You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署的Redash v7无法连接Amazon RDS MySQL 8.0.28报‘SSL connection error: unknown error number’的解决方案咨询

Fixing SSL Connection Error Between Redash v7 (Docker) and Amazon RDS MySQL 8.0.28

I've run into similar compatibility issues with older Python 2.7-based tools connecting to MySQL 8.0, so let's break down the problem and actionable solutions:

The root cause here is that Redash v7 runs on Python 2.7 paired with an outdated version of MySQLdb (likely MySQL-python <=1.2.5), which doesn't support the newer TLS protocols or certificate validation mechanisms used by MySQL 8.0.28. Redash v10 uses modern dependencies (Python 3.x + updated MySQL clients) which explains why it works without issues.

Here are three solutions, ordered by preference:

1. Upgrade the MySQL client in the Redash container

The most robust fix is to replace the old MySQL-python package with mysqlclient—a maintained fork that supports both Python 2.7 and MySQL 8.0:

  • First, enter your running Redash container:
    docker exec -it <your-redash-container-id/name> bash
    
  • Uninstall the outdated MySQL client:
    pip uninstall -y MySQL-python
    
  • Install a compatible version of mysqlclient (supports Python 2.7):
    pip install mysqlclient==1.4.6
    
  • Restart Redash services to apply the change:
    supervisorctl restart all
    

Test your Python script again—this should resolve the SSL error by adding proper MySQL 8.0 support.

2. Specify a compatible SSL cipher

If upgrading dependencies isn't feasible right now, you can force the connection to use an SSL cipher that the old MySQLdb understands:

  • Modify your test script's SSL params to include a legacy cipher:
    ssl_params = {
        'ca': '/app/redash/query_runner/files/rds-combined-ca-bundle.pem',
        'cipher': 'DHE-RSA-AES256-SHA'
    }
    
  • For Redash's built-in MySQL data source, add this to the Additional Parameters field:
    ssl_cipher=DHE-RSA-AES256-SHA
    

This works by telling MySQL to use an encryption suite that the old client can handle.

As a last resort (since this reduces connection security), you can adjust your RDS instance's parameter group to use a TLS version compatible with the old client:

  1. Go to the AWS RDS Console, find your instance's associated parameter group.
  2. Edit the tls_version parameter and set it to TLSv1.0.
  3. Reboot your RDS instance to apply the change.

Again, this is a temporary fix—you should prioritize upgrading Redash or using the first solution to maintain secure connections.

After applying any of these fixes, run your test script to confirm the connection works:

python example.py

内容的提问来源于stack exchange,提问作者mythosil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 15:22:28