同一VPC内Lambda无法连接AWS ElastiCache Serverless Memcached排查
问题
尝试为AWS Lambda部署ElastiCache Serverless Memcached,当前配置如下:
- ElastiCache实例部署在跨两个私有子网的VPC中,已开启VPC的
dns_hostnames - Lambda部署在同一VPC的相同私有子网
- ElastiCache安全组开放了11211、11212端口的TCP入站流量
- Lambda使用
memcache-plus模块连接,已附加elasticache:*的IAM权限
但调用Lambda时,在创建MemcachePlus客户端步骤失败。
相关代码
const MemcachePlus = require('memcache-plus'); const client = new MemcachePlus({ hosts: [process.env.ELASTICACHE_ENDPOINT], autodiscover: true, onNetError: function (err) { console.error(err); }, });
Lambda安全组Terraform配置
resource "aws_security_group" "vpc_enabled_lambda_sg" { name = "bp-${terraform.workspace}-vpc-lambda-sg" description = "Managed by Terraform" vpc_id = aws_vpc.db_proxy_vpc.id # To Allow Port 80 Transport ingress { from_port = 80 protocol = "tcp" to_port = 80 cidr_blocks = ["10.0.0.0/16"] description = "Allow HTTP traffic from within VPC" } # Open port 8000 for external access ingress { from_port = 443 protocol = "tcp" to_port = 443 cidr_blocks = ["10.0.0.0/16"] description = "Allow HTTPS traffic from within VPC" } egress { from_port = 0 to_port = 0 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] } lifecycle { create_before_destroy = true } }
ElastiCache安全组Terraform配置
resource "aws_security_group" "elasticache_memcached_sg" { name = "bp-${terraform.workspace}-elasticache-memcached-sg" description = "Managed by Terraform" vpc_id = aws_vpc.db_proxy_vpc.id # To Allow Port 11211 Transport ingress { from_port = 11211 protocol = "tcp" to_port = 11211 cidr_blocks = ["10.0.0.0/16"] description = "Allow memcache traffic from within VPC" } # Open port 8000 for external access ingress { from_port = 11212 protocol = "tcp" to_port = 11212 cidr_blocks = ["10.0.0.0/16"] description = "Allow memcache read traffic from within VPC" } egress { from_port = 0 to_port = 0 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] } lifecycle { create_before_destroy = true } }
已尝试将MemcachePlus类放在handler内外,问题仍未解决。请问缺少哪些配置才能成功连接ElastiCache?
排查与解决方案
以下是几个可能导致连接失败的关键点及修复建议:
验证ElastiCache端点格式
- 确保
ELASTICACHE_ENDPOINT环境变量为hostname:port格式,例如your-cluster-name.xxxxxx.cfg.use1.cache.amazonaws.com:11211,遗漏端口会直接导致连接失败。 - ElastiCache Serverless Memcached默认端口为11211,11212为自动发现端口,
memcache-plus的autodiscover参数会自动处理该端口,无需手动指定。
- 确保
完善VPC DNS配置
- 除开启
dns_hostnames,需确认VPC的dns_support已启用(默认开启,建议检查)。 - 确保Lambda所在私有子网的路由表中,存在指向VPC DNS服务器(VPC IPv4范围的第2个IP,如10.0.0.2)的路由,否则无法解析ElastiCache域名。
- 除开启
优化安全组入站规则
- 当前ElastiCache安全组使用
10.0.0.0/16作为入源,改为直接引用Lambda安全组ID更精准可靠,避免CIDR范围过大的潜在问题:ingress { from_port = 11211 protocol = "tcp" to_port = 11211 security_groups = [aws_security_group.vpc_enabled_lambda_sg.id] description = "Allow memcache traffic from Lambda security group" } ingress { from_port = 11212 protocol = "tcp" to_port = 11212 security_groups = [aws_security_group.vpc_enabled_lambda_sg.id] description = "Allow memcache discovery traffic from Lambda security group" }
- 当前ElastiCache安全组使用
检查Lambda VPC配置细节
- 确认Lambda已关联至少两个私有子网(与ElastiCache子网一致),避免单点故障。
- 若Lambda依赖外部网络下载包,需确保私有子网配置了NAT网关;若为完全私有子网,需提前打包依赖包部署,不能在线安装。
调整memcache-plus客户端配置
- 先关闭
autodiscover测试基础连接,排查自动发现功能是否存在问题:const client = new MemcachePlus({ hosts: [process.env.ELASTICACHE_ENDPOINT], autodiscover: false, onNetError: function (err) { console.error(err); }, }); - 增加超时配置,避免因网络延迟导致连接超时:
const client = new MemcachePlus({ hosts: [process.env.ELASTICACHE_ENDPOINT], autodiscover: true, timeout: 5000, // 设置5秒超时 onNetError: function (err) { console.error(err); }, });
- 先关闭
梳理IAM权限必要性
- ElastiCache Memcached(含Serverless)默认无需IAM权限连接,仅当启用IAM身份验证时才需要。若未启用IAM认证,附加
elasticache:*权限无意义,建议移除后专注排查网络问题;若已启用,需使用支持IAM签名的客户端(如elasticache-memcached-client)或在memcache-plus中配置签名逻辑。
- ElastiCache Memcached(含Serverless)默认无需IAM权限连接,仅当启用IAM身份验证时才需要。若未启用IAM认证,附加
通过日志精准定位
- 查看Lambda的CloudWatch日志,根据
onNetError输出的具体错误定位:ENOTFOUND:检查DNS配置和端点格式;ECONNREFUSED:检查安全组规则和ElastiCache实例状态;ETIMEDOUT:检查路由表、子网连通性或安全组。
- 查看Lambda的CloudWatch日志,根据
内容的提问来源于stack exchange,提问作者Sree Teja
相关产品推荐
相关产品推荐

