssmmessages:CreateControlChannelssmmessages:CreateDataChannelssmmessages:OpenControlChannelssmmessages:OpenDataChannel
- 环境:Windows系统,AWS CLI版本2.8.2
补充检测结果
通过ECS Exec检查工具得到如下提示:
---------- Managed Agent Status ---------- 1. STOPPED (Reason: null) for "ultima" - LastStartedAt: null ---------- Init Process Enabled (first-run-task-definition:12) ---------- 1. Disabled - "ultima"
尝试ecs:<集群名>_<任务ID>_<容器运行时ID>格式启动会话,收到错误:
An error occurred (TargetNotConnected) when calling the StartSession operation: ecs:UltimaF_838d773b17954bcfbbacf343fb4fea70_838d773b17954bcfbbacf343fb4fea70-2587323273 is not connected.
解决步骤
1. 启用容器的Init进程
ECS Exec代理依赖容器的Init进程启动,当前ultima容器的Init进程处于禁用状态,需修改任务定义并重新部署:
- 进入ECS控制台,找到任务定义
first-run-task-definition:12 - 编辑容器定义,为
ultima容器添加init: true配置项 - 创建新的任务定义修订版,并用该修订版启动新任务(旧任务无法动态启用Init进程)
2. 验证新任务的代理状态
新任务启动后,执行以下命令确认代理运行状态:
aws ecs describe-tasks --cluster UltimaF --tasks <新任务ID> --query 'tasks[0].containers[0].managedAgents'
确保返回结果中lastStartedAt有有效值,status为RUNNING。
3. 重新尝试连接
确认代理正常运行后,执行原连接命令(替换为新任务ID):
aws ecs execute-command --cluster UltimaF --task <新任务ID> --container ultima --interactive --command "/bin/sh"
额外排查点(若仍失败)
- 检查任务所在VPC是否配置了SSM端点(
com.amazonaws.<区域>.ssmmessages),或通过NAT网关具备公网访问权限 - 确认任务角色的信任策略允许ECS服务承担该角色
- 升级AWS CLI至最新版本(当前2.8.2版本较旧,可能存在兼容性问题)
内容的提问来源于stack exchange,提问作者Anatoly Bugakov
相关产品推荐
相关产品推荐

