所以我试图通过 terraform 将一个公共托管的 docker 容器启动到我的 ECS 中。计划完成没有任何错误,并启动服务但ECS实例为空,服务仅抱怨没有分配给集群的ECS实例。
作为我的基础设施的一部分,我定义了:
- 专有网络
- 安全组
- 我的角色
- ecs集群
- 带有 ALB 的 ecs 服务
鉴于其他一切都启动并且我可以 ssh 到 ecs(甚至手动拉取并运行 docker 映像),我很确定所有网络都正常,这让我认为这可能是 ECS 服务和 ALB 之间的连接?
ECS服务:
locals {
application_name = "${var.environment}-kafka"
}
resource "aws_ecs_service" "kafka" {
name = "${local.application_name}"
iam_role = "${var.iam-role_arn}"
cluster = "${var.ecs-cluster_id}"
task_definition = "${aws_ecs_task_definition.kafka_definition.arn}"
desired_count = "${var.count_kafka}"
deployment_minimum_healthy_percent = "${var.deployment_min_healthy_percent}"
deployment_maximum_percent = "${var.deployment_max_percent}"
depends_on = ["aws_alb_listener.kafka-alb-listener"]
load_balancer {
target_group_arn = "${aws_alb_target_group.kafka-alb-target-group.arn}"
container_port = 80
container_name = "kafka"
}
lifecycle {
create_before_destroy = true
}
}
resource "aws_ecs_task_definition" "kafka_definition" {
family = "${var.environment}_kafka"
container_definitions = "${data.template_file.kafka_task.rendered}"
lifecycle {
create_before_destroy = true
}
}
data "template_file" "kafka_task" {
template= "${file("${path.module}/kafka_task_definition.tpl")}"
vars {
kafka_docker_image = "${var.kafka-docker-image_name}:${var.kafka-docker-image_tag}"
}
}
ALB:
resource "aws_alb" "kakfa-alb" {
name = "${local.application_name}-alb"
security_groups = ["${var.security_groups_ids}"]
subnets = ["${var.public_subnet_ids}"]
tags {
Name = "${local.application_name}-alb"
Environment = "${var.environment}"
}
}
resource "aws_alb_target_group" "kafka-alb-target-group" {
name = "${aws_alb.kakfa-alb.name}-target-group"
port = "5000"
protocol = "HTTP"
vpc_id = "${var.vpc_id}"
depends_on = ["aws_alb.kakfa-alb"]
health_check {
healthy_threshold = "5"
unhealthy_threshold = "2"
interval = "30"
matcher = "200"
path = "/"
port = "traffic-port"
protocol = "HTTP"
timeout = "5"
}
tags {
Name = "${aws_alb.kakfa-alb.name}-target-group"
Environment = "${var.environment}"
}
}
resource "aws_alb_listener" "kafka-alb-listener" {
load_balancer_arn = "${aws_alb.kakfa-alb.arn}"
port = "80"
protocol = "HTTP"
default_action {
target_group_arn = "${aws_alb_target_group.kafka-alb-target-group.arn}"
type = "forward"
}
}