AWS ECS WordPress服务容器定义配置后公网访问技术咨询
Hey there! Let's work through getting your ECS-hosted WordPress accessible publicly. First, here's your current container definition for reference:
{ "containerDefinitions": [ { "name": "wordpress", "links": [ "mysql" ], "image": "wordpress", "essential": true, "portMappings": [ { "containerPort": 0, "hostPort": 80 } ], "memory": 250, "cpu": 10 }, { "environment": [ { "name": "MYSQL_ROOT_PASSWORD", "value": "password" } ], "name": "mysql", "image": "mysql", "cpu": 10, "memory": 250, "essential": true } ], "family": "wordpress" }
Let's break down the most common issues and fixes for public access:
1. Fix the Container Port Mapping
Your WordPress container has containerPort: 0, which makes Docker assign a random port to the container. This is tricky for public access since you can't reliably route traffic to a random port.
Update the port mapping to use WordPress's default port (80):
"portMappings": [ { "containerPort": 80, "hostPort": 80 } ]
If you're using Fargate, you can omit hostPort or set it to 0—Fargate doesn't support host network mode, so this field is ignored anyway.
2. Verify Network & Security Group Settings
For EC2 Launch Type:
- Ensure the ECS EC2 instance's security group allows inbound HTTP (port 80) or HTTPS (port 443) traffic from
0.0.0.0/0(or your specific IP for testing). - The EC2 instance needs a public IP, or your VPC must have a NAT Gateway configured if the instance is in a private subnet.
For Fargate Launch Type:
- Deploy your task to subnets that have a route to an Internet Gateway (check the subnet's route table).
- Enable "Assign public IP" in your task definition's network settings (or use a load balancer if you prefer not to assign public IPs directly).
- Make sure the task's security group allows inbound 80/443 traffic from the public internet.
3. Set Up an Application Load Balancer (Recommended for Production)
Directly assigning public IPs to ECS tasks isn't ideal for production. An ALB will handle traffic routing, scaling, and health checks:
- Create an Application Load Balancer with a listener on port 80 (and 443 if you're using HTTPS).
- Create a target group with target type set to
IP, and configure the health check path to/or/wp-admin/install.php(a reliable WordPress endpoint). - Update your ECS service to associate with this target group, mapping the WordPress container's port 80 to the ALB listener.
- Ensure the ALB's security group allows public inbound 80/443 traffic.
4. Validate WordPress-MySQL Connectivity
Sometimes a failed database connection can make WordPress unresponsive, which might feel like a public access issue:
- Confirm the MySQL container's
MYSQL_ROOT_PASSWORDmatches what WordPress expects. Since you're using container links, WordPress should be able to reach MySQL via themysqlhostname. - Test the connection by running
curl mysql:3306inside the WordPress container (useaws ecs execute-commandto access the container). - Check container logs for errors:
aws ecs logs --cluster <your-cluster-name> --task <your-task-id> --container wordpress aws ecs logs --cluster <your-cluster-name> --task <your-task-id> --container mysql
5. Check DNS & Routing
If you're using a custom domain, make sure it's pointing to your ALB's public DNS or your ECS instance/task's public IP. If you're testing with an IP, try accessing http://<public-ip> directly in your browser—if it times out, double-check your security group and port settings.
内容的提问来源于stack exchange,提问作者Anand Naik B

