本地正常的.NET 8容器部署到ACI后无法连接Azure SQL Server求助
解决Azure Container Instance连接Azure SQL的预登录握手错误
针对你遇到的连接成功建立但预登录握手时出现Connection reset by peer错误,可按以下步骤排查解决:
1. 强制指定TLS版本
.NET 8默认优先使用TLS 1.3,部分Azure SQL Server环境对TLS 1.3的兼容性可能存在问题。修改连接字符串,添加TLS版本强制配置:
Server=tcp:<your-server>.database.windows.net,1433;Initial Catalog=<your-db>;Persist Security Info=False;User ID=<user>;Password=<password>;MultipleActiveResultSets=False;Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;TlsVersion=TLS1.2
2. 验证连接字符串完整性
- 确认ACI环境变量中的连接字符串与本地完全一致,重点检查用户名、密码、服务器地址是否正确,注意密码中的特殊字符(如@、&)是否需要转义。
- 延长连接超时时间至30秒以上,避免网络波动导致握手中断。
3. 排查ACI网络出站限制
- 若ACI部署在自定义虚拟网络中,检查网络安全组(NSG)的出站规则,确保允许访问目标Azure SQL Server的1433端口。
- 确认ACI未配置限制SQL访问的代理或防火墙规则。
4. 检查Azure SQL Server状态
- 查看Azure SQL Server的诊断日志,确认是否存在针对ACI连接的拒绝记录或服务器性能异常。
- 非生产环境可尝试重启SQL Server,排除临时服务故障。
5. 容器内直接测试连接
进入ACI容器内部,使用sqlcmd工具直接测试数据库连接,定位问题是否出在应用代码层面:
sqlcmd -S <your-server>.database.windows.net -U <username> -P <password> -d <database-name>
报错信息参考:
Microsoft.AspNetCore.Server.Kestrel[13] Connection id "0HN1SVGHL7U9F", Request id "0HN1SVGHL7U9F:00000001": An unhandled exception was thrown by the application. Microsoft.Data.SqlClient.SqlException (0x80131904): A connection was successfully established with the server, but then an error occurred during the pre-login handshake. (provider: TCP Provider, error: 35 - An internal exception was caught) ---> System.IO.IOException: Unable to read data from the transport connection: Connection reset by peer. ---> System.Net.Sockets.SocketException (104): Connection reset by peer"
内容的提问来源于stack exchange,提问作者Alireza Yadegari
相关产品推荐
相关产品推荐

