You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform配置的SecretsManager账号密码连接pgAdmin4失败求助

解决pgAdmin连接AWS RDS PostgreSQL时提示“名称或服务未知”的问题

我通过Terraform创建了AWS测试环境,其中包含一个公开可访问的PostgreSQL RDS实例。提前用AWS CLI在Secrets Manager中存储了数据库的用户名和密码,terraform apply执行成功,但使用pgAdmin4连接时,收到错误:无法连接到服务器:连接失败:名称或服务未知


相关代码

main.tf

resource "aws_vpc" "testrdsvpc" {
 cidr_block = "10.0.0.0/16"
 enable_dns_support = true
 enable_dns_hostnames= true 

 tags = {

   Name = "Test-RDS-related-VPC"

 }
}

resource "aws_subnet" "public_subnets" {
 count      = length(var.public_subnet_cidrs)
 vpc_id     = aws_vpc.testrdsvpc.id
 cidr_block = element(var.public_subnet_cidrs, count.index)
 availability_zone = element(var.azs, count.index)
 map_public_ip_on_launch = true


 
 tags = {

   Name = "Public Subnet(rds) ${count.index + 1}"

 }

}

resource "aws_subnet" "private_subnets" {
 count      = length(var.private_subnet_cidrs)
 vpc_id     = aws_vpc.testrdsvpc.id
 cidr_block = element(var.private_subnet_cidrs, count.index)
 availability_zone = element(var.azs, count.index)
 map_public_ip_on_launch = false

 tags = {

   Name = "Private Subnet(rds) ${count.index + 1}"

 }
}

resource "aws_internet_gateway" "gw" {
 vpc_id = aws_vpc.testrdsvpc.id
 tags = {
   Name = "testrds-vpc-igw"

 }

}

resource "aws_route_table" "second_rt" {

 vpc_id = aws_vpc.testrdsvpc.id

 
 route {
   cidr_block = "0.0.0.0/0"
   gateway_id = aws_internet_gateway.gw.id

 }

 tags = {

   Name = "2nd Route Table"

 }
}

resource "aws_route_table_association" "public_subnet_asso" {
 count = length(var.public_subnet_cidrs)
 subnet_id      = element(aws_subnet.public_subnets[*].id, count.index)
 route_table_id = aws_route_table.second_rt.id
}

resource "aws_security_group" "rds-security-group" {
 name        = "Allow postgres"
 description = "Allow inbound traffic from my IP address"
 vpc_id      = aws_vpc.testrdsvpc.id

ingress {
   description = "postgresql ingress"
   from_port   = 5432
   to_port     = 5432
   protocol    = "tcp"
   cidr_blocks = ["myipaddrsss"]
   ipv6_cidr_blocks = ["myipv6ipaddress"]
 }


egress {
   from_port   = 0
   to_port     = 0
   protocol    = "-1"
   cidr_blocks = ["0.0.0.0/0"]
   ipv6_cidr_blocks = ["::/0"]

 }

 tags = {
    Name = "postgres-sg"
 }

}

data "aws_secretsmanager_secret" "rds_secret" {
  count = length(var.secrets_list)
  name = element(var.secrets_list,count.index)
}

data "aws_secretsmanager_secret_version" "secret-rds-version" {
  count = length(var.secrets_list)
  secret_id = data.aws_secretsmanager_secret.rds_secret[count.index].id
}

#rds_instance name is:"RDS_learner_db"
resource "aws_db_instance" "learner-rds-ins" {
  allocated_storage    = var.allocated_storage
  db_name              = var.rds_instance_name
  publicly_accessible  = true
  engine               = var.engine
  engine_version       = var.engine_version
  instance_class       = var.instance_class
  username             = var.db_username
  password             = var.db_password
  db_subnet_group_name = aws_db_subnet_group.rds_sub_grp.name
  skip_final_snapshot  = true
  vpc_security_group_ids = [aws_security_group.rds-security-group.id]
}

resource "aws_db_subnet_group" "rds_sub_grp" {
  name       = "rds-subnet-test-grp"
  subnet_ids = aws_subnet.public_subnets[*].id

  tags = {
    Name = "My RDS subnet group"
  }
}

outputs.tf

output "secret_value" {
  value = data.aws_secretsmanager_secret_version.secret-rds-version[*].secret_string
  sensitive = true
}

output "rds_instance_endpoint" {
  value = aws_db_instance.learner-rds-ins.address
}

output "rds_instance_endpoint-port" {
  value = aws_db_instance.learner-rds-ins.port
}

补充说明

  • var.db_username和var.db_password与Secrets Manager中存储的用户名、密码(密钥名称)一致
  • var.secrets_list对应AWS控制台Secrets Manager中的密钥名称

相关截图:
pgAdmin连接错误提示
AWS RDS实例端点信息


可能的原因及解决步骤

1. 端点域名解析失败

这个错误核心指向DNS解析问题,即本地机器无法将RDS端点域名转换为有效IP地址:

  • 执行nslookup <你的RDS端点地址>,检查是否能返回正常IP;
  • 若解析失败,切换本地DNS为公共DNS(如8.8.8.8)后重试;
  • 确认RDS实例状态为可用(Available),未处于创建或维护阶段。

2. 安全组/网络ACL配置错误

  • 验证安全组cidr_blocks中的IP是否为当前公网IP(带/32后缀,可通过curl ifconfig.me获取);
  • 检查VPC网络ACL,确保入站规则允许5432端口流量从你的IP进入,出站规则允许响应流量返回。

3. RDS公开访问配置异常

  • 在AWS控制台查看RDS实例“连接性”配置,确认“公开访问”为是;
  • 检查RDS所在子网是否关联了包含Internet Gateway默认路由的路由表。

4. 端点地址输入错误

确认pgAdmin中填写的端点地址与Terraform输出的rds_instance_endpoint完全一致,不要包含端口号(端口需单独填写在对应字段)。


内容的提问来源于stack exchange,提问作者RendezYT

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 08:36:00