You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ECS Fargate环境下Nginx Resolver配置无效,容器IP变更后无法解析新IP的问题求助

ECS Fargate环境下Nginx Resolver配置无效,容器IP变更后无法解析新IP的问题求助

大家好,我现在碰到一个特别头疼的问题:在AWS ECS Fargate环境里,当同网络内的容器IP发生变更后,我在Linux系统里能正常访问这些容器,但Nginx死活解析不到新的IP地址。

我查了一堆资料,看到Nginx官方文档明确说用resolver指令可以解决DNS缓存的问题,但我配置之后完全没效果——不管是用Fargate的默认DNS(172.16.0.23)、Google DNS(8.8.8.8)还是/etc/resolv.conf里的nameserver,都没法让Nginx刷新缓存。感觉Nginx就死死攥着旧IP不放,我几乎试了能想到的所有办法,还是搞不定,有没有大佬能给点提示?

我的环境与已尝试操作

  • 运行环境:AWS ECS Fargate
  • 已尝试的操作:
    • 在Nginx配置中添加resolver指令,设置valid=10s缩短缓存有效期
    • 更换过多个DNS服务器地址测试
    • 确认Linux系统本身能正常解析容器的新IP

相关配置文件

docker-compose.yml

version: "3.7"

x-aws-loadbalancer: ***

services:
  i***-root:
    image: ***
    container_name: i***-root
    ports:
      - "80:80"
      - "443:443"
    depends_on:
      - i***-angular
      - i***-react

  i***-angular:
    image: ***
    container_name: i***-angular

  i***-react:
    image: ***
    container_name: i***-react

x-aws-cloudformation:
  Resources:
    I***angularService:
      Properties:
        EnableExecuteCommand: true
    I***reactService:
      Properties:
        EnableExecuteCommand: true
    I***rootService:
      Properties:
        EnableExecuteCommand: true
    I***angularTaskDefinition:
      Properties:
        Cpu: 2048
        Memory: 4096
        TaskRoleArn: ***
    I***reactTaskDefinition:
      Properties:
        Cpu: 2048
        Memory: 4096
        TaskRoleArn: ***
    I***rootTaskDefinition:
      Properties:
        Cpu: 2048
        Memory: 4096
        TaskRoleArn: ***
    I***rootTCP80TargetGroup:
      Properties:
        HealthCheckPath: /
    I***rootTCP443TargetGroup:
      Properties:
        Protocol: HTTPS
        HealthCheckPath: /
    I***rootTCP443Listener:
      Properties:
        Protocol: HTTPS
        Certificates:
          - CertificateArn: ***

i***-root的Dockerfile

FROM node:16 as build-root
WORKDIR /app
ENV PATH /app/node_modules/.bin:$PATH
COPY map.json ./
COPY package.json yarn.lock ./
RUN yarn install
COPY . .
RUN yarn build
COPY ./public /app/dist/

FROM nginx:alpine
RUN rm /etc/nginx/conf.d/default.conf
COPY nginx/nginx-custom.conf /etc/nginx/conf.d/nginx-custom.conf
COPY nginx/nginx-custom443.conf /etc/nginx/conf.d/nginx-custom443.conf
COPY nginx/***-cert.pem /etc/ssl/certs/***-cert.pem
COPY nginx/***-private.pem /etc/ssl/certs/***-private.pem

WORKDIR /usr/share/nginx/html
COPY --from=build-root /app/dist .

CMD ["nginx", "-g", "daemon off;"]

nginx-custom.conf(配置了resolver的部分)

server {
    listen 80 default_server;
    server_name default;
    root   /usr/share/nginx/html;
    index index.html index.htm;

    location / {
        try_files $uri $uri/ /index.html;
    }

    resolver 172.16.0.23 ipv6=off valid=10s;
    set $upstream_endpoint http://***-react;

    location /***-react/ {
        rewrite ^/***-react/(.*) /$1 break;
        proxy_pass $upstream_endpoint;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection keep-alive;
        proxy_set_header Host $http_host;
        proxy_set_header IdRef $http_IdRef;
        proxy_cache_bypass $http_upgrade;
        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header   X-Forwarded-Proto $scheme;
        fastcgi_read_timeout 999999;
        proxy_connect_timeout 999999;
        proxy_send_timeout   999999;
        proxy_read_timeout   999999;
        send_timeout 999999;
        fastcgi_buffers 16 16k;
        fastcgi_buffer_size 32k;
    }
}

我按照Nginx文档的要求,用变量$upstream_endpoint间接指定upstream(因为直接写proxy_pass http://***-react的话Nginx只会在启动时解析一次),但还是没效果,实在搞不懂哪里出问题了,求各位大佬指点!

备注:内容来源于stack exchange,提问作者Rafael darkxp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 07:49:29