【问题标题】:UserData giving timeout error while accessing s3 bucketUserData 在访问 s3 存储桶时给出超时错误
【发布时间】:2018-09-17 19:11:09
【问题描述】:

我正在尝试从 S3 公共存储桶访问一个对象,但在执行我的 Cfn-init 帮助程序脚本时出现以下错误:

ConnectionError Traceback(最近一次调用最后一次):文件“cfnbootstrap\util.pyc”,第 162 行,_retry 文件“cfnbootstrap\util.pyc”,第 234 行,_timeout ConnectionError: ('Connection aborted.', error (10060, '连接尝试失败,因为连接方在一段时间后没有正确响应,或者连接失败,因为连接的主机没有响应'))"

如果我 RDP 实例并在浏览器中更改代理设置,我可以访问 S3 存储桶。

下面是我的代码:

 "Resources": {
    "WebServer": {
        "Type" : "AWS::EC2::Instance",
        "Metadata": {
            "AWS::CloudFormation::Authentication": {
                "S3AccessCreds": {
                    "type": "S3",
                    "roleName": "sit-test-user",
                    "buckets" : ["sit-test-bucket"]
                }
            },
            "AWS::CloudFormation::Init": {
                "config": {
                    "sources": {
                        "c:\\S3\\xxxx" : "https://s3-ap-southeast-2.amazonaws.com/xxxxxxx/xxxxxx.ps1"
                    }
                }
            }
        },



"UserData" : {
              "Fn::Base64" : { 
                  "Fn::Join" : ["", [
                  "<script>\n",
                    "cfn-init.exe -s ", 
                    {"Ref" : "AWS::StackId"}, 
                    " -r WebServer --region ", 
                    {"Ref" : "AWS::Region"},
                    " --http-proxy http://proxy.aws.xxxxxx.local:8080 \n",
                "</script>\n"
                ]]
            }
        }

【问题讨论】:

    标签: amazon-web-services amazon-s3 amazon-ec2 amazon-cloudformation


    【解决方案1】:

    我得到了同样的错误,直到相同的错误行号。在我的例子中,我将我的实例启动到一个私有子网中,然后尝试从 UserData 中的 S3(没有 VPC 端点)执行各种配置命令和下载。但是,我的子网没有通往 Internet 的路由。为了解决这个问题,我做了:

    • 在我的 CloudFormation 模板中,将路由表关联添加到指向 NAT 网关的路由表:
    AssocANat:
    Type: 'AWS::EC2::SubnetRouteTableAssociation'
    DependsOn:
      - SubnetA
      - RouteTableNATGatewayA
    Properties:
      RouteTableId: !Ref RouteTableNATGatewayA
      SubnetId: !Ref SubnetA
    
    • 添加了出站安全组规则以允许 TCP 443 以及我的 UserData 需要的任何其他内容:
    SecurityGroupEgress:
    - IpProtocol: tcp
      FromPort: '443'
      ToPort: '443'
      CidrIp: 0.0.0.0/0
    

    【讨论】:

      猜你喜欢
      • 2018-06-19
      • 2017-12-12
      • 1970-01-01
      • 2016-11-01
      • 1970-01-01
      • 2017-05-12
      • 2016-07-28
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多