如何通过AWS CLI/API指定RDS快照恢复的目标VPC?
问题:RDS恢复实例时指定目标VPC的方法
我有两个VPC,一个是默认VPC,另一个专门用于数据库。执行以下AWS CLI命令恢复RDS实例:
aws rds restore-db-instance-from-db-snapshot --db-instance-identifier test --db-snapshot-identifier db-arn --vpc-security-group-ids "foo"
出现如下错误:
An error occurred (InvalidParameterCombination) when calling the RestoreDBInstanceFromDBSnapshot operation: The DB instance and EC2 security group are in different VPCs. The DB instance is in vpc-a and the EC2 security group is in b
查阅AWS官方文档时看到:
对于CLI和API,您需要指定VPC安全组ID。
目前系统总是默认在默认VPC中创建实例,请问如何在API/CLI中指定创建数据库的目标VPC?
解决方法
要指定RDS实例恢复的目标VPC,核心是通过数据库子网组来关联,而非直接指定VPC ID,具体操作如下:
确认/创建目标VPC对应的RDS子网组
如果你还没有为数据库VPC创建RDS子网组,先执行以下命令创建(子网必须属于目标VPC):aws rds create-db-subnet-group --db-subnet-group-name my-db-subnet-group --db-subnet-group-description "子网组:数据库专用VPC" --subnet-ids subnet-xxxx subnet-yyyy替换
subnet-xxxx、subnet-yyyy为目标VPC下的实际子网ID。恢复实例时指定子网组
在原恢复命令中添加--db-subnet-group-name参数,指定刚才创建的子网组名称:aws rds restore-db-instance-from-db-snapshot --db-instance-identifier test --db-snapshot-identifier db-arn --vpc-security-group-ids "foo" --db-subnet-group-name my-db-subnet-group
原理说明
RDS实例的VPC归属由数据库子网组决定,子网组内的所有子网都属于同一个VPC。指定对应目标VPC的子网组后,RDS会自动在该VPC中创建实例,同时要确保你指定的--vpc-security-group-ids也属于这个VPC,否则仍会触发跨VPC的错误。
内容的提问来源于stack exchange,提问作者DariusFontaine
相关产品推荐
相关产品推荐

