AWS EC2上.NET 8应用无法连接Vertex AI,.NET 4.8可正常运行
我使用Google.Cloud.AIPlatform.V1调用Vertex AI获取预测响应时,遇到连接超时错误,但相同代码在.NET 4.8控制台应用、本地或私有虚拟机环境中可正常运行,仅在AWS EC2环境中出现问题。已尝试设置http_proxy和grpc_proxy,问题依旧。
错误信息
Grpc.Core.RpcException: Status(StatusCode="Unavailable", Detail="Error connecting to subchannel.", DebugException="System.Net.Sockets.SocketException: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.")
System.Net.Sockets.SocketException (10060): A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.System.Threading.Tasks.Sources.IValueTaskSource.GetResult(Int16 token)
at System.Net.Sockets.Socket.g__WaitForConnectWithCancellation|285_0(AwaitableSocketAsyncEventArgs saea, ValueTask connectTask, CancellationToken cancellationToken)
at Grpc.Net.Client.Balancer.Internal.SocketConnectivitySubchannelTransport.TryConnectAsync(ConnectContext context)
--- End of inner exception stack trace ---
at Grpc.Net.Client.Balancer.Internal.ConnectionManager.PickAsync(PickContext context, Boolean waitForReady, CancellationToken cancellationToken)
at Grpc.Net.Client.Balancer.Internal.BalancerHttpHandler.SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
at Grpc.Net.Client.Internal.GrpcCall2.RunCall(HttpRequestMessage request, Nullable1 timeout)
at Google.Api.Gax.Grpc.ApiCallRetryExtensions.<>c__DisplayClass0_0`2.<b__0>d.MoveNext()
--- End of stack trace from previous location ---
调用代码
PredictionServiceClientBuilder ClientBuilder = new PredictionServiceClientBuilder(); ClientBuilder.JsonCredentials = File.ReadAllText(credentialsPath); ClientBuilder.Endpoint = "us-central1-aiplatform.googleapis.com"; var _predictionServiceClient = ClientBuilder.Build(); Console.WriteLine("Asking Google Vertex - How are you"); var prompt = "How are you ?"; var endpoint = EndpointName.FromProjectLocationPublisherModel("xxxx-xxxx-xxxx", "us-central1", "google", "text-bison@001").ToString(); var content = prompt; var instanceValue = new wkt::Value { StructValue = new wkt::Struct { Fields = { { "content", new wkt::Value { StringValue = content } } } } }; var instances = new List<wkt::Value> { instanceValue }; var parameters = new wkt::Value { StructValue = new wkt::Struct { Fields = { { "temperature", new wkt::Value { NumberValue = 0.5} }, { "maxOutputTokens", new wkt::Value { NumberValue = 1000 } }, { "topP", new wkt::Value { NumberValue = 0.45 } }, { "topK", new wkt::Value { NumberValue = 10 } } } } }; var response = await _predictionServiceClient.PredictAsync(endpoint, instances, parameters); Console.WriteLine(); Console.WriteLine("Response - "); Console.WriteLine(response.Predictions[0].StructValue.Fields["content"].StringValue);
解决建议
- 检查EC2网络出站规则:确认EC2实例安全组出站规则允许访问
us-central1-aiplatform.googleapis.com的443端口(HTTPS);若使用VPC,需确保NAT网关/互联网网关正常工作,或配置了Vertex AI的VPC端点。 - 验证代理配置有效性:AWS环境的代理可能需要身份验证,或地址、端口配置错误。在EC2实例上用
curl https://us-central1-aiplatform.googleapis.com测试代理连通性,同时确保GRPC代理支持HTTP/2协议。 - 统一.NET环境版本:确保EC2上使用的.NET版本与本地(.NET 4.8)一致,避免GRPC客户端兼容性问题。
- 添加超时与重试策略:在客户端构建时显式设置超时和重试逻辑,应对网络波动:
ClientBuilder.CallSettings = CallSettings.FromRetry(RetrySettings.FromExponentialBackoff( maxAttempts: 5, initialBackoff: TimeSpan.FromSeconds(1), maxBackoff: TimeSpan.FromSeconds(10), backoffMultiplier: 2 ).WithRetryFilter(status => status.StatusCode == StatusCode.Unavailable)); - 检查DNS解析:在EC2实例执行
nslookup us-central1-aiplatform.googleapis.com,确认域名能正常解析;若失败,检查VPC的DNS设置是否启用了解析服务。
内容的提问来源于stack exchange,提问作者Nitin A

