You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

EC2实例上的Mattermost无法连接AWS Postgres RDS求助

问题描述

我正尝试在EC2实例上安装Mattermost,但Mattermost无法连接我的Postgres RDS实例。

Mattermost配置

"SqlSettings": {
        "DriverName": "postgres",
        "DataSource": "postgres://username:password@site.eu-west-2.rds.amazonaws.com:5432/mattermost?sslmode=disable\u0026connect_timeout=10\u0026binary_parameters=yes",
        "DataSourceReplicas": [],
        "DataSourceSearchReplicas": [],
        "MaxIdleConns": 20,
        "ConnMaxLifetimeMilliseconds": 3600000,
        "ConnMaxIdleTimeMilliseconds": 300000,
        "MaxOpenConns": 300,
        "Trace": false,
        "AtRestEncryptKey": "1ekbsxs1rs96gfffctc1xm317sw9r4rn",
        "QueryTimeout": 30,
        "DisableDatabaseSearch": false,
        "MigrationsStatementTimeoutSeconds": 100000,
        "ReplicaLagSettings": []
    },

环境与错误信息

Postgres的5432端口已开放,我可以通过pgadmin正常连接该Postgres实例,但Mattermost持续报错:

{"timestamp":"2023-07-24 10:10:55.707 Z","level":"info","msg":"Pinging SQL","caller":"sqlstore/store.go:238","database":"master"}
{"timestamp":"2023-07-24 10:10:55.720 Z","level":"error","msg":"Failed to ping DB","caller":"sqlstore/store.go:248","error":"pq: no pg_hba.conf entry for host \"172.0.0.0\", user \"postgres\", database \"mattermost\", no encryption","retrying in seconds":10}
{"timestamp":"2023-07-24 10:11:05.721 Z","level":"info","msg":"Pinging SQL","caller":"sqlstore/store.go:238","database":"master"}
{"timestamp":"2023-07-24 10:11:05.732 Z","level":"error","msg":"Failed to ping DB","caller":"sqlstore/store.go:248","error":"pq: no pg_hba.conf entry for host \"172.0.0.0\", user \"postgres\", database \"mattermost\", no encryption","retrying in seconds":10}
解决方案

错误核心是Postgres RDS的安全策略不允许EC2实例以非加密方式连接,或未将EC2所在IP段加入信任列表,按以下步骤修复:

1. 调整Mattermost的SSL连接配置

当前配置中sslmode=disable,但RDS默认可能强制SSL连接。将其修改为sslmode=require,修改后的DataSource示例:

postgres://username:password@site.eu-west-2.rds.amazonaws.com:5432/mattermost?sslmode=require&connect_timeout=10&binary_parameters=yes

2. 检查RDS的安全与参数设置

  • 确认RDS安全组已允许EC2实例的私有IP或所在VPC的CIDR段访问5432端口;
  • 进入RDS控制台的「参数组」,查看rds.force_ssl参数,若值为1则必须使用SSL连接,不能禁用;
  • 确保RDS的访问规则允许EC2所在IP段(如172.0.0.0/16)以加密方式访问mattermost数据库,用户为postgres。

3. 验证连接有效性

修改配置后重启Mattermost服务,若仍报错,直接在EC2实例上用psql测试连接:

psql "postgres://username:password@site.eu-west-2.rds.amazonaws.com:5432/mattermost?sslmode=require"

如果psql能连接,排查Mattermost配置细节;如果psql也失败,继续检查RDS的安全策略与SSL设置。

内容的提问来源于stack exchange,提问作者etranz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 05:10:14