使用Pulumi公开暴露AWS ElastiCache Redis实例失败排查
问题:AWS ElastiCache Serverless Redis无法通过公网访问(Pulumi部署)
我尝试用Pulumi将AWS ElastiCache Serverless Redis实例暴露到公网,当前部署环境是带公有子网、互联网网关和出站路由表的VPC,采用@pulumi/aws包实现。已为Redis实例绑定允许任意IP访问6379端口的安全组,但实例仍无法从公网访问。
部署代码
import * as aws from '@pulumi/aws'; import * as pulumi from '@pulumi/pulumi'; const stackName = pulumi.getStack(); const vpc = new aws.ec2.Vpc(`vpc-${stackName}`, { cidrBlock: '10.0.0.0/16', enableDnsHostnames: true, enableDnsSupport: true, }); const subnet1 = new aws.ec2.Subnet(`subnet1-${stackName}`, { vpcId: vpc.id, availabilityZone: 'us-east-1a', cidrBlock: '10.0.26.0/24', mapPublicIpOnLaunch: true, }); const igw = new aws.ec2.InternetGateway(`igw-${stackName}`, { vpcId: vpc.id }); const routeTable = new aws.ec2.RouteTable(`routeTable-${stackName}`, { vpcId: vpc.id, routes: [{ cidrBlock: '0.0.0.0/0', gatewayId: igw.id }], }); new aws.ec2.RouteTableAssociation(`rta-${stackName}`, { subnetId: subnet1.id, routeTableId: routeTable.id, }); export const redisSecurityGroup = new aws.ec2.SecurityGroup(`redis-sg-${stackName}`, { vpcId: vpc.id, ingress: [{ fromPort: 6379, toPort: 6379, protocol: 'tcp', cidrBlocks: ['0.0.0.0/0'] }], egress: [{ fromPort: 0, toPort: 0, protocol: '-1', cidrBlocks: ['0.0.0.0/0'] }], }); export const redisCache = new aws.elasticache.ServerlessCache(`redisCache-${stackName}`, { engine: 'redis', name: `redis-${stackName}`, securityGroupIds: [redisSecurityGroup.id], subnetIds: [subnet1.id], userGroupId: '<YOUR_USER_GROUP_ID>', });
已尝试的操作
- 验证子网
mapPublicIpOnLaunch参数设为true - 配置安全组允许6379端口的所有入站/出站流量
- 确保存在指向互联网网关的公网路由
解决方案
核心缺失配置:开启公网访问权限
AWS ElastiCache Serverless Redis默认仅允许VPC内部访问,必须显式开启公网访问权限。修改ServerlessCache资源,添加publicAccessEnabled: true配置项:
export const redisCache = new aws.elasticache.ServerlessCache(`redisCache-${stackName}`, { engine: 'redis', name: `redis-${stackName}`, securityGroupIds: [redisSecurityGroup.id], subnetIds: [subnet1.id], userGroupId: '<YOUR_USER_GROUP_ID>', // 新增:开启公网访问 publicAccessEnabled: true, });
额外检查点
- 用户组权限:确认指定的用户组包含有权限访问Redis的用户,且访问凭证(如密码)正确。
- 路由表关联:通过AWS控制台验证子网确实关联了指向互联网网关的路由表(代码中已配置,可再次确认状态)。
- 安全组规则:若需支持IPv6公网访问,需在安全组入站规则中添加
::/0访问6379端口的规则。 - 端点使用:公网访问需使用Redis实例的公网端点,可通过Pulumi输出的
redisCache.endpoint查看正确地址。
内容的提问来源于stack exchange,提问作者Capaj
相关产品推荐
相关产品推荐

