Service Fabric开发集群启动失败 求助技术排查
Service Fabric Local Dev Cluster Fails to Start with Permission & Service Timeout Errors
Let's break down the issues you're facing and add targeted troubleshooting steps beyond what you've already tried:
Core Symptoms You've Identified
- Running
DevClusterSetup.ps1fails whenFabricHostSvcstops and can't restart - FabricDeployer logs warn that firewall rules are disabled for the current profile
- Windows Event Viewer shows critical errors:
E_ACCESSDENIEDpermission failuresFabricHostSvcstartup timeouts- Access failures for
FabricHostSettings.xml
You've already tried validating the Windows Firewall service, reinstalling the cluster, and adjusting IP configurations—let's dive into other potential fixes:
Troubleshooting & Fixes to Try
1. Verify FabricHostSvc Service Permissions
- Open
services.msc, locate FabricHostSvc, right-click → Properties → Log On tab. Ensure it's set to use the Local System account (the default for dev clusters) and temporarily check Allow service to interact with desktop (test only, not recommended for production). - Navigate to
C:\Program Files\Microsoft Service Fabric, right-click → Properties → Security. Confirm theLocal Systemaccount has Modify or Full Control permissions for this directory and all subfolders.
2. Fix FabricHostSettings.xml Access or Integrity
- Find
FabricHostSettings.xml(typically inC:\ProgramData\Microsoft\Service Fabric). Right-click → Properties → Security and ensure theFabricHostSvcruntime account (Local System) has Read & Write access. - If the file is corrupted, back it up, delete it, then re-run
DevClusterSetup.ps1—the setup script should regenerate a fresh copy.
3. Extend FabricHostSvc Startup Timeout
- Open
regeditand navigate toHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FabricHostSvc. - If the
StartTimeoutDWORD value doesn't exist, create it. Set its value data to60000(60 seconds, double the default 30s) to give the service more time to initialize. Restart your machine and retry cluster setup.
4. Check Local Security Policy Permissions
- Open
secpol.msc, expand Local Policies → User Rights Assignment:- Confirm Log on as a service includes the
Local Systemaccount - Ensure Adjust memory quotas for a process and Bypass traverse checking are granted to the service's runtime account
- Confirm Log on as a service includes the
- Apply any changes and restart your machine before testing again.
5. Rule Out Third-Party Security Software Interference
- Third-party antivirus, firewalls, or endpoint protection tools often block Service Fabric's service startup or file access. Temporarily disable these tools, then run
DevClusterSetup.ps1to see if the cluster initializes successfully. If it works, you'll need to add exceptions for Service Fabric directories and services in your security software.
内容的提问来源于stack exchange,提问作者Mohammed Elrasheed Osman
相关产品推荐
相关产品推荐

