You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot连接AWS RDS PostgreSQL时用户密码认证失败问题

问题描述

我正在开发一个集成PostgreSQL数据库的Spring Boot应用,已在AWS上创建该数据库的RDS实例,并尝试通过AWS Elastic Beanstalk部署应用。但将RDS端点URL复制到application.properties文件后,出现错误:FATAL: password authentication failed for user "israelsanchez"。相关配置文件如下:

application.properties配置

spring.datasource.url=jdbc:postgresql://letscook-db.cldqpbve1mun.us-east-2.rds.amazonaws.com:5432/
spring.datasource.username=israelsanchez
spring.datasource.password=<Mypassword>
spring.jpa.defer-datasource-initialization=true
spring.jpa.hibernate.ddl-auto=update
spring.jpa.show-sql=true
spring.jpa.properties.hibernate.dialect=org.hibernate.dialect.PostgreSQLDialect
spring.jpa.properties.hibernate.format_sql=true
server.error.include-messages=always
server.port=5000
spring.thymeleaf.prefix=classpath:/templates/
spring.thymeleaf.suffix=.html
spring.thymeleaf.enabled=true

pg_hba.conf配置(本地默认配置,不适用于AWS RDS)

# Put your actual configuration here
# ----------------------------------
#
# If you want to allow non-local connections, you need to add more
# "host" records.  In that case you will also need to make PostgreSQL
# listen on a non-local interface via the listen_addresses
# configuration parameter, or via the -i or -h command line switches.

@authcomment@

# TYPE  DATABASE        USER            ADDRESS                 METHOD

@remove-line-for-nolocal@# "local" is for Unix domain socket connections only
@remove-line-for-nolocal@local   all             all                                     @authmethodlocal@
# IPv4 local connections:
host    all             all             127.0.0.1/32            trust
# IPv6 local connections:
host    all             all             ::1/128                 trust
# Allow replication connections from localhost, by a user with the
# replication privilege.
@remove-line-for-nolocal@local   replication     all                                     @authmethodlocal@
host    replication     all             127.0.0.1/32            @authmethodhost@
host    replication     all             ::1/128                 @authmethodhost@

postgresql.conf配置(本地默认配置,不适用于AWS RDS)

#------------------------------------------------------------------------------
# CONNECTIONS AND AUTHENTICATION
#------------------------------------------------------------------------------

# - Connection Settings -

#listen_addresses = '*'     # what IP address(es) to listen on;
                    # comma-separated list of addresses;
                    # defaults to 'localhost'; use '*' for all
                    # (change requires restart)
#port = 5432                # (change requires restart)
#max_connections = 100          # (change requires restart)
#superuser_reserved_connections = 3 # (change requires restart)
#unix_socket_directories = '/tmp'   # comma-separated list of directories
                    # (change requires restart)
#unix_socket_group = ''         # (change requires restart)
#unix_socket_permissions = 0777     # begin with 0 to use octal notation
                    # (change requires restart)
#bonjour = off              # advertise server via Bonjour
                    # (change requires restart)
#bonjour_name = ''          # defaults to the computer name
                    # (change requires restart)

# - TCP settings -
# see "man tcp" for details

#tcp_keepalives_idle = 0        # TCP_KEEPIDLE, in seconds;
                    # 0 selects the system default
#tcp_keepalives_interval = 0        # TCP_KEEPINTVL, in seconds;
                    # 0 selects the system default
#tcp_keepalives_count = 0       # TCP_KEEPCNT;
                    # 0 selects the system default
#tcp_user_timeout = 0           # TCP_USER_TIMEOUT, in milliseconds;
                    # 0 selects the system default

#client_connection_check_interval = 0   # time between checks for client
                    # disconnection while running queries;
                    # 0 for never

# - Authentication -

#authentication_timeout = 1min      # 1s-600s
#password_encryption = scram-sha-256    # scram-sha-256 or md5
#db_user_namespace = off

# GSSAPI using Kerberos
#krb_server_keyfile = 'FILE:${sysconfdir}/krb5.keytab'
#krb_caseins_users = off 

# - SSL -

#ssl = off
#ssl_ca_file = ''
#ssl_cert_file = 'server.crt'
#ssl_crl_file = ''
#ssl_crl_dir = ''
#ssl_key_file = 'server.key'
#ssl_ciphers = 'HIGH:MEDIUM:+3DES:!aNULL' # allowed SSL ciphers
#ssl_prefer_server_ciphers = on
#ssl_ecdh_curve = 'prime256v1'
#ssl_min_protocol_version = 'TLSv1.2'
#ssl_max_protocol_version = ''
#ssl_dh_params_file = ''
#ssl_passphrase_command = ''
#ssl_passphrase_command_supports_reload = off
解决建议
  • 补充数据库名称:spring.datasource.url末尾缺少具体的数据库名称,正确格式应为jdbc:postgresql://letscook-db.cldqpbve1mun.us-east-2.rds.amazonaws.com:5432/<你的数据库名>,需要填入你在RDS实例中创建的数据库名称。
  • 核对用户名密码:确保spring.datasource.username和spring.datasource.password与创建RDS实例时设置的主用户名、密码完全一致,注意大小写、特殊字符的转义(比如密码含&、#等字符时需处理)。
  • 检查RDS安全组:在AWS控制台确认Elastic Beanstalk环境的安全组被添加到RDS实例的入站规则中,允许5432端口的访问。RDS默认仅允许指定安全组访问,这是常见的连接失败原因。
  • 忽略本地PostgreSQL配置文件:你提供的pg_hba.conf和postgresql.conf是本地PostgreSQL的默认配置,AWS RDS的这些配置由AWS管理,无需手动修改,也不会影响你的RDS实例连接。
  • 确认JDBC驱动版本:如果RDS的密码加密方式是scram-sha-256,需确保使用的PostgreSQL JDBC驱动版本在42.2.0及以上,旧版本驱动不支持该认证方式会导致密码验证失败。

内容的提问来源于stack exchange,提问作者Israel Sanchez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 04:54:54