AWS Certified Developer – Associate (DVA-C02)Troubleshooting and MonitoringMedium

A developer is investigating why an AWS CodeBuild project is failing consistently during the `BUILD` phase. The build logs show errors indicating `Cannot connect to Docker daemon` and `permission denied while trying to connect to the Docker daemon socket`. The CodeBuild project is configured with a Linux environment and uses a standard image. What is the MOST likely cause of this issue?

  1. AThe CodeBuild project's 'Privileged' flag is not enabled in its compute environment settings.
  2. BThe build image used by CodeBuild does not have Docker installed or configured correctly.
  3. CThe CodeBuild project's service role is missing permissions to interact with Amazon ECR.
  4. DThe `buildspec.yml` file has an incorrect `runtime-versions` setting for Docker.
Show answer & explanation

Correct answer: A. The CodeBuild project's 'Privileged' flag is not enabled in its compute environment settings.

The error 'Cannot connect to Docker daemon' and 'permission denied' strongly suggests that the build environment does not have the necessary privileges to run Docker commands. In CodeBuild, enabling the 'Privileged' flag is required to run Docker commands or build Docker images within the build environment.

Why the other options are wrong

  • B. Standard CodeBuild images typically come with Docker pre-installed. If it wasn't installed, the error would likely be 'docker command not found', not a permission issue with the daemon.
  • C. Missing ECR permissions would manifest as authentication or push/pull errors with ECR, not issues connecting to the local Docker daemon.
  • D. The `runtime-versions` setting is for languages like Node.js or Python, not directly for Docker daemon connectivity issues. Docker is managed via the privileged flag and image choice.

CodeBuild Privileged Mode

CodeBuild's 'Privileged' flag grants the build environment the ability to run Docker commands, essential for building Docker images or interacting with the Docker daemon.

  • Required for `docker build`, `docker run`, etc.
  • Enabled in the CodeBuild project settings.
  • Not enabled by default for security reasons.

Memory trick: For Docker in CodeBuild, 'Privileged' is the magic word.

More Troubleshooting and Monitoring questions