You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过本地Golang程序连接运行中的Docker版Azure Cosmos模拟器

问题诊断与解决方案

核心问题

你代码里配置的是https://localhost:8081/,但Azure Cosmos Go SDK内部会尝试解析容器的内部IP(172.17.0.2),而这个IP在主机网络里无法直接访问,导致路由失败。同时,模拟器的自签名证书也需要正确配置,让Go程序能信任它。

修复步骤

1. 强制模拟器返回主机可访问的端点

启动容器时添加环境变量,让模拟器对外暴露localhost而非内部IP,避免SDK被重定向到不可访问的地址:

docker run \
    --publish 8081:8081 \
    --publish 10250-10255:10250-10255 \
    --interactive \
    --tty \
    -e AZURE_COSMOS_EMULATOR_IP_ADDRESS_OVERRIDE=localhost \
    mcr.microsoft.com/cosmosdb/linux/azure-cosmos-emulator:latest

2. 让Go程序信任模拟器证书

先下载证书:

curl -k https://localhost:8081/_explorer/emulator.pem > ~/emulatorcert.crt

Mac用户需要把证书添加到钥匙串并设置为「始终信任」,然后修改Go代码加载信任该证书:

package main

import (
    "context"
    "crypto/tls"
    "crypto/x509"
    "log"
    "os"
    "net/http"

    "github.com/Azure/azure-sdk-for-go/sdk/azcore"
    "github.com/Azure/azure-sdk-for-go/sdk/data/azcosmos"
)

func handle(err error) {
    if err != nil {
        log.Fatal(err)
    }
}

func main() {
    const (
        cosmosDbEndpoint = "https://localhost:8081/"
        cosmosDbKey      = "C2y6yDjf5/R+ob0N8A7Cgv30VRDJIWEHLM+4QDU5DE2nQ9nDuVTqobD4b8mGGyPMbIZnqyMsEcaGQy67XIw/Jw=="
        dbname           = "db5"
    )

    // 加载模拟器证书
    certPool := x509.NewCertPool()
    certBytes, err := os.ReadFile("~/emulatorcert.crt") // 替换为你的证书实际路径
    handle(err)
    if !certPool.AppendCertsFromPEM(certBytes) {
        log.Fatal("无法添加证书到信任池")
    }

    cred, err := azcosmos.NewKeyCredential(cosmosDbKey)
    handle(err)

    // 配置客户端使用信任的证书
    client, err := azcosmos.NewClientWithKey(cosmosDbEndpoint, cred, &azcosmos.ClientOptions{
        ClientOptions: azcore.ClientOptions{
            Transport: &http.Transport{
                TLSClientConfig: &tls.Config{
                    RootCAs: certPool,
                },
            },
        },
    })
    handle(err)

    databaseProperties := azcosmos.DatabaseProperties{ID: dbname}
    _, err = client.CreateDatabase(context.Background(), databaseProperties, nil)
    handle(err)

    log.Println("数据库创建成功")
}

3. 临时测试方案(不推荐用于生产)

如果只是快速验证功能,可以临时跳过证书验证(仅测试用):

client, err := azcosmos.NewClientWithKey(cosmosDbEndpoint, cred, &azcosmos.ClientOptions{
    ClientOptions: azcore.ClientOptions{
        Transport: &http.Transport{
            TLSClientConfig: &tls.Config{
                InsecureSkipVerify: true,
            },
        },
    },
})

4. 确认端口映射正常

执行以下命令检查容器端口映射是否生效:

docker ps

确保容器的8081/tcp端口已映射到主机的0.0.0.0:8081或localhost:8081。

内容的提问来源于stack exchange,提问作者Andres

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 15:52:42