首页 > 解决方案 > ECS Fargate NGINX 容器未在 CloudWatch 日志中显示错误

问题描述

我的 nginx Dockerfile:

FROM nginx:1.15.12-alpine
RUN rm /etc/nginx/conf.d/default.conf
COPY ./nginx/nginx.conf /etc/nginx/conf.d

# Forward request logs to Docker log collector
RUN ln -sf /dev/stdout /var/log/nginx/access.log \
  && ln -sf /dev/stderr /var/log/nginx/error.log
EXPOSE 80
ENTRYPOINT ["nginx", "-g", "daemon off;"]

我的 ECS 任务定义中的容器:

[
  {
    "name": "nginx",
    "image": "<ECR REPO HERE>",
    "networkMode": "awsvpc",
    "essential": true,
    "portMappings": [
      {
        "containerPort": 80,
        "protocol": "http"
      }
    ],
    "logConfiguration": {
      "logDriver": "awslogs",
      "options": {
        "awslogs-group": "mygroup",
        "awslogs-region": "us-east-1",
        "awslogs-stream-prefix": "nginx"
      }
    },
    "essential": true
  }
]

然而,当部署任务时,它失败了,在 CloudWatch 中我看到以下内容:

在此处输入图像描述

我对 ECS / Cloudwatch 很陌生。如何查看容器失败的 NGINX 错误?

标签: dockernginxamazon-ecsamazon-cloudwatchaws-fargate

解决方案


  1. 你应该检查一下ECS_Execution_Role_Policy。它应该包含logs权限。像 :
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ecr:GetAuthorizationToken",
                "ecr:BatchCheckLayerAvailability",
                "ecr:GetDownloadUrlForLayer",
                "ecr:BatchGetImage",
                "logs:CreateLogStream",
                "logs:PutLogEvents"
            ],
            "Resource": "*"
        }
    ]
}
  1. 您应该ecs_agentawslogs驱动程序配置 的配置。

此配置文件路径/etc/ecs/ecs.config在主机中。这个文件应该是这样的:

ECS_CLUSTER=test_ecs_cluster
ECS_AVAILABLE_LOGGING_DRIVERS=["awslogs","json-file"]

看 :

这是一个文件


推荐阅读