寻求AWS专家协助:基于CloudFormation实现ECS持久化(EFS/EBS)部署
Hey there, I feel your pain—spending a week troubleshooting deployment issues is no fun, especially when missing persistence is the roadblock. Let’s break down how to get your Docker backend set up with reliable persistent storage on AWS ECS, whether you opt for EFS (great for scalability or Fargate compatibility) or EBS (for high-performance, single-instance workloads).
First: Choose Between EFS and EBS
- EFS: Network-attached, managed storage that works with both Fargate and EC2 launch types. Perfect if you need shared storage across multiple containers/instances, or want to stick with Fargate (note: AWS does support EFS with Fargate now—you might have missed this earlier!). It’s scalable and low-overhead.
- EBS: Block storage that only works with EC2 launch type. Ideal for workloads needing low-latency, high IOPS (like databases), but tied to a single AZ and instance (unless using EBS Multi-Attach, which has limits).
Setting Up ECS + EFS via CloudFormation
Let’s walk through the critical parts of a CloudFormation template that links EFS to your ECS service:
EFS File System & Mount Targets:
You’ll need an EFS file system and mount targets in each AZ where your ECS tasks run. Here’s a snippet:MyEFSFileSystem: Type: AWS::EFS::FileSystem Properties: PerformanceMode: generalPurpose # Use maxIO for high-throughput workloads Encrypted: true EFSMountTarget: Type: AWS::EFS::MountTarget Properties: FileSystemId: !Ref MyEFSFileSystem SubnetId: !Ref YourECSSubnet SecurityGroups: [!Ref EFSSecurityGroup] # Allow NFS (port 2049) from ECS tasksEnsure your
EFSSecurityGroupallows inbound NFS traffic from your ECS task security group.ECS Task Definition:
Update your task definition to include the EFS volume and mount it into your container:TaskDefinition: Type: AWS::ECS::TaskDefinition Properties: Family: your-backend-task NetworkMode: awsvpc # Required for Fargate or EC2 with awsvpc networking ExecutionRoleArn: !Ref ECSExecutionRole TaskRoleArn: !Ref ECSTaskRole Volumes: - Name: efs-volume EFSVolumeConfiguration: FileSystemId: !Ref MyEFSFileSystem RootDirectory: /app/data/efs TransitEncryption: ENABLED ContainerDefinitions: - Name: your-backend-container Image: your-docker-image-uri MountPoints: - SourceVolume: efs-volume ContainerPath: /app/data # Where your app writes persistent data PortMappings: - ContainerPort: 8080 # Add other configs (env vars, logging, etc.) hereFor Fargate, confirm your task uses platform version 1.4.0 or higher (the first version supporting EFS).
ECS Service:
When defining your ECS service, ensure it’s associated with subnets and security groups that can reach the EFS mount targets.
If You Prefer EBS with EC2 Launch Type
For EBS-backed persistence, here’s what to add to your CloudFormation template:
EBS Volume & Instance Attachment:
Create an EBS volume and attach it to your ECS EC2 instance, or use an EC2 launch template to auto-attach EBS volumes when instances spin up. Don’t forget to format and mount the EBS volume on the instance via user data:# User data snippet for EC2 launch template mkfs.ext4 /dev/xvdh mkdir -p /mnt/ebs mount /dev/xvdh /mnt/ebs echo "/dev/xvdh /mnt/ebs ext4 defaults 0 0" >> /etc/fstabTask Definition with Host Volumes:
Volumes: - Name: ebs-volume Host: SourcePath: /mnt/ebs # Path where EBS is mounted on the EC2 instanceMount this volume into your container just like the EFS example.
Troubleshooting Tips
- Permissions: Ensure your ECS task role has permissions for EFS (use
AmazonEFSFullAccessor a custom policy withelasticfilesystem:ClientMountandelasticfilesystem:ClientWrite). - Security Groups: Double-check that port 2049 (NFS) is open between ECS tasks and EFS mount targets.
- Fargate Compatibility: If returning to Fargate, verify your task uses platform version ≥1.4.0 and EFS has transit encryption enabled.
I hope this helps you get your persistent deployment up and running smoothly. If you hit specific snags with your CloudFormation template, feel free to share snippets—I’m happy to refine them with you!
内容的提问来源于stack exchange,提问作者Mugetsu

