如何让.NET C# REST API免SSH连接Amazon Neptune数据库?
解决.NET C#连接Amazon Neptune的两种方案
一、修复SSH端口转发连接(快速验证)
问题定位
你当前的端口转发代码存在两个关键错误:
gremlinHost设为localhost错误,该参数需指向Neptune集群的正式端点,而非EC2本地地址- Neptune默认强制SSL连接,你代码中
enableSsl: false会直接导致连接失败
修正后的代码
1. 复用SSH连接(避免每次查询重建)
将SshClient改为静态实例,维持长连接:
// 静态实例,复用已有连接 private static SshClient _ec2SshClient; // 获取或创建SSH连接 private static SshClient GetOrCreateEC2SshClient() { if (_ec2SshClient == null || !_ec2SshClient.IsConnected) { string host = "12.345.678.99"; string username = "ec2-user"; string privateKeyFilePath = "C:\\Users\\my-user\\privatekey.pem"; PrivateKeyFile privateKeyFile = new PrivateKeyFile(privateKeyFilePath); var connectionInfo = new ConnectionInfo( host, username, new PrivateKeyAuthenticationMethod(username, privateKeyFile)); _ec2SshClient = new SshClient(connectionInfo); _ec2SshClient.Connect(); } return _ec2SshClient; }
2. 修正端口转发与Gremlin客户端逻辑
// 替换为你的Neptune集群端点,格式类似:xxx.cluster-xxx.us-east-1.neptune.amazonaws.com string neptuneEndpoint = "your-neptune-cluster-endpoint"; int neptunePort = 8182; int localForwardPort = 8182; // 本地监听端口 var sshClient = GetOrCreateEC2SshClient(); // 配置端口转发:本地端口 → EC2 → Neptune集群端点 var portForwarded = new ForwardedPortLocal("127.0.0.1", (uint)localForwardPort, neptuneEndpoint, (uint)neptunePort); sshClient.AddForwardedPort(portForwarded); portForwarded.Start(); // 必须开启SSL,Neptune默认强制要求 var gremlinServer = new GremlinServer("localhost", localForwardPort, enableSsl: true); var gremlinClient = new GremlinClient(gremlinServer); var remoteConnection = new DriverRemoteConnection(gremlinClient, "g"); var g = Traversal().WithRemote(remoteConnection); // 测试查询示例 var testResult = g.V().Limit(10).ToList();
注意事项
- 确保EC2安全组允许出站访问Neptune的8182端口
- 确保Neptune安全组允许EC2实例的IP访问8182端口
- 程序退出时需释放资源:
portForwarded.Stop(); sshClient.Disconnect(); sshClient.Dispose();
二、使用网络负载均衡器(NLB)从VPC外连接Neptune(生产级方案)
具体设置步骤
创建网络负载均衡器(NLB)
- 选择与Neptune集群相同的VPC
- 选择Neptune所在的公网子网(或配置NAT网关确保外部可访问NLB)
- 监听端口设为
8182,协议选择TCP - 安全组配置:允许你的.NET服务所在IP/网段访问8182端口
创建目标组
- 目标类型选择
IP - 协议
TCP,端口8182 - 添加Neptune集群的端点IP(可从Neptune控制台「连接」页面获取)
- 健康检查:协议
TCP,端口8182
- 目标类型选择
关联NLB与目标组
- 将NLB的8182监听规则指向刚创建的目标组
配置Neptune安全组
- 允许NLB的安全组IP访问8182端口
.NET C#连接代码(直接连接NLB)
无需SSH,直接通过NLB端点连接,代码更简洁:
// 替换为你的NLB端点,格式类似:nlb-neptune-xxxxxx.us-east-1.elb.amazonaws.com string nlbEndpoint = "your-nlb-endpoint"; int nlbPort = 8182; // 必须开启SSL,与Neptune通信强制要求 var gremlinServer = new GremlinServer(nlbEndpoint, nlbPort, enableSsl: true); var gremlinClient = new GremlinClient(gremlinServer); var remoteConnection = new DriverRemoteConnection(gremlinClient, "g"); var g = Traversal().WithRemote(remoteConnection); // 查询示例 var vertices = g.V().HasLabel("Person").ToList();
注意事项
- NLB仅支持TCP协议监听,因为Neptune的Gremlin协议基于WebSocket
- 确保NLB子网路由配置正确,外部网络可访问NLB
- 生产环境建议用AWS Secrets Manager存储配置,避免硬编码敏感信息
内容的提问来源于stack exchange,提问作者Ben Tan
相关产品推荐
相关产品推荐

