无法将EC2实例端口映射至Docker容器端口(ECS部署场景)
Hey there, let's walk through your ECS task definition and the steps to confirm your PostGraphile deployment is working on your EC2 instance.
Your ECS Task Definition Breakdown
First, here's your task definition formatted for readability:
{ "containerDefinitions": [ { "name": "postgraphile-container", "image": "019384571013.dkr.ecr.us-east-2.amazonaws.com/test-repository", "memory": 500, "essential": true, "portMappings": [ { "hostPort": 5000, "containerPort": 5000, "protocol": "tcp" } ] } ], "volumes": [], "memory": "900", "cpu": "128", "placementConstraints": [], "family": "postgraphile", "taskRoleArn": "" }
Key Details to Note
- Container Setup: Your
postgraphile-containeruses an image from your us-east-2 ECR repo, with 500MB of memory allocated. The port mapping ties EC2's port 5000 directly to the container's port 5000 over TCP. Sinceessentialis set totrue, if this container crashes, the entire ECS task will terminate. - Task Resources: The task gets 900MB total memory and 128 CPU units—this should be sufficient for your PostGraphile instance, since you've only allocated 500MB to the container itself.
- Family & Permissions: The task is part of the
postgraphilefamily, and you haven't specified a task role ARN. That means it'll use the default ECS task execution role you configured (make sure that role has permissions to pull images from your ECR repo).
Verifying the Deployment on EC2
Since you're able to SSH into your EC2 instance, here are quick checks to confirm everything's running smoothly:
- Run
docker psto list active containers. You should seepostgraphile-containerlisted with the port mapping0.0.0.0:5000->5000/tcp. - Check the container logs with
docker logs postgraphile-containerto make sure PostGraphile started without errors (look for lines indicating the server is listening on port 5000). - Test the endpoint locally on the EC2 instance using
curl http://localhost:5000—you should get a response from PostGraphile (like a GraphQL introspection endpoint or welcome message).
Common Troubleshooting Tips
If something's off (e.g., container exits immediately, port isn't accessible), try these fixes:
- Security Group Check: Ensure your EC2 instance's security group allows inbound traffic on port 5000 if you need to access PostGraphile from outside the instance.
- ECR Image Validation: Double-check that your image was pushed to the correct ECR repo and that the task definition is using the right tag (if you didn't specify one, it defaults to
latest—confirm that's the image you intended). - Execution Role Permissions: Make sure the ECS task execution role has the
AmazonEC2ContainerRegistryReadOnlypolicy attached, otherwise it can't pull the image from ECR.
内容的提问来源于stack exchange,提问作者Vic
相关产品推荐
相关产品推荐

