Elastic Beanstalk单容器Docker应用CloudWatch日志仅部署时更新问题
Let's break down why your logs aren't streaming automatically and fix this step by step. I've dealt with similar issues on EB Docker environments, so here's what to check:
First, Validate the Basics
Before diving into configs, confirm these foundational points:
- Check if your app is actually writing logs: SSH into your EC2 instance and run
tail -f /var/log/eb-docker/containers/eb-current-app/stdouterr.log. If you don't see new logs here as your app runs, the problem is with your .NET Core app's logging setup (not CloudWatch streaming). Ensure your app is configured to write to the console (Docker captures console output to this file by default). - Verify awslogs agent status: On the EC2 instance, run
service awslogs statusto make sure the agent is running. If it's stopped, start it withservice awslogs startand check its logs for errors:tail -f /var/log/awslogs.log. This log will tell you exactly why logs aren't being pushed (e.g., missing files, permission issues).
Fix the awslogs Configuration
Your earlier config had a mismatch in the log file path—EB's single-container Docker environment stores app logs at /var/log/eb-docker/containers/eb-current-app/stdouterr.log, not /var/log/containers/*-stdouterr.log. Use this corrected .ebextensions/logs.config:
option_settings: - namespace: aws:elasticbeanstalk:cloudwatch:logs option_name: StreamLogs value: true - namespace: aws:elasticbeanstalk:cloudwatch:logs option_name: DeleteOnTerminate value: false - namespace: aws:elasticbeanstalk:cloudwatch:logs option_name: RetentionInDays value: 14 files: "/etc/awslogs/config/eb-docker-app.conf": mode: "000644" owner: root group: root content: | [/var/log/eb-docker/containers/eb-current-app/stdouterr.log] log_group_name=/aws/elasticbeanstalk/`{ "Ref" : "AWSEBEnvironmentName" }`/var/log/eb-docker/containers/eb-current-app/stdouterr.log log_stream_name={instance_id} file=/var/log/eb-docker/containers/eb-current-app/stdouterr.log datetime_format=%Y-%m-%d %H:%M:%S initial_position=start_of_file commands: "01_restart_awslogs": command: "service awslogs restart || true" "02_verify_awslogs": command: "service awslogs status"
Key improvements here:
- Matches the exact log file path used by EB's single-container setup
- Adds
datetime_formatto help the awslogs agent correctly parse log timestamps (prevents duplicate/missed entries) - Sets
initial_position=start_of_fileto ensure existing logs are pushed, not just new ones created after the agent starts
Check IAM Permissions
Your EC2 instance's role (usually named aws-elasticbeanstalk-ec2-role) needs permissions to push logs to CloudWatch. Ensure it has at least these permissions:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents", "logs:DescribeLogStreams" ], "Resource": "arn:aws:logs:*:*:*" } ] }
You can attach this as a custom policy to the role via the IAM console if it's missing.
Debug with awslogs Logs
If logs still aren't streaming, check the awslogs agent's own log file for critical clues:
tail -f /var/log/awslogs.log- Look for errors like
No file found matching(path is wrong) AccessDenied(IAM permissions missing)Invalid sequence token(rare, but means a conflict in log stream writes)
- Look for errors like
After making these changes, redeploy your app to apply the config, then monitor the CloudWatch log stream again. It should start updating within a minute or two as new logs are generated.
内容的提问来源于stack exchange,提问作者user826988

