跨VPC对等连接解析私有API Gateway端点失败求助
环境说明
- 在api_vpc(原VPC A)中已部署私有API Gateway端点:
xxxxxxxxxx.execute-api.eu-central-1.amazonaws.com - 已建立api_vpc与client_vpc(原VPC B)的VPC对等连接,且启用DNS解析
- 两个VPC均开启DNS名称与DNS解析功能
- api_vpc内实例可成功访问该API端点
- client_vpc与api_vpc的实例可互相解析对方DNS名称
问题描述
client_vpc内实例无法解析execute-api.eu-central-1.amazonaws.com域名
尝试方案
- 在api_vpc创建Route53入站解析端点,Terraform配置如下:
resource "aws_route53_resolver_endpoint" "inbound_resolver_ep" { name = "private-api-inbound-resolver-endpoint" direction = "INBOUND" security_group_ids = [aws_security_group.inbound_resolver_ep_sg.id] ip_address { subnet_id = aws_subnet.private_sn_az1.id ip = "10.0.1.10" } ip_address { subnet_id = aws_subnet.private_sn_az2.id ip = "10.0.2.10" } tags = { Name = "private-api-inbound-resolver-endpoint" } }
- 在client_vpc创建Route53出站解析端点及转发规则,Terraform配置如下:
resource "aws_route53_resolver_endpoint" "outbound_resolver_ep" { name = "private-api-outbound-resolver-endpoint" direction = "OUTBOUND" security_group_ids = [aws_security_group.outbound_resolver_ep_sg.id] ip_address { subnet_id = aws_subnet.api_client_pri_sn_az1.id ip = "172.128.1.10" } ip_address { subnet_id = aws_subnet.api_client_pri_sn_az2.id ip = "172.128.2.10" } tags = { Name = "private-api-resolver-endpoint" } } resource "aws_route53_resolver_rule" "private_api_resolver_rule" { name = "private-api-resolver-rule" domain_name = var.private_api_domain_name rule_type = "FORWARD" resolver_endpoint_id = aws_route53_resolver_endpoint.outbound_resolver_ep.id target_ip { ip = "10.0.1.10" } target_ip { ip = "10.0.2.10" } tags = { Name = "private-api-resolver-rule" } }
测试结果
- 两VPC实例仍可互相解析对方DNS名称
- client_vpc实例可解析私有API Gateway接口端点,但无法解析API端点域名
- 测试命令及输出:
sh-5.2$ nslookup scnejgvlzb.execute-api.eu-central-1.amazonaws.com Server: 172.128.0.2 Address: 172.128.0.2#53 ** server can't find scnejgvlzb.execute-api.eu-central-1.amazonaws.com: NXDOMAIN sh-5.2$ curl -X POST https://scnejgvlzb.execute-api.eu-central-1.amazonaws.com/dev/claim curl: (6) Could not resolve host: scnejgvlzb.execute-api.eu-central-1.amazonaws.com sh-5.2$ nslookup vpce-0e7d18d5586aefb59-o8c71fb8-eu-central-1a.execute-api.eu-central-1.vpce.amazonaws.com Server: 172.128.0.2 Address: 172.128.0.2#53 Non-authoritative answer: Name: vpce-0e7d18d5586aefb59-o8c71fb8-eu-central-1a.execute-api.eu-central-1.vpce.amazonaws.com Address: 10.0.1.199 sh-5.2$ nslookup ip-10-0-1-97.eu-central-1.compute.internal Server: 172.128.0.2 Address: 172.128.0.2#53 Non-authoritative answer: Name: ip-10-0-1-97.eu-central-1.compute.internal Address: 10.0.1.97 sh-5.2$ sh-5.2$ ping ip-10-0-1-187.eu-central-1.compute.internal PING ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187) 56(84) bytes of data. 64 bytes from ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187): icmp_seq=1 ttl=127 time=0.299 ms 64 bytes from ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187): icmp_seq=2 ttl=127 time=0.432 ms 64 bytes from ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187): icmp_seq=3 ttl=127 time=0.470 ms 64 bytes from ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187): icmp_seq=4 ttl=127 time=0.406 ms 64 bytes from ip-10-0-1-187.eu-central-1.compute.internal (10.0.1.187): icmp_seq=5 ttl=127 time=0.412 ms ^C --- ip-10-0-1-187.eu-central-1.compute.internal ping statistics --- 5 packets transmitted, 5 received, 0% packet loss, time 4095ms rtt min/avg/max/mdev = 0.299/0.403/0.470/0.056 ms sh-5.2$ sh-5.2$ curl http://ip-10-0-1-187.eu-central-1.compute.internal <html><body><h1>It works!</h1></body></html> sh-5.2$
补充说明
- 首次使用Route53解析端点,可能存在配置遗漏
- 项目通过Terraform部署,client_vpc实例可正常访问api_vpc内实例,但无法解析目标API域名
- 已尝试Route53解析端点配置,问题仍未解决
内容的提问来源于stack exchange,提问作者Fon Nkwenti
相关产品推荐
相关产品推荐

