You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将AWS账户A中的Redis缓存跨区域、跨AWS账户连接至多台EC2实例

How to Connect AWS ElastiCache Redis Across Regions & AWS Accounts

Great question! Let's break down how to connect your AWS ElastiCache Redis instance (hosted in Account A, specific region) to EC2 instances in other AWS accounts and regions. Network connectivity is the core here, so I'll walk you through the most reliable approaches step by step.


1. Cross-Account (Same Region) Connection

VPC Peering is the go-to solution for same-region cross-account access—it’s low-cost, straightforward, and ideal for 1-to-1 VPC connections.

  • Step 1: Create a VPC Peering Connection

    • In Account A’s VPC Console, initiate a peering request. Enter the target account ID and the VPC ID where your target EC2 instances live.
    • Switch to the target AWS account, navigate to the VPC Peering section, and accept the incoming request.
  • Step 2: Update Route Tables

    • In Account A: Edit the route table associated with your Redis instance’s subnet. Add a route for the target account’s VPC CIDR range, with the peering connection ID as the next hop.
    • In the target account: Edit the route table for your EC2 subnet. Add a route for the Redis instance’s subnet CIDR range, with the peering connection ID as the next hop.
  • Step 3: Adjust Security Groups

    • For your Redis instance’s security group: Add an inbound rule allowing traffic on Redis port (default: 6379 for unencrypted, 6380 for encrypted) from the target EC2 instances’ security group (or their subnet CIDR).
    • For the target EC2 instances’ security group: Add an outbound rule allowing traffic to the Redis port on the Redis instance’s subnet CIDR.
  • Step 4: Test Connectivity

    • SSH into your target EC2 instance and run: redis-cli -h <redis-primary-endpoint> -p <port> to verify the connection.

2. Cross-Region Connection

Cross-region access requires more robust network setup—here are the top options depending on your scale and latency needs:

Option 1: AWS Transit Gateway (Scalable for Multi-Account/Multi-Region)

If you need to connect multiple accounts and regions, Transit Gateway (TGW) is the most scalable choice—it acts as a central hub for all your VPCs.

  • Step 1: Create & Share a Transit Gateway

    • In Account A (or a dedicated shared account), create a Transit Gateway. Enable "Cross-region access" during setup.
    • Use AWS Resource Access Manager (RAM) to share the TGW with all target AWS accounts and regions you need access to.
  • Step 2: Attach VPCs to the Transit Gateway

    • In Account A: Attach the VPC hosting your Redis instance to the TGW.
    • In each target account/region: Attach the VPC with your EC2 instances to the same TGW.
  • Step 3: Update Route Tables

    • For every attached VPC’s route table, add routes pointing to the CIDR ranges of all other connected VPCs, with the TGW as the next hop.
  • Step 4: Secure the Connection

    • Adjust security groups and Network Access Control Lists (NACLs) the same way as the cross-account scenario—ensure Redis allows inbound traffic from target EC2s, and EC2s allow outbound to Redis.

Option 2: Cross-Region VPC Peering (1-to-1 Scenarios)

If you only need to connect two regions (Account A’s region + one target region), cross-region VPC peering works, but note it doesn’t support transit traffic (you can’t chain peerings).

  • Follow the same steps as same-region peering, but select the target region when initiating the peering request.
  • Update route tables and security groups to include the cross-region CIDR ranges.

Option 3: AWS Global Accelerator (Low-Latency Access)

For low-latency cross-region access, Global Accelerator provides static IPs and routes traffic through AWS’s global network to reduce latency.

  • Step 1: Set Up a Network Load Balancer (NLB)
    • In Account A’s Redis region, create an NLB in the same VPC as Redis. Configure a target group pointing to your Redis instance’s endpoint and port.
  • Step 2: Create a Global Accelerator
    • Create a Global Accelerator, add the NLB as an endpoint group in your Redis region.
  • Step 3: Grant Access
    • Use RAM to share the accelerator with target accounts, or update Redis’s security group to allow traffic from the target EC2 instances’ CIDR.
  • Step 4: Connect
    • Use the static IP provided by Global Accelerator in your redis-cli command: redis-cli -h <accelerator-static-ip> -p <port>

3. Key Additional Checks

  • Encryption: If your Redis uses in-transit encryption, test with redis-cli --tls -h <endpoint> -p <port> to ensure SSL connectivity.
  • IAM Authentication: If you’ve enabled IAM auth for Redis, your target EC2 instances need an IAM role with the elasticache:Connect permission. Generate an auth token using AWS CLI (aws elasticache generate-auth-token --user-id <user-id> --region <region>) and use it to connect.
  • Read Replicas: For heavy cross-region read traffic, consider creating a read replica of your Redis instance in the target region—this reduces latency and offloads traffic from the primary.
  • NACLs: Don’t forget NACLs are stateless—ensure both inbound and outbound rules allow Redis port traffic between the relevant subnets.

内容的提问来源于stack exchange,提问作者krishnakumar Balasubramaniam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 15:48:13