AWS Aurora(兼容PostgreSQL)数据库C#连接超时及RDS控制台无法找到公共可访问性设置面板问题求助
Hey there, let's walk through solving your connection issues step by step—since you can connect via the AWS CLI but not your local C# app, we need to address both the missing accessibility setting and the underlying network/configuration gaps.
First: Locating the "Public Accessibility" Setting for Aurora PostgreSQL
It’s easy to miss this because Aurora uses a cluster-instance structure, and the setting lives on the individual instance (not the cluster itself). Here’s how to find it:
- Open the AWS RDS Console and navigate to your Aurora PostgreSQL cluster.
- Switch to the Instances tab—you’ll see at least one primary instance listed here.
- Select the instance, then click the Modify button at the top of the page.
- Scroll down to the Network & Security section, and you’ll find the "Public accessibility" toggle. Set it to Yes.
- Scroll to the bottom, choose either Apply immediately (for testing) or schedule the change for your maintenance window, then confirm the modification.
Note for Serverless Clusters:
If you’re using Aurora Serverless v1, this setting can’t be modified after cluster creation—you’ll need to spin up a new cluster with public accessibility enabled during setup. For Serverless v2, the above steps apply just like provisioned instances.
Next: Troubleshooting the Connection Timeout in Your C# App
Even with public accessibility enabled, you’ll need to check these critical configurations to get your local app connected:
1. Update Your Security Group Rules
Your RDS instance’s security group is likely blocking incoming traffic from your local IP:
- Go back to your RDS instance details page, and click on the security group linked under Connectivity & security.
- In the security group console, go to the Inbound rules tab.
- Add a new rule:
- Type:
PostgreSQL(port 5432) - Source: Enter your local public IP address (you can look this up via a simple web search if you don’t know it)
- Type:
- Save the rule.
2. Verify Subnet Configuration
If your RDS instance is in a private subnet (one without an Internet Gateway in its route table), enabling public accessibility won’t work—private subnets don’t assign public IPs to resources. To fix this:
- Either move the instance to a public subnet (not recommended for production environments)
- Or use a VPN connection, AWS Direct Connect, or set up a bastion host to access the private subnet from your local machine.
3. Fix Your C# Connection String
Make sure your connection string is correctly formatted, and add SSL (required for most AWS RDS instances):
var connectionString = "Server=<your-RDS-instance-or-cluster-endpoint>; Database=<your-db-name>; User ID=<your-db-user>; Password=<your-db-password>; Port=5432; Ssl Mode=Require";
Double-check that the endpoint matches the one listed in your RDS instance’s connectivity details—don’t use the cluster endpoint if you’re targeting a specific instance (though the cluster endpoint should work too).
4. Test Local Network Access
Your local network might block outbound traffic on port 5432. Test this with a simple command:
telnet <your-RDS-endpoint> 5432
If the connection fails, reach out to your network administrator to open port 5432 for outbound traffic to your RDS endpoint.
Why Does the AWS CLI Work?
The aws rds-data execute-statement command uses AWS’s managed API to run queries—it doesn’t directly connect to the database’s 5432 port. As long as your IAM user has permissions for rds-data:ExecuteStatement and access to the Secrets Manager secret, it will work even if the database isn’t publicly accessible. This is a key difference from direct PostgreSQL client connections like the one in your C# app.
内容的提问来源于stack exchange,提问作者Simon Lomax

