You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过私有IP:9000端口连接Azure上的SonarQube实例求助

无法通过私有IP连接Azure上的SonarQube实例(连接超时)

我在Azure上部署了SonarQube实例,尝试通过私有IP+9000端口连接时始终提示连接超时,已做以下排查:

  • 机器防火墙未阻止9000端口入站流量
  • 私有IP地址正确
  • 确认SonarQube使用9000端口
  • 日志中无连接相关错误
  • 重启SonarQube实例无效

使用环境:Linux机器 + Bash命令,附部署用的Terraform代码,求进一步排查方案。

provider "azurerm" {
   features {}
}


locals {
  sonarqube_image_name = "sonarqube:9.9-community"
  sonarqube_container_name = "sonarqube-container"
  postgres_container_name = "postgres-container"
}

resource "azurerm_resource_group" "examplegroup" {
  name     = "example-rg"
  location = "South Central US"
}

resource "azurerm_network_security_group" "nsg-example-sonargroup" {
  name                = "nsg-example-sonargroup"
  location            = azurerm_resource_group.sonargroup.location
  resource_group_name = azurerm_resource_group.sonargroup.name
}

resource "azurerm_virtual_network" "example-sonar-vnet" {
  name                = "example-sonar-vnet"
  location            = azurerm_resource_group.sonargroup.location
  resource_group_name = azurerm_resource_group.sonargroup.name
  address_space       = ["10.0.0.0/16"]
}

resource "azurerm_subnet" "example-sonar-subnet" {
  name                 = "sonar-subnet"
  resource_group_name  = azurerm_resource_group.sonargroup.name
  virtual_network_name = azurerm_virtual_network.example-sonar-vnet.name
  address_prefixes     = ["10.0.0.0/16"] 

  delegation {
    name = "delegation"

    service_delegation {
      name    = "Microsoft.ContainerInstance/containerGroups"
      actions = ["Microsoft.Network/virtualNetworks/subnets/join/action", "Microsoft.Network/virtualNetworks/subnets/prepareNetworkPolicies/action"]
    }
  }
}

resource "azurerm_container_group" "sonarqube" {
  name                = "sonarqube-group"
  location            = azurerm_resource_group.sonargroup.location
  resource_group_name = azurerm_resource_group.sonargroup.name
  ip_address_type     = "Private"
  os_type             = "Linux"
  subnet_ids          = [azurerm_subnet.example-sonar-subnet.id]

  container {
    name   = local.sonarqube_container_name
    image  = local.sonarqube_image_name
    cpu    = 1
    memory = 1.5

    ports {
      port = 9000
    }
    environment_variables = {
      SONARQUBE_JDBC_URL = "jdbc:postgresql://postgres-container:5432/sonarqube_db"
      SONARQUBE_JDBC_USERNAME = "example_user"
      SONARQUBE_JDBC_PASSWORD = "example_password"
    }
  }

  container {
    name   = local.postgres_container_name
    image  = "postgres:11"
    cpu    = 1
    memory = 2
    ports {
      port = 5432
    }
    environment_variables = {
      POSTGRES_DB = "example_db"
      POSTGRES_USER = "example_user"
      POSTGRES_PASSWORD = "example_password"
    }
  }
}

output "private_ip_address" {
  value = azurerm_container_group.sonarqube.ip_address
}
排查及解决建议

一、Terraform配置问题修正

  1. 资源组引用错误:
    NSG、VNet、Subnet、容器组均引用了azurerm_resource_group.sonargroup,但实际定义的资源组是azurerm_resource_group.examplegroup,需统一修改为azurerm_resource_group.examplegroup,否则会导致资源关联失败。

  2. 子网地址前缀冲突:
    子网address_prefixes = ["10.0.0.0/16"]与VNet的address_space = ["10.0.0.0/16"]完全重叠,不符合Azure子网配置规范,建议修改为["10.0.1.0/24"]这类细分网段。

  3. NSG未关联子网且缺少入站规则:
    定义的NSG未绑定到子网,需添加关联资源,并配置允许9000端口入站的规则:

    resource "azurerm_subnet_network_security_group_association" "sonar-subnet-nsg" {
      subnet_id                 = azurerm_subnet.example-sonar-subnet.id
      network_security_group_id = azurerm_network_security_group.nsg-example-sonargroup.id
    }
    
    resource "azurerm_network_security_rule" "allow-sonarqube-9000" {
      name                        = "Allow-SonarQube-9000"
      priority                    = 100
      direction                   = "Inbound"
      access                      = "Allow"
      protocol                    = "Tcp"
      source_port_range           = "*"
      destination_port_range      = "9000"
      source_address_prefix       = "10.0.0.0/16" # 限制为VNet内部IP,更安全
      destination_address_prefix  = "*"
      resource_group_name         = azurerm_resource_group.examplegroup.name
      network_security_group_name = azurerm_network_security_group.nsg-example-sonargroup.name
    }
    
  4. 数据库配置不匹配:
    SonarQube的SONARQUBE_JDBC_URL指定数据库为sonarqube_db,但Postgres的POSTGRES_DB是example_db,两者不一致,需统一为同一个数据库名。

二、运行时排查步骤

  1. 确认SonarQube容器状态:
    执行命令查看容器运行状态:

    az container show --resource-group example-rg --name sonarqube-group --query 'containers[].instanceView.currentState'
    

    若状态异常,查看容器日志:

    az container logs --resource-group example-rg --name sonarqube-group --container-name sonarqube-container
    
  2. 在同VNet机器测试连通性:
    私有IP仅支持同VNet/对等VNet内访问,确保测试机器与SonarQube在同一网络,然后执行:

    nc -zv <SonarQube私有IP> 9000
    # 或用telnet测试
    telnet <SonarQube私有IP> 9000
    
  3. 检查SonarQube监听地址:
    进入容器查看端口监听情况,确保绑定到0.0.0.0而非仅本地回环:

    az container exec --resource-group example-rg --name sonarqube-group --container-name sonarqube-container --command "netstat -tulpn | grep 9000"
    
  4. 验证Postgres连接有效性:
    检查SonarQube是否能正常连接数据库:

    az container exec --resource-group example-rg --name sonarqube-group --container-name sonarqube-container --command "psql -h postgres-container -U example_user -d sonarqube_db"
    

内容的提问来源于stack exchange,提问作者johnny3210

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 01:50:30