AWS RDS PostgreSQL 15.2无加密pg_hba.conf条目连接报错求助
解决AWS RDS PostgreSQL连接报错:no encryption
问题核心
你遇到的错误pg_hba.conf entry for host "103.215.537.148", user "dbmasteruser", database "postgres", no encryption,本质是你的RDS PostgreSQL实例要求所有连接必须使用SSL加密,但客户端连接时未启用加密。注意:AWS RDS不允许直接修改pg_hba.conf文件,所有安全规则通过RDS控制台的参数组和实例配置管理。
解决方案
1. 启用RDS实例强制SSL连接
登录AWS RDS控制台:
- 找到目标PostgreSQL实例,进入「配置」标签页查看「SSL连接」状态。
- 若未启用强制SSL,进入关联的「参数组」,找到参数
rds.force_ssl并设置为1,保存后重启RDS实例生效。
2. 修改Node.js连接配置,启用SSL
pg-pubsub依赖pg库,需在连接时明确指定SSL选项,有两种修改方式:
方式一:连接字符串添加SSL参数
const pgClient = new PGPubsub( 'postgres://dbmasteruser:password@host.ap-south-1.rds.amazonaws.com:5432/postgres?ssl=true', { log: console.log } );
方式二:通过配置对象传入SSL选项(更灵活)
const pgClient = new PGPubsub( 'postgres://dbmasteruser:password@host.ap-south-1.rds.amazonaws.com:5432/postgres', { log: console.log, ssl: { rejectUnauthorized: false // 测试环境可直接使用;生产环境建议导入RDS根证书并设为true } } );
3. 补充检查安全组配置
虽然错误并非端口问题,但需确保RDS实例的安全组入站规则允许客户端IP(103.215.537.148)访问5432端口:
- 进入实例「连接与安全性」标签页,查看关联的安全组。
- 编辑安全组入站规则,添加「PostgreSQL」类型规则,源设置为你的客户端IP。
调整后的完整代码示例
import WebSocket from 'ws'; import PGPubsub from 'pg-pubsub'; import { db } from '../../config'; const initializeWebSocket = async (server: any) => { const wss = new WebSocket.Server({ server }); const connectionString = process.env.NODE_ENV === 'development' ? db.dev.DB_URL : db.production.DB_URL; console.log('_____', process.env.NODE_ENV, '______ws'); // 启用SSL连接配置 const pgClient = new PGPubsub( connectionString, { log: console.log, ssl: { rejectUnauthorized: false } } ); const channel = 'users_insert'; await pgClient.addChannel(channel, function (channelPayload) { console.log(channelPayload, 'channnel run is ther some insersion'); wss.clients.forEach((client) => { if (client.readyState === WebSocket.OPEN) { client.send('Data in the database has changed'); } }); }); const matchChannel = 'match_update'; await pgClient.addChannel(matchChannel, function (channelPayload) { wss.clients.forEach((client) => { if (client.readyState === WebSocket.OPEN) { client.send('Data in the database has changed'); } }); }); const res = await pgClient.publish(channel, { hello: 'world' }); }; export default initializeWebSocket;
import Logger from './core/Logger'; import { port } from './config'; import app from './app'; import http from 'http'; import WebSocket from './routes/webSocket/webSocketServer'; console.log('hii server'); const server = http.createServer(app); WebSocket(server); server .listen(port, () => { Logger.info(`server running on port : ${port}`); }) .on('error', (e) => Logger.error(e));
内容的提问来源于stack exchange,提问作者Parth Shrivastav
相关产品推荐
相关产品推荐

