General questions about Serverless Containers
Can I get logs of my operations in Yandex Cloud?
Yes, you can request information about operations with your resources from Yandex Cloud logs. Do it by contacting support
Why does an API request return the Illegal duration format error?
If your API request body contains parameters in type.googleapis.com/google.protobuf.Duration format, you may get the following error:
Illegal duration format; duration must end with 's' for type type.googleapis.com/google.protobuf.Duration
When using this format, make sure to append s to duration values.
For example:
{
"timeout": "120s"
}
Why do I get a Code 502 Message Error during function invocationerror after migrating an application to Serverless Containers?
You may get a 502 error when the code inside your container makes an HTTP request that fails with an error.
View the container execution log. It may include the full error text mentioning the failing HTTP request. If you cannot find helpful data in the log, configure structured logging for your containerized application.
Note
When invoking a container over HTTPS, some request and response HTTP headers may change (see Filtering message headers for details). Take this into account when migrating your application to Serverless Containers.
Why do I get a user container exec format errorerror when trying to invoke a container in Serverless Containers?
The issue occurs due to an incompatible runtime environment.
Rebuild the container for the --platform=linux/amd64 architecture.
How do I fix an out-of-space error?
Example error messages
zip I/O error: No space left on device
zip error: Output file write failure (write error on zip file)
===> executing build script
===> will start 'pip3.** install' in /function/code
...
ERROR: Could not install packages due to an OSError: [Errno 28] No space left on device
Serverless Containers has limits on the maximum storage capacity. Limits are technical constraints of the Yandex Cloud architecture. You cannot change the limits.
If your application requires more space, create a Compute Cloud VM instance and use it to deploy the application.
How do I assign a static IP address to a container?
You cannot assign a static IP address to a container because the container may run on resources with different addresses.
If your use case strictly requires a static IP address, create a Compute Cloud VM instance, make its public IP address static, and install the runtime environment for your programming language. Then use that VM to run your code.
Note
You can also use an API gateway to invoke the container using a custom domain. For more information, see the following:
Why do I get a Permission denied error with status code 403when trying to create a container revision?
Example error messages
url: https://console.yandex.cloud/folders/b1g*****************/functions/create-trigger;
message: Authentication problem: permission denied;
status: 403; description: Authentication problem: permission denied; code: GATEWAY_REQUEST_ERROR;
Request ID: ********-****-****-****-************; Trace ID: ****************;
url: https://console.yandex.cloud/folders/b1g*****************//serverless-containers/containers/bba*****************/editor;
message: Authentication problem: permission denied;
status: 403; description: Authentication problem: permission denied; code: GATEWAY_REQUEST_ERROR;
Request ID: ********-****-****-****-************; Trace ID: ****************;
url: https://console.yandex.cloud/folders/b1g*****************/api-gateway/create;
message: Permission denied; status: 403;
description: Permission denied; code: GATEWAY_REQUEST_ERROR;
Request ID: ********-****-****-****-************; Trace ID: ****************;
- Check user roles. Make sure the service account has a role for the folder or cloud that allows creating resources, such as
editoror higher. - Check the cloud status. The cloud status must be
ACTIVE.- If the cloud is
PENDING_DELETION, you cannot modify its resources. Try to cancel the pending cloud deletion. - If the cloud is suspended, e.g., due to arrears, you resolve the issue causing the suspension.
- If the cloud is
In most cases, the error occurs because the service account used by the resource lacks permissions to interact with other services. For example, if you see the Error PERMISSION_DENIED in client lockbox error, the service account does not have the roles to access Yandex Lockbox secrets.
If the error occurs when working with a mounted bucket, make sure the service account has the storage.viewer role to read bucket data or the storage.uploader role to read and write data to the bucket.
If you get this error when working with triggers, make sure the service account associated with the function, container, or trigger has the required roles:
functions.functionInvokerto invoke the function, orserverless-containers.containerInvokerto invoke the container.- Additional roles for triggers:
- Trigger for Message Queue:
ymq.readerfor the folder hosting the message queue. - Trigger for Container Registry:
container-registry.images.pullerto pull Docker images. - Trigger for Cloud Logging:
logging.readerfor the log group. - Trigger for Data Streams:
yds.editorfor the data stream. - Email trigger:
storage.uploaderfor the bucket storing email attachments. - Dead-letter queue:
ymq.writerrole for the DLQ to write unprocessed messages. This is optional.
- Trigger for Message Queue:
Note
A common pitfall causing this error is assigning a role for the service account as a resource. A role like this does not provide access to other folder resources. To resolve this, assign the role to the service account for a folder or a specific resource.