无法通过Google虚拟机(反向SSH)将PostgreSQL暴露至云端
反向SSH隧道暴露树莓派PostgreSQL至Google云虚拟机失败排查
问题背景
尝试通过Google云虚拟机的反向SSH隧道,将树莓派上运行的PostgreSQL暴露到公网,但未能成功。
已执行步骤
Google云虚拟机端
- 添加标签为
allow-postgresql的防火墙规则 - 为VM实例的网络标签添加
allow-postgresql - 重启虚拟机
树莓派端
- 安装并运行PostgreSQL
- 生成SSH密钥
- 将公钥添加至Google虚拟机的SSH密钥列表
- 执行反向隧道命令:
ssh -f -N -R 5432:localhost:5432 $google_vm_ip
测试结果
树莓派本地测试
执行nc -zv localhost 5432,输出:Connection to localhost 5432 port [tcp/postgresql] succeeded!
Google云虚拟机SSH内测试
- 执行
nc -zv localhost 5432,输出:Connection to localhost 5432 port [tcp/postgresql] succeeded! - 执行
nc -zv domain.com 5432,输出:nc: connect to domain.com port 5432 (tcp) failed: Connection refused - 执行
nc -zv <public_ip_of_vm> 5432,输出:nc: connect to <public_ip_of_vm> port 5432 (tcp) failed: Connection refused
可见反向隧道在VM本地可访问,但公网无法连接。
更新测试记录
| 树莓派执行的命令 | Google虚拟机执行的命令 | 结果 |
|---|---|---|
| 无隧道 | nc -zv localhost 5432 | nc: connect to localhost 5432 port (tcp) failed: Connection refused |
ssh -N -R 5432:localhost:5432 <remote_public_ip> | nc -zv localhost 5432 | nc: connection to localhost port 5432 (tcp) succeeded! |
nc -zv <remote_private_ip> 5432 | nc: connect to <remote_private_ip> 5432 port (tcp) failed: Connection refused | |
nc -zv <remote_public_ip> 5432 | nc: connect to <remote_public_ip> 5432 port (tcp) failed: Connection refused | |
ssh -N -R 5432:<remote_private_ip>:5432 <remote_public_ip> | nc -zv localhost 5432 | nc: connection to localhost port 5432 (tcp) succeeded! |
nc -zv <remote_private_ip> 5432 | nc: connect to <remote_private_ip> 5432 port (tcp) failed: Connection refused | |
nc -zv <remote_public_ip> 5432 | nc: connect to <remote_public_ip> 5432 port (tcp) failed: Connection refused |
请求帮助
不清楚遗漏了什么配置,求排查思路。
内容的提问来源于stack exchange,提问作者Gowtham Shanmugaraj
相关产品推荐
相关产品推荐

