You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Airflow社区Helm Chart无法连接Azure外部PostgreSQL数据库

排查Airflow社区Helm Chart连接Azure PostgreSQL失败的问题

一、先定位核心错误原因

事件显示check-db初始化容器启动后失败,先查看该容器的日志获取具体报错:

kubectl logs airflow-db-migrations-6f86f64cfc-gwhk6 -c check-db

日志会直接告诉你连接失败的根因,比如认证方式不匹配、SSL配置错误等。

二、修正社区Helm Chart的外部数据库配置

社区Chart和官方Chart的数据库参数逻辑存在差异,结合Azure PostgreSQL的强制要求,调整values.yaml配置:

postgresql:  
  enabled: false
externalDatabase:
  type: postgres
  host: database-postgres-db.postgres.database.azure.com
  port: 5432
  database: cool_db
  user: cool_user@database-postgres-db
  password: CoolPassword!1234
  authType: scram-sha-256  # Azure PostgreSQL默认启用该认证,社区Chart必须显式指定
  ssl:
    mode: require  # 社区Chart用ssl字段统一配置SSL,替代官方的properties参数

关键配置说明:

  • authType: scram-sha-256:Azure PostgreSQL默认使用SCRAM认证,社区Chart默认可能用MD5,不指定会直接认证失败。
  • ssl.mode: require:Azure强制要求SSL连接,社区Chart通过该字段自动生成正确的连接参数,无需手动写properties,避免参数冲突。
  • 移除原有的properties: "sslmode=enable":该配置会和ssl.mode重复,导致连接字符串格式错误。

三、补充验证网络连通性

如果配置修正后仍失败,从集群内部测试数据库连通性:

kubectl run -it --rm --image=postgres:14-alpine pg-test -- psql -h database-postgres-db.postgres.database.azure.com -p 5432 -U cool_user@database-postgres-db -d cool_db

输入密码后若能成功连接,说明网络和权限无问题;若失败,重新排查Azure防火墙规则、VNET对等配置。

四、重新部署Chart

清理现有资源后重新安装:

helm uninstall airflow
helm repo update
helm install airflow apache-airflow/airflow -f values.yaml

内容的提问来源于stack exchange,提问作者pajo-po

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 16:37:02