Swarm模式下容器启动失败、8080端口无法连接的排查咨询
Since you confirmed the container works with docker run, the issue is almost certainly tied to Swarm's networking setup or AWS-specific configurations. Let’s walk through step-by-step checks to narrow down the problem:
1. Validate Your Swarm Service Port Configuration
First, make sure your service is actually publishing port 8080 correctly. Run these commands:
- List active services to confirm your service is running:
docker service ls - Inspect the service’s port mapping details:
You should see an entry likedocker service inspect <your-service-name> --format '{{.Endpoint.Spec.Ports}}'[{8080 tcp 0.0.0.0:8080 8080}]—this means Swarm is forwarding host port 8080 to your container’s target port. If the published port is missing or mapped incorrectly, recreate the service with the proper--publish 8080:<container-port>flag.
2. Check if Port 8080 is Listening on the Swarm Node
Even with correct service config, the Swarm ingress proxy might not be binding to the port. SSH into the node where your service task is running (use docker service ps <your-service-name> to find the node), then run:
ss -tulpn | grep 8080
You should see a docker-proxy process listening on 0.0.0.0:8080. If nothing appears, check for port conflicts with lsof -i :8080 to identify another process using the port.
3. Verify AWS Security Group Rules
This is the most common gotcha on AWS. Double-check:
- The security group attached to your Swarm EC2 nodes allows inbound traffic on port 8080 from your source IP (use
0.0.0.0/0temporarily for testing, then restrict it later). - If using an AWS Load Balancer with Swarm, ensure the LB’s security group allows inbound 8080 traffic, and the target group forwards traffic to port 8080 on your nodes.
- Confirm your Swarm nodes have public IPs (if accessing directly from outside AWS) or that VPC routing is set up correctly for internal access.
4. Check Swarm Ingress Network Health
Swarm uses the ingress overlay network for published ports. Verify it’s functioning properly:
docker network inspect ingress
Look for errors in the output, and ensure all Swarm nodes are listed under Containers (each node should have an ingress proxy container). If the network is corrupted, reset it (note: this will temporarily disrupt published ports):
# Run on all nodes except the manager docker swarm leave --force # Reinitialize the manager node docker swarm init # Rebuild the ingress network docker network rm ingress docker network create --driver overlay ingress
5. Inspect Service Task Logs and Placement
Even if the container works with docker run, there might be issues in Swarm mode:
- Check where your service tasks are running:
docker service ps <your-service-name> - Pull logs for a task to confirm the app inside the container is starting correctly:
Look for errors like "address already in use" inside the container, or the app listening ondocker logs <task-id>127.0.0.1instead of0.0.0.0(which blocks external access even in Swarm).
6. Test Connectivity Internally
To rule out external network issues, test from within the Swarm cluster:
- On the node running the task, curl localhost:8080:
curl localhost:8080 - From another Swarm node, curl the target node’s private IP on 8080:
curl <node-private-ip>:8080
If internal access works but external doesn’t, the problem is definitely with AWS security groups or public IP routing.
内容的提问来源于stack exchange,提问作者shantanuo

