AWS004 - Could Not Reach AWS
Agent error code #AWS004 indicates that the AWS CLI on the agent host never got an answer from AWS. The CLI reports Could not connect to the endpoint URL or Connect timeout on endpoint URL in this situation.
AWS did not reject anything. The request did not arrive.
Common causes include:
- The region on the connection is mistyped, so the CLI is calling an endpoint that does not exist
- The agent host has no route to the internet, or its firewall blocks outbound HTTPS
- The agent host needs a proxy to reach AWS and the CLI is not configured to use it
- DNS on the agent host cannot resolve AWS endpoint names
Steps to Resolve
Check the Region
- In the Knocknoc admin interface, open the AWS connection
- Confirm the region is an AWS region code such as
us-east-1orap-southeast-2, not a display name such as "Sydney" - Confirm it is the region the security group lives in
Check the Agent Host's Network Path
From the agent host, confirm it can reach the EC2 endpoint for the region, replacing the region as needed:
curl -sS -o /dev/null -w '%{http_code}\n' https://ec2.us-east-1.amazonaws.com/
Any HTTP status code means the endpoint is reachable. A timeout or a name resolution error points at the host's network, firewall or DNS.
Configure a Proxy
If the host reaches the internet through a proxy, set HTTPS_PROXY in the agent service's environment so the AWS CLI inherits it.