You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Pulumi公开暴露AWS ElastiCache Redis实例失败排查

问题:AWS ElastiCache Serverless Redis无法通过公网访问(Pulumi部署)

我尝试用Pulumi将AWS ElastiCache Serverless Redis实例暴露到公网,当前部署环境是带公有子网、互联网网关和出站路由表的VPC,采用@pulumi/aws包实现。已为Redis实例绑定允许任意IP访问6379端口的安全组,但实例仍无法从公网访问。

部署代码

import * as aws from '@pulumi/aws';
import * as pulumi from '@pulumi/pulumi';

const stackName = pulumi.getStack();

const vpc = new aws.ec2.Vpc(`vpc-${stackName}`, {
  cidrBlock: '10.0.0.0/16',
  enableDnsHostnames: true,
  enableDnsSupport: true,
});

const subnet1 = new aws.ec2.Subnet(`subnet1-${stackName}`, {
  vpcId: vpc.id,
  availabilityZone: 'us-east-1a',
  cidrBlock: '10.0.26.0/24',
  mapPublicIpOnLaunch: true,
});

const igw = new aws.ec2.InternetGateway(`igw-${stackName}`, { vpcId: vpc.id });

const routeTable = new aws.ec2.RouteTable(`routeTable-${stackName}`, {
  vpcId: vpc.id,
  routes: [{ cidrBlock: '0.0.0.0/0', gatewayId: igw.id }],
});

new aws.ec2.RouteTableAssociation(`rta-${stackName}`, {
  subnetId: subnet1.id,
  routeTableId: routeTable.id,
});

export const redisSecurityGroup = new aws.ec2.SecurityGroup(`redis-sg-${stackName}`, {
  vpcId: vpc.id,
  ingress: [{ fromPort: 6379, toPort: 6379, protocol: 'tcp', cidrBlocks: ['0.0.0.0/0'] }],
  egress: [{ fromPort: 0, toPort: 0, protocol: '-1', cidrBlocks: ['0.0.0.0/0'] }],
});

export const redisCache = new aws.elasticache.ServerlessCache(`redisCache-${stackName}`, {
  engine: 'redis',
  name: `redis-${stackName}`,
  securityGroupIds: [redisSecurityGroup.id],
  subnetIds: [subnet1.id],
  userGroupId: '<YOUR_USER_GROUP_ID>',
});

已尝试的操作

  • 验证子网mapPublicIpOnLaunch参数设为true
  • 配置安全组允许6379端口的所有入站/出站流量
  • 确保存在指向互联网网关的公网路由

解决方案

核心缺失配置:开启公网访问权限

AWS ElastiCache Serverless Redis默认仅允许VPC内部访问,必须显式开启公网访问权限。修改ServerlessCache资源,添加publicAccessEnabled: true配置项:

export const redisCache = new aws.elasticache.ServerlessCache(`redisCache-${stackName}`, {
  engine: 'redis',
  name: `redis-${stackName}`,
  securityGroupIds: [redisSecurityGroup.id],
  subnetIds: [subnet1.id],
  userGroupId: '<YOUR_USER_GROUP_ID>',
  // 新增:开启公网访问
  publicAccessEnabled: true,
});

额外检查点

  • 用户组权限:确认指定的用户组包含有权限访问Redis的用户,且访问凭证(如密码)正确。
  • 路由表关联:通过AWS控制台验证子网确实关联了指向互联网网关的路由表(代码中已配置,可再次确认状态)。
  • 安全组规则:若需支持IPv6公网访问,需在安全组入站规则中添加::/0访问6379端口的规则。
  • 端点使用:公网访问需使用Redis实例的公网端点,可通过Pulumi输出的redisCache.endpoint查看正确地址。

内容的提问来源于stack exchange,提问作者Capaj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 20:40:55