You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform部署AWS RDS PostgreSQL无法公网访问求助

公网连接AWS RDS PostgreSQL实例超时问题排查与解决

问题详情

连接命令:

psql -h postgress-rds-external-instance.ch3jsdgkjsd.us-west-2.rds.amazonaws.com -p 5432 -U postgadmin -d postgres -W

错误信息:

psql: error: connection to server at "postgress-rds-external-instance.ch3jsdgkjsd.us-west-2.rds.amazonaws.com" (54.244.16.262), port 5432 failed: Operation timed out
    Is the server running on that host and accepting TCP/IP connections?

现有Terraform配置

VPC模块配置

module "vpc" {
  source  = "terraform-aws-modules/vpc/aws"
  version = "~> 5.0"

  # VPC Basic Details
  name            = var.vpc_name
  cidr            = "10.0.0.0/16"
  azs             = ["us-west-2b", "us-west-2c"]
  private_subnets = ["10.0.1.0/24", "10.0.2.0/24"]
  public_subnets  = ["10.0.101.0/24", "10.0.102.0/24"]

 # Database Subnets
  create_database_subnet_group       = true
  create_database_subnet_route_table = true
  database_subnets                   = ["10.0.151.0/24", "10.0.152.0/24"]

  #create_database_nat_gateway_route = true
  #create_database_internet_gateway_route = true

  # NAT Gateways - Outbound Communication
  enable_nat_gateway = true
  single_nat_gateway = true

  # VPC DNS Parameters
  enable_dns_hostnames = true
  enable_dns_support   = true


  public_subnet_tags = var.public_subnet_tags

  private_subnet_tags = var.private_subnet_tags

  database_subnet_tags = var.database_subnet_tags

  tags = var.tags

  vpc_tags = var.vpc_tags
}

安全组模块配置

module "rds_sg" {
  source  = "terraform-aws-modules/security-group/aws"
  version = "5.1.0"

  name        = "rds-sg"
  description = "Security Group for RDS access"
  vpc_id      = module.vpc.vpc_id

  # Ingress Rules
  ingress_rules = ["postgresql-tcp", "openvpn-udp", "openvpn-tcp", "openvpn-https-tcp"]

  # CIDR Blocks for Ingress
  ingress_cidr_blocks = ["0.0.0.0/0", module.vpc.vpc_cidr_block] # Allow access from all IP addresses. Adjust as needed.

  # Egress Rule - all-all open
  egress_rules = ["all-all"]
}

RDS实例模块配置

module "postgres" {
  source                         = "terraform-aws-modules/rds/aws" // Source of the module
  version                        = "5.9.0"                         // Version of the module
  identifier                     = "postg-rds-external-instance"
  instance_use_identifier_prefix = true
  engine                         = "postgres"
  engine_version                 = "14"
  family                         = "postgres14" # DB parameter group
  major_engine_version           = "14"         # DB option group
  instance_class                 = "db.t4g.micro"
  create_db_option_group         = true
  create_db_parameter_group      = true
  allocated_storage              = 5
  db_name                        = "postgdb"
  username                       = "postgadmin"
  password                       = "pS6sdfdsfdsfdsdfs"
  port                           = 5432
  publicly_accessible            = true
  db_subnet_group_name           = module.vpc.database_subnet_group_name
  subnet_ids                     = module.vpc.database_subnets
  vpc_security_group_ids         = [module.rds_sg.security_group_id]
  maintenance_window             = "Mon:00:00-Mon:03:00"
  backup_window                  = "03:00-06:00"
  backup_retention_period        = 0
  storage_encrypted              = true
  skip_final_snapshot            = true
  deletion_protection            = false
}

核心原因

  • 数据库子网缺少公网路由:VPC配置中注释了create_database_internet_gateway_route = true,导致数据库子网的路由表未关联互联网网关(IGW)。即使RDS设置了publicly_accessible = true,无公网路由的子网无法让实例接收公网流量,也无法分配有效公网IP。

解决方案

1. 修正VPC模块的公网路由配置

修改VPC模块代码,启用数据库子网的互联网网关路由:

module "vpc" {
  source  = "terraform-aws-modules/vpc/aws"
  version = "~> 5.0"

  # ... 保留其他原有配置 ...

  # Database Subnets
  create_database_subnet_group       = true
  create_database_subnet_route_table = true
  database_subnets                   = ["10.0.151.0/24", "10.0.152.0/24"]

  # 启用数据库子网的互联网网关路由,允许公网流量进出
  create_database_internet_gateway_route = true
  # create_database_nat_gateway_route = true # 保持注释,公网子网无需NAT网关

  # ... 保留其他原有配置 ...
}

2. 确认RDS公网可访问配置

确保RDS模块中的publicly_accessible = true参数保持启用,该参数会触发AWS为RDS实例分配公网IP地址。

3. 验证安全组配置

当前安全组已允许0.0.0.0/0访问5432端口,配置有效。生产环境建议替换为你的固定公网IP以提升安全性。

4. 重新部署并验证

执行以下Terraform命令更新基础设施:

terraform init
terraform plan
terraform apply

部署完成后,在AWS控制台的RDS实例详情页面,检查连接 & 安全性标签:

  • 确认实例状态为可用
  • 确认端点解析到公网IP地址
  • 重新使用psql命令测试连接

额外检查项

  • 本地网络防火墙是否允许5432端口的出站流量
  • 本地ISP是否未封锁5432端口

内容的提问来源于stack exchange,提问作者endlessCode

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 13:32:52