VPC私有子网内Lambda无法发布消息至SNS Topic求助
问题排查与修复建议
核心问题:SNS VPC接口终端节点的安全组规则缺失
你的SNS接口终端节点绑定了EC2的安全组db_proxy_sg_private,但这个安全组的入站规则仅开放了22、80、8000端口给公网子网(10.0.1.0/24),未允许Lambda所在私有子网的流量访问SNS终端节点的HTTPS端口(443),导致Lambda调用SNS时无法建立连接,触发超时。
具体修复步骤
1. 为SNS VPC终端节点配置独立安全组(推荐)
创建专门适配SNS终端节点的安全组,避免与EC2安全组规则冲突:
resource "aws_security_group" "sns_vpc_endpoint_sg" { name = "sns-vpc-endpoint-sg" description = "Allow Lambda access to SNS VPC endpoint" vpc_id = VPC_ID # 允许Lambda所在私有子网访问SNS的HTTPS端口 ingress { from_port = 443 protocol = "tcp" to_port = 443 cidr_blocks = ["10.0.0.0/24"] # 替换为Lambda所在私有子网的实际CIDR description = "Lambda private subnet to SNS HTTPS" } egress { from_port = 0 to_port = 0 protocol = "-1" cidr_blocks = ["0.0.0.0/0"] } } # 更新SNS VPC终端节点的安全组配置 resource "aws_vpc_endpoint" "sns" { vpc_id = VPC_ID service_name = "com.amazonaws.ca-central-1.sns" vpc_endpoint_type = "Interface" private_dns_enabled = true subnet_ids = [ PRIVATE_SUBNET_ID ] security_group_ids = [ aws_security_group.sns_vpc_endpoint_sg.id ] }
2. 临时修复:修改现有EC2安全组(不推荐,易影响EC2)
若暂时无法新建安全组,可在db_proxy_sg_private中补充入站规则:
resource "aws_security_group" "db_proxy_sg_private" { name = NAME description = "Managed by Terraform" vpc_id = VPC_ID # 保留原有入站规则... # 添加SNS访问规则 ingress { from_port = 443 protocol = "tcp" to_port = 443 cidr_blocks = ["10.0.0.0/24"] # 替换为Lambda所在私有子网的实际CIDR description = "Allow Lambda to access SNS VPC endpoint" } # 保留原有出站规则... }
额外验证点
- 确认
private_dns_enabled = true生效:Lambda运行时会自动将SNS公共域名解析为终端节点私有IP,无需修改代码中的SNS地址。 - 检查Lambda安全组:确保其允许出站访问443端口到SNS终端节点的CIDR或安全组。
- 私有子网路由表验证:启用私有DNS后,SNS请求会优先走VPC终端节点,无需依赖NAT网关。
内容的提问来源于stack exchange,提问作者Sree Teja
相关产品推荐
相关产品推荐

