使用Terraform为PostgreSQL创建专用链接(Private Link)
Fixing Terraform Configuration for Azure PostgreSQL Private Link DNS
It looks like the core issue here ties to incorrect Private DNS Zone naming and misconfigured network link settings—Azure enforces specific DNS zone standards for PaaS services like PostgreSQL to ensure proper private endpoint resolution, and your current setup uses a custom zone name that won’t work with Azure’s default private link DNS flow.
Let’s break down the fixes and share a corrected configuration:
Key Issues in Your Current Code
- Wrong DNS Zone Name: Azure PostgreSQL requires the private DNS zone to be named
privatelink.postgres.database.azure.com—custom names won’t work unless you’re running a fully self-managed DNS setup, which isn’t the standard approach here. - Incorrect
registration_enabledValue: For private endpoint DNS links, this should be set tofalse. This flag is meant for auto-registering VMs into the DNS zone, not for linking private endpoints. - Potential Subnet Policy Gap: Your target subnet must have
private_endpoint_network_policiesdisabled (a requirement for private endpoints to function).
Corrected Terraform Configuration
# Use Azure's REQUIRED private DNS zone name for PostgreSQL resource "azurerm_private_dns_zone" "postgres_priv_dns" { name = "privatelink.postgres.database.azure.com" resource_group_name = var.resource_group_name } # Virtual network link with registration disabled (correct for private endpoints) resource "azurerm_private_dns_zone_virtual_network_link" "postgres_dns_link" { name = "postgres-priv-dns-link" resource_group_name = var.resource_group_name private_dns_zone_name = azurerm_private_dns_zone.postgres_priv_dns.name virtual_network_id = var.virtual_network_id registration_enabled = false # Critical fix here } # Optional: Add this if your subnet doesn't already have private endpoint policies disabled resource "azurerm_subnet" "data_subnet" { name = var.data_subnet_name resource_group_name = var.resource_group_name virtual_network_name = var.virtual_network_name address_prefixes = var.data_subnet_prefixes private_endpoint_network_policies_enabled = false } resource "azurerm_private_endpoint" "sql_postgres" { name = var.postgresql_private_endpoint location = var.location resource_group_name = var.resource_group_name subnet_id = var.data_subnet_id # Replace with azurerm_subnet.data_subnet.id if you added the subnet resource above private_service_connection { name = var.postgresql_private_link private_connection_resource_id = azurerm_postgresql_server.postgresql.id subresource_names = ["postgresqlServer"] # This part was already correct is_manual_connection = false } private_dns_zone_group { name = "dns-group" private_dns_zone_ids = [azurerm_private_dns_zone.postgres_priv_dns.id] } }
Post-Deployment Validation
- After applying the config, check the private endpoint in the Azure Portal—it should show an "Approved" status (since
is_manual_connectionis false, Azure auto-approves the link). - Navigate to the
privatelink.postgres.database.azure.comDNS zone and confirm an A record was automatically created, pointing to your PostgreSQL private endpoint’s private IP. - Test connectivity from a VM in the linked virtual network: run
nslookup <your-postgres-server-name>.postgres.database.azure.com—it should resolve to the private IP of the endpoint.
If issues persist, double-check that your PostgreSQL server’s firewall/network settings allow access via private endpoints (or restrict public access entirely to enforce private link usage).
内容的提问来源于stack exchange,提问作者Akshay
相关产品推荐
相关产品推荐

