You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

同一VPC内Lambda无法连接AWS ElastiCache Serverless Memcached排查

问题

尝试为AWS Lambda部署ElastiCache Serverless Memcached,当前配置如下:

  • ElastiCache实例部署在跨两个私有子网的VPC中,已开启VPC的dns_hostnames
  • Lambda部署在同一VPC的相同私有子网
  • ElastiCache安全组开放了11211、11212端口的TCP入站流量
  • Lambda使用memcache-plus模块连接,已附加elasticache:*的IAM权限

但调用Lambda时,在创建MemcachePlus客户端步骤失败。

相关代码

const MemcachePlus = require('memcache-plus');
const client = new MemcachePlus({
  hosts: [process.env.ELASTICACHE_ENDPOINT],
  autodiscover: true,
  onNetError: function (err) {
    console.error(err);
  },
});

Lambda安全组Terraform配置

resource "aws_security_group" "vpc_enabled_lambda_sg" {
  name        = "bp-${terraform.workspace}-vpc-lambda-sg"
  description = "Managed by Terraform"
  vpc_id      = aws_vpc.db_proxy_vpc.id

  # To Allow Port 80 Transport
  ingress {
    from_port   = 80
    protocol    = "tcp"
    to_port     = 80
    cidr_blocks = ["10.0.0.0/16"]
    description = "Allow HTTP traffic from within VPC"
  }

  # Open port 8000 for external access
  ingress {
    from_port   = 443
    protocol    = "tcp"
    to_port     = 443
    cidr_blocks = ["10.0.0.0/16"]
    description = "Allow HTTPS traffic from within VPC"
  }

  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  lifecycle {
    create_before_destroy = true
  }
}

ElastiCache安全组Terraform配置

resource "aws_security_group" "elasticache_memcached_sg" {
  name        = "bp-${terraform.workspace}-elasticache-memcached-sg"
  description = "Managed by Terraform"
  vpc_id      = aws_vpc.db_proxy_vpc.id

  # To Allow Port 11211 Transport
  ingress {
    from_port   = 11211
    protocol    = "tcp"
    to_port     = 11211
    cidr_blocks = ["10.0.0.0/16"]
    description = "Allow memcache traffic from within VPC"
  }

  # Open port 8000 for external access
  ingress {
    from_port   = 11212
    protocol    = "tcp"
    to_port     = 11212
    cidr_blocks = ["10.0.0.0/16"]
    description = "Allow memcache read traffic from within VPC"
  }

  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  lifecycle {
    create_before_destroy = true
  }
}

已尝试将MemcachePlus类放在handler内外,问题仍未解决。请问缺少哪些配置才能成功连接ElastiCache?


排查与解决方案

以下是几个可能导致连接失败的关键点及修复建议:

  1. 验证ElastiCache端点格式

    • 确保ELASTICACHE_ENDPOINT环境变量为hostname:port格式,例如your-cluster-name.xxxxxx.cfg.use1.cache.amazonaws.com:11211,遗漏端口会直接导致连接失败。
    • ElastiCache Serverless Memcached默认端口为11211,11212为自动发现端口,memcache-plus的autodiscover参数会自动处理该端口,无需手动指定。
  2. 完善VPC DNS配置

    • 除开启dns_hostnames,需确认VPC的dns_support已启用(默认开启,建议检查)。
    • 确保Lambda所在私有子网的路由表中,存在指向VPC DNS服务器(VPC IPv4范围的第2个IP,如10.0.0.2)的路由,否则无法解析ElastiCache域名。
  3. 优化安全组入站规则

    • 当前ElastiCache安全组使用10.0.0.0/16作为入源,改为直接引用Lambda安全组ID更精准可靠,避免CIDR范围过大的潜在问题:
      ingress {
        from_port       = 11211
        protocol        = "tcp"
        to_port         = 11211
        security_groups = [aws_security_group.vpc_enabled_lambda_sg.id]
        description     = "Allow memcache traffic from Lambda security group"
      }
      ingress {
        from_port       = 11212
        protocol        = "tcp"
        to_port         = 11212
        security_groups = [aws_security_group.vpc_enabled_lambda_sg.id]
        description     = "Allow memcache discovery traffic from Lambda security group"
      }
      
  4. 检查Lambda VPC配置细节

    • 确认Lambda已关联至少两个私有子网(与ElastiCache子网一致),避免单点故障。
    • 若Lambda依赖外部网络下载包,需确保私有子网配置了NAT网关;若为完全私有子网,需提前打包依赖包部署,不能在线安装。
  5. 调整memcache-plus客户端配置

    • 先关闭autodiscover测试基础连接,排查自动发现功能是否存在问题:
      const client = new MemcachePlus({
        hosts: [process.env.ELASTICACHE_ENDPOINT],
        autodiscover: false,
        onNetError: function (err) {
          console.error(err);
        },
      });
      
    • 增加超时配置,避免因网络延迟导致连接超时:
      const client = new MemcachePlus({
        hosts: [process.env.ELASTICACHE_ENDPOINT],
        autodiscover: true,
        timeout: 5000, // 设置5秒超时
        onNetError: function (err) {
          console.error(err);
        },
      });
      
  6. 梳理IAM权限必要性

    • ElastiCache Memcached(含Serverless)默认无需IAM权限连接,仅当启用IAM身份验证时才需要。若未启用IAM认证,附加elasticache:*权限无意义,建议移除后专注排查网络问题;若已启用,需使用支持IAM签名的客户端(如elasticache-memcached-client)或在memcache-plus中配置签名逻辑。
  7. 通过日志精准定位

    • 查看Lambda的CloudWatch日志,根据onNetError输出的具体错误定位:
      • ENOTFOUND:检查DNS配置和端点格式;
      • ECONNREFUSED:检查安全组规则和ElastiCache实例状态;
      • ETIMEDOUT:检查路由表、子网连通性或安全组。

内容的提问来源于stack exchange,提问作者Sree Teja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 00:48:11