terraform - 如何将第二个注册目标(具有不同端口)添加到指向任务定义的 alb 目标组
问题描述
我从这个可交付的教程开始,作为创建我的 AWS 环境的基础:http: //blog.shippable.com/setup-a-container-cluster-on-aws-with-terraform-part-2-provision-a-cluster
现在我有 2 个服务在 2 个负载均衡器后面的 2 个 EC2 实例上运行 2 个容器(每个服务 1 个)。我正在尝试将具有不同端口的第二个注册目标添加到目标组,并将其指向我的一个容器。侦听器很容易添加到 ALB,但我似乎无法弄清楚如何添加第二个目标以动态指向运行我的服务的实例。
在 UI 中,我只能手动将其指向一个 AWS 实例,而不是让它动态指向正在运行我的服务的任何实例。
以下看起来应该可以工作,但是由于我的容器是在任务中创建的,因此我似乎无法访问容器 id 来将 target_ip 指向,并且它不能指向服务。
resource "aws_alb_target_group_attachment" "test" {
target_group_arn = "${aws_alb_target_group.ecs-target-group.arn}"
target_id = "${aws_ecs_task_definition.test.id}"
port = 5000
}
下面是更多用于上下文的 terraform 代码:
resource "aws_alb" "ecs-load-balancer" {
name = "ecs-load-balancer"
security_groups = ["${aws_security_group.test_public_sg.id}"]
subnets = ["${aws_subnet.test_public_sn_01.id}", "${aws_subnet.test_public_sn_02.id}"]
tags {
Name = "ecs-load-balancer"
}
}
resource "aws_alb_target_group" "ecs-target-group" {
name = "ecs-target-group"
port = "80"
protocol = "HTTP"
vpc_id = "${aws_vpc.test_vpc.id}"
health_check {
healthy_threshold = "5"
unhealthy_threshold = "2"
interval = "30"
matcher = "200"
path = "/"
port = "traffic-port"
protocol = "HTTP"
timeout = "5"
}
tags {
Name = "ecs-target-group"
}
}
resource "aws_alb_listener" "alb-listener" {
load_balancer_arn = "${aws_alb.ecs-load-balancer.arn}"
port = "80"
protocol = "HTTP"
default_action {
target_group_arn = "${aws_alb_target_group.ecs-target-group.arn}"
type = "forward"
}
}
resource "aws_alb_listener" "alb-listener-vemcoio" {
load_balancer_arn = "${aws_alb.ecs-load-balancer.arn}"
port = "5000"
protocol = "HTTP"
default_action {
target_group_arn = "${aws_alb_target_group.ecs-target-group.arn}"
type = "forward"
}
}
resource "aws_ecs_task_definition" "test" {
family = "test"
container_definitions = "${data.template_file.test.rendered}"
}
data "template_file" "test" {
depends_on = ["aws_instance.mongodb_one"]
template = "${file("task-definitions/test.json")}"
vars {
mongo_ip = "${aws_instance.mongodb_one.private_ip}"
}
}
解决方案
您无需使用资源"aws_alb_target_group_attachment"
将目标组与容器或任务或实例连接起来。
您可以使用以下代码。它将自动处理 ecs 任务的动态端口。
检查以下代码的最后四行。
resource "aws_lb_target_group" "rc" {
name = "rc"
port = 80
protocol = "HTTP"
vpc_id = "${var.vpc_id}"
}
resource "aws_lb_listener_rule" "rc" {
listener_arn = "${var.listener_arn}"
priority = 100
action {
type = "forward"
target_group_arn = "${aws_lb_target_group.rc.arn}"
}
condition {
field = "host-header"
values = ["www.domain.com"]
}
}
resource "aws_ecs_service" "rc" {
name = "${var.name}"
cluster = "${var.cluster}"
task_definition = "${aws_ecs_task_definition.rc.arn}"
desired_count = "${var.desired_count}"
health_check_grace_period_seconds = "${var.health_grace_period}"
deployment_maximum_percent = "${var.deployment_maximum_percent}"
deployment_minimum_healthy_percent = "${var.deployment_minimum_healthy_percent}"
load_balancer {
target_group_arn = "${aws_lb_target_group.rc.arn}"
container_name = "test"
container_port = 5000
}
}
推荐阅读
- arrays - ValueError:形状(2,210)和(2,210)未对齐:210(dim 1)!= 2(dim 0)
- c# - WPF TextBox 检测文本是否溢出
- java - 使用 Enums 为每个不同的对象返回不同的操作
- javascript - 无法重新组合数组
- regex - Go 正则表达式是否支持连续匹配?
- java - 意外结果:字符串旁边的 null
- javascript - 从 forEachloop Javascript 中的异步函数返回值
- node.js - React Native:无法解析本地模块。存在于节点模块中
- ruby-on-rails - 为什么我的 rails 应用程序没有捕获我的条带错误?我是否正确使用救援?
- raspberry-pi - Remote.it 和 openVPN 一起使用