Skip to main content

AWS004 - Could Not Reach AWS

Agent error code #AWS004 indicates that the AWS CLI on the agent host never got an answer from AWS. The CLI reports Could not connect to the endpoint URL or Connect timeout on endpoint URL in this situation.

AWS did not reject anything. The request did not arrive.

Common causes include:

  • The region on the connection is mistyped, so the CLI is calling an endpoint that does not exist
  • The agent host has no route to the internet, or its firewall blocks outbound HTTPS
  • The agent host needs a proxy to reach AWS and the CLI is not configured to use it
  • DNS on the agent host cannot resolve AWS endpoint names

Steps to Resolve

Check the Region

  1. In the Knocknoc admin interface, open the AWS connection
  2. Confirm the region is an AWS region code such as us-east-1 or ap-southeast-2, not a display name such as "Sydney"
  3. Confirm it is the region the security group lives in

Check the Agent Host's Network Path

From the agent host, confirm it can reach the EC2 endpoint for the region, replacing the region as needed:

curl -sS -o /dev/null -w '%{http_code}\n' https://ec2.us-east-1.amazonaws.com/

Any HTTP status code means the endpoint is reachable. A timeout or a name resolution error points at the host's network, firewall or DNS.

Configure a Proxy

If the host reaches the internet through a proxy, set HTTPS_PROXY in the agent service's environment so the AWS CLI inherits it.