ECS实例IP表配置及容器实例获取AWS凭证的网络命令设置
Alright, let's walk through the exact network configurations you need to apply to your ECS container instances—this ensures your task containers can successfully fetch AWS credentials.
Step 1: Enable Local Route Forwarding
First, you need to allow your instance to route traffic destined for the local link subnet to the loopback interface. Run this command:
sudo sysctl -w net.ipv4.conf.all.route_localnet=1
Note: To make this setting persist after instance reboots, add net.ipv4.conf.all.route_localnet=1 to your /etc/sysctl.conf file.
Step 2: Add NAT Prerouting Rule
Next, add an iptables rule to redirect traffic sent to 169.254.170.2:80 (the ECS credential endpoint) to the local ECS credential proxy running on port 51679:
sudo iptables -t nat -A PREROUTING -p tcp -d 169.254.170.2 --dport 80 -j DNAT --to-destination 127.0.0.1:51679
Step 3: Complete the Required iptables Rules
Since your original command was truncated, you'll also need this OUTPUT chain rule to handle traffic originating from the instance itself (including containers):
sudo iptables -t nat -A OUTPUT -d 169.254.170.2 -p tcp --dport 80 -j REDIRECT --to-ports 51679
Persisting iptables Rules
To keep these iptables rules after a reboot, save them using your OS-specific method. For Debian/Ubuntu-based systems:
iptables-save > /etc/iptables/rules.v4
For RHEL/CentOS-based systems:
service iptables save
内容的提问来源于stack exchange,提问作者Sunil Kumar Mohanty

