将Hyperledger Composer连接已有Fabric:部署BNA遇错求助
Hey there, let's work through this issue together. That "EOF" error when installing your BNA usually points to a connection mismatch between your setup and the AWS-hosted Fabric network, plus a couple of other gaps we can fix step by step.
1. First, Let's Address the Missing CA Container
Looking at your docker ps output, there's no CA container running for Org1. Even though your immediate error is peer-related, a missing CA will cause authentication failures later when you try to interact with the network (like registering identities).
To fix this:
- Check your AWS Fabric template configuration to see if CA deployment was disabled by default. If so, enable it and redeploy, or manually start the CA container with this command (adjust the image tag if needed):
docker run -d --name ca.org1.example.com \ -p 7054:7054 \ -e FABRIC_CA_HOME=/etc/hyperledger/fabric-ca-server \ -e FABRIC_CA_SERVER_CA_NAME=ca.org1.example.com \ 763976151875.dkr.ecr.us-east-2.amazonaws.com/fabric-ca:latest \ fabric-ca-server start -b admin:adminpw - Make sure your EC2 security group allows inbound traffic on port 7054 (for CA) once it's running.
2. Fix the Core Peer Connection Issue (The "EOF" Error)
This error typically happens when your connection settings don't match the actual state of the Fabric peers on AWS. Here's what to check:
Step 1: Verify if TLS is Enabled on Peers
AWS Hyperledger Fabric templates almost always enable TLS by default, but your connection.json uses unencrypted grpc:// URLs. If TLS is on, peers will reject unencrypted connections, leading to the EOF error.
- Check if TLS is enabled for your peer:
Look fordocker inspect peer0.org1.example.com | grep -A 10 "Command"--tls.enabled=truein the output. If it's present, you need to update yourconnection.json:- Change peer/orderer URLs from
grpc://togrpcs:// - Add TLS certificate paths (you'll need to copy the peer's TLS cert from the AWS instance to your local machine if you're deploying remotely)
Example peer config:
"peers": { "peer0.org1.example.com": { "url": "grpcs://<YOUR_AWS_EC2_PUBLIC_IP>:7051", "eventUrl": "grpcs://<YOUR_AWS_EC2_PUBLIC_IP>:7053", "tlsCACerts": { "path": "/local/path/to/peer0.org1.example.com-tls-cert.pem" } } } - Change peer/orderer URLs from
Step 2: Replace "localhost" with Your AWS EC2 IP
Your connection.json uses localhost for all endpoints, but if you're running the BNA deployment command from your local machine (not directly on the AWS EC2 instance), localhost points to your own computer—not the Fabric network on AWS.
- Replace every instance of
localhostinconnection.jsonwith your EC2 instance's public IP address (if connecting from outside AWS) or private IP (if connecting from within the same VPC). - Double-check that your EC2 security group allows inbound traffic on ports 7050 (orderer), 7051 (peer endorser), and 7053 (peer event hub).
Step 3: Test Peer Connectivity
To confirm the network path is working:
- From the machine where you're running the BNA deployment, run:
If this fails, your security group is blocking the port, or there's a firewall between you and the EC2 instance. Fix that before proceeding.telnet <YOUR_AWS_EC2_IP> 7051 - Check the peer's logs for more details on why connections are failing:
Look for TLS handshake errors or port misconfiguration messages.docker logs peer0.org1.example.com
3. Final Checks
After making these changes:
- Restart any local tools (like the BNA deployment CLI) to pick up the updated
connection.json - Ensure the CA container is running (if you started it manually)
- Retry installing the business network
Content of the question comes from Stack Exchange, question author: ulu

