将AWS App Runner服务接入VPC后无法访问互联网的问题排查求助
Let's break down the problem you're facing: after switching App Runner to VPC mode, it can't resolve external hostnames or reach public services like Bitbucket or the npm registry—even though your security group allows all outbound traffic. Here are the most likely fixes to check step by step:
1. Verify Subnet Routing (Critical for Private IP Internet Access)
App Runner tasks in VPC mode use private IP addresses by default—they can't directly use an Internet Gateway (IGW) to reach the public internet. You need a NAT Gateway to route outbound traffic from private subnets to the internet. Here's how to check:
- Go to the VPC Console → Subnets → Find the subnets assigned to your App Runner service.
- Check the associated route table for these subnets: there must be a route for
0.0.0.0/0(all traffic) pointing to a NAT Gateway (nat-xxxxxx), not an IGW.- If you don't see this route, add it. Make sure your NAT Gateway is in a public subnet (with its own route table pointing to an IGW) and is in an
availablestate.
- If you don't see this route, add it. Make sure your NAT Gateway is in a public subnet (with its own route table pointing to an IGW) and is in an
2. Check VPC DNS Configuration
The ssh: Could not resolve hostname error points to DNS failure. AWS App Runner relies on VPC DNS settings to resolve external domains:
- Go to VPC Console → Your VPC → Details.
- Ensure DNS support and DNS hostnames are both set to
Yes.- If either is disabled, your App Runner tasks can't use AWS's internal DNS server (VPC CIDR + 2, e.g.,
10.0.0.2) to resolve public hostnames likebitbucket.org.
- If either is disabled, your App Runner tasks can't use AWS's internal DNS server (VPC CIDR + 2, e.g.,
3. Validate Network ACLs (Subnet-Level Firewall)
Security groups handle instance-level traffic, but Network ACLs (NACLs) act as a subnet-level firewall. Even if your security group allows outbound traffic, a restrictive NACL can block it:
- Go to VPC Console → Network ACLs → Find the NACL associated with your App Runner subnets.
- For outbound rules: ensure there's a rule allowing all traffic (
0.0.0.0/0) on all ports, or at least TCP ports 22 (for Bitbucket SSH) and 443 (for npm HTTPS). - For inbound rules: allow ephemeral port ranges (typically 1024-65535) from
0.0.0.0/0—this lets return traffic from public services reach your App Runner tasks.
4. Confirm App Runner VPC Subnet Selection
Double-check that you assigned App Runner to private subnets (subnets without "Auto-assign public IPv4 address" enabled). While App Runner can work with public subnets, tasks won't get a public IP by default, so they still need a NAT Gateway to reach the internet. Using private subnets is the recommended pattern for this use case.
Why Your RDS Instance Works (But App Runner Doesn't)
Your RDS instance has a public IP enabled, so it can directly use the IGW to reach the internet (or you're connecting to it from the public internet). App Runner tasks don't get public IPs in VPC mode, so they depend entirely on the NAT Gateway for outbound internet access.
Try these steps in order—most of the time, missing NAT Gateway routing or misconfigured DNS settings are the root cause here.
内容的提问来源于stack exchange,提问作者gregdev

