You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻求AWS专家协助:基于CloudFormation实现ECS持久化(EFS/EBS)部署

ECS + EFS/EBS Persistence for Your Docker Backend: Step-by-Step Guidance

Hey there, I feel your pain—spending a week troubleshooting deployment issues is no fun, especially when missing persistence is the roadblock. Let’s break down how to get your Docker backend set up with reliable persistent storage on AWS ECS, whether you opt for EFS (great for scalability or Fargate compatibility) or EBS (for high-performance, single-instance workloads).

First: Choose Between EFS and EBS

  • EFS: Network-attached, managed storage that works with both Fargate and EC2 launch types. Perfect if you need shared storage across multiple containers/instances, or want to stick with Fargate (note: AWS does support EFS with Fargate now—you might have missed this earlier!). It’s scalable and low-overhead.
  • EBS: Block storage that only works with EC2 launch type. Ideal for workloads needing low-latency, high IOPS (like databases), but tied to a single AZ and instance (unless using EBS Multi-Attach, which has limits).

Setting Up ECS + EFS via CloudFormation

Let’s walk through the critical parts of a CloudFormation template that links EFS to your ECS service:

  1. EFS File System & Mount Targets:
    You’ll need an EFS file system and mount targets in each AZ where your ECS tasks run. Here’s a snippet:

    MyEFSFileSystem:
      Type: AWS::EFS::FileSystem
      Properties:
        PerformanceMode: generalPurpose # Use maxIO for high-throughput workloads
        Encrypted: true
    
    EFSMountTarget:
      Type: AWS::EFS::MountTarget
      Properties:
        FileSystemId: !Ref MyEFSFileSystem
        SubnetId: !Ref YourECSSubnet
        SecurityGroups: [!Ref EFSSecurityGroup] # Allow NFS (port 2049) from ECS tasks
    

    Ensure your EFSSecurityGroup allows inbound NFS traffic from your ECS task security group.

  2. ECS Task Definition:
    Update your task definition to include the EFS volume and mount it into your container:

    TaskDefinition:
      Type: AWS::ECS::TaskDefinition
      Properties:
        Family: your-backend-task
        NetworkMode: awsvpc # Required for Fargate or EC2 with awsvpc networking
        ExecutionRoleArn: !Ref ECSExecutionRole
        TaskRoleArn: !Ref ECSTaskRole
        Volumes:
          - Name: efs-volume
            EFSVolumeConfiguration:
              FileSystemId: !Ref MyEFSFileSystem
              RootDirectory: /app/data/efs
              TransitEncryption: ENABLED
        ContainerDefinitions:
          - Name: your-backend-container
            Image: your-docker-image-uri
            MountPoints:
              - SourceVolume: efs-volume
                ContainerPath: /app/data # Where your app writes persistent data
            PortMappings:
              - ContainerPort: 8080
            # Add other configs (env vars, logging, etc.) here
    

    For Fargate, confirm your task uses platform version 1.4.0 or higher (the first version supporting EFS).

  3. ECS Service:
    When defining your ECS service, ensure it’s associated with subnets and security groups that can reach the EFS mount targets.

If You Prefer EBS with EC2 Launch Type

For EBS-backed persistence, here’s what to add to your CloudFormation template:

  1. EBS Volume & Instance Attachment:
    Create an EBS volume and attach it to your ECS EC2 instance, or use an EC2 launch template to auto-attach EBS volumes when instances spin up. Don’t forget to format and mount the EBS volume on the instance via user data:

    # User data snippet for EC2 launch template
    mkfs.ext4 /dev/xvdh
    mkdir -p /mnt/ebs
    mount /dev/xvdh /mnt/ebs
    echo "/dev/xvdh /mnt/ebs ext4 defaults 0 0" >> /etc/fstab
    
  2. Task Definition with Host Volumes:

    Volumes:
      - Name: ebs-volume
        Host:
          SourcePath: /mnt/ebs # Path where EBS is mounted on the EC2 instance
    

    Mount this volume into your container just like the EFS example.

Troubleshooting Tips

  • Permissions: Ensure your ECS task role has permissions for EFS (use AmazonEFSFullAccess or a custom policy with elasticfilesystem:ClientMount and elasticfilesystem:ClientWrite).
  • Security Groups: Double-check that port 2049 (NFS) is open between ECS tasks and EFS mount targets.
  • Fargate Compatibility: If returning to Fargate, verify your task uses platform version ≥1.4.0 and EFS has transit encryption enabled.

I hope this helps you get your persistent deployment up and running smoothly. If you hit specific snags with your CloudFormation template, feel free to share snippets—I’m happy to refine them with you!

内容的提问来源于stack exchange,提问作者Mugetsu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 10:02:18