You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform为PostgreSQL创建专用链接(Private Link)

It looks like the core issue here ties to incorrect Private DNS Zone naming and misconfigured network link settings—Azure enforces specific DNS zone standards for PaaS services like PostgreSQL to ensure proper private endpoint resolution, and your current setup uses a custom zone name that won’t work with Azure’s default private link DNS flow.

Let’s break down the fixes and share a corrected configuration:

Key Issues in Your Current Code

  • Wrong DNS Zone Name: Azure PostgreSQL requires the private DNS zone to be named privatelink.postgres.database.azure.com—custom names won’t work unless you’re running a fully self-managed DNS setup, which isn’t the standard approach here.
  • Incorrect registration_enabled Value: For private endpoint DNS links, this should be set to false. This flag is meant for auto-registering VMs into the DNS zone, not for linking private endpoints.
  • Potential Subnet Policy Gap: Your target subnet must have private_endpoint_network_policies disabled (a requirement for private endpoints to function).

Corrected Terraform Configuration

# Use Azure's REQUIRED private DNS zone name for PostgreSQL
resource "azurerm_private_dns_zone" "postgres_priv_dns" {
  name                = "privatelink.postgres.database.azure.com"
  resource_group_name = var.resource_group_name
}

# Virtual network link with registration disabled (correct for private endpoints)
resource "azurerm_private_dns_zone_virtual_network_link" "postgres_dns_link" {
  name                  = "postgres-priv-dns-link"
  resource_group_name   = var.resource_group_name
  private_dns_zone_name = azurerm_private_dns_zone.postgres_priv_dns.name
  virtual_network_id    = var.virtual_network_id
  registration_enabled  = false # Critical fix here
}

# Optional: Add this if your subnet doesn't already have private endpoint policies disabled
resource "azurerm_subnet" "data_subnet" {
  name                 = var.data_subnet_name
  resource_group_name  = var.resource_group_name
  virtual_network_name = var.virtual_network_name
  address_prefixes     = var.data_subnet_prefixes

  private_endpoint_network_policies_enabled = false
}

resource "azurerm_private_endpoint" "sql_postgres" {
  name                = var.postgresql_private_endpoint
  location            = var.location
  resource_group_name = var.resource_group_name
  subnet_id           = var.data_subnet_id # Replace with azurerm_subnet.data_subnet.id if you added the subnet resource above

  private_service_connection {
    name                           = var.postgresql_private_link
    private_connection_resource_id = azurerm_postgresql_server.postgresql.id
    subresource_names              = ["postgresqlServer"] # This part was already correct
    is_manual_connection           = false
  }

  private_dns_zone_group {
    name                 = "dns-group"
    private_dns_zone_ids = [azurerm_private_dns_zone.postgres_priv_dns.id]
  }
}

Post-Deployment Validation

  1. After applying the config, check the private endpoint in the Azure Portal—it should show an "Approved" status (since is_manual_connection is false, Azure auto-approves the link).
  2. Navigate to the privatelink.postgres.database.azure.com DNS zone and confirm an A record was automatically created, pointing to your PostgreSQL private endpoint’s private IP.
  3. Test connectivity from a VM in the linked virtual network: run nslookup <your-postgres-server-name>.postgres.database.azure.com—it should resolve to the private IP of the endpoint.

If issues persist, double-check that your PostgreSQL server’s firewall/network settings allow access via private endpoints (or restrict public access entirely to enforce private link usage).

内容的提问来源于stack exchange,提问作者Akshay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 22:22:31