I am having issues setting up pact broker with aws...
# pact-broker
g
I am having issues setting up pact broker with aws ecs with the pact-foundation/pact-broker docker image I have a load balancer with https listener that forwards to my TargetGroup that points to my ecs service container at port 9292
Copy code
TargetGroup:
    Type: AWS::ElasticLoadBalancingV2::TargetGroup
    Properties:
      Name: pact-target-group
      Port: ${param:brokerPort}
      Protocol: HTTP
      VpcId: ${param:VpcId}
      TargetType: ip
      HealthCheckIntervalSeconds: 60
      HealthCheckPath: /diagnostic/status/heartbeat
      HealthCheckTimeoutSeconds: 30
      HealthyThresholdCount: 3
      UnhealthyThresholdCount: 2
  Listener:
    Type: AWS::ElasticLoadBalancingV2::Listener
    Properties:
      LoadBalancerArn: !Ref LoadBalancer
      Port: 443
      Certificates:
        - CertificateArn: ${cf(ap-southeast-2):scale-certificates.MultiRegionDomainCertificate, ''}
      Protocol: HTTPS
      SslPolicy: ELBSecurityPolicy-TLS13-1-2-2021-06
      DefaultActions:
        - Type: forward
          TargetGroupArn: !Ref TargetGroup
  ListenerHttp:
    Type: AWS::ElasticLoadBalancingV2::Listener
    Properties:
      LoadBalancerArn: !Ref LoadBalancer
      Port: 80
      Protocol: HTTP
      DefaultActions:
        - Type: 'redirect'
          RedirectConfig:
            Protocol: 'HTTPS'
            Port: 443
            Host: '#{host}'
            Path: '/#{path}'
            Query: '#{query}'
            StatusCode: 'HTTP_301'
but im currently having issues where the ecs container is returning my health checks as status 503 can someone help?
u
You need to check that
/diagnostic/status/heartbeat
is accessible from outside the ECS task and the port is the correct one that is exported from the docker container, the security groups are setup correctly to allow traffic from the ELB to the target group and that the IAM roles are configured correctly to interact with the target group. If any of those do not align up properly, you will get that response.
g
@uglyog it was the lack of security group defined! thank you so much for the tip!