无法通过私有IP:9000端口连接Azure上的SonarQube实例求助
我在Azure上部署了SonarQube实例,尝试通过私有IP+9000端口连接时始终提示连接超时,已做以下排查:
- 机器防火墙未阻止9000端口入站流量
- 私有IP地址正确
- 确认SonarQube使用9000端口
- 日志中无连接相关错误
- 重启SonarQube实例无效
使用环境:Linux机器 + Bash命令,附部署用的Terraform代码,求进一步排查方案。
provider "azurerm" { features {} } locals { sonarqube_image_name = "sonarqube:9.9-community" sonarqube_container_name = "sonarqube-container" postgres_container_name = "postgres-container" } resource "azurerm_resource_group" "examplegroup" { name = "example-rg" location = "South Central US" } resource "azurerm_network_security_group" "nsg-example-sonargroup" { name = "nsg-example-sonargroup" location = azurerm_resource_group.sonargroup.location resource_group_name = azurerm_resource_group.sonargroup.name } resource "azurerm_virtual_network" "example-sonar-vnet" { name = "example-sonar-vnet" location = azurerm_resource_group.sonargroup.location resource_group_name = azurerm_resource_group.sonargroup.name address_space = ["10.0.0.0/16"] } resource "azurerm_subnet" "example-sonar-subnet" { name = "sonar-subnet" resource_group_name = azurerm_resource_group.sonargroup.name virtual_network_name = azurerm_virtual_network.example-sonar-vnet.name address_prefixes = ["10.0.0.0/16"] delegation { name = "delegation" service_delegation { name = "Microsoft.ContainerInstance/containerGroups" actions = ["Microsoft.Network/virtualNetworks/subnets/join/action", "Microsoft.Network/virtualNetworks/subnets/prepareNetworkPolicies/action"] } } } resource "azurerm_container_group" "sonarqube" { name = "sonarqube-group" location = azurerm_resource_group.sonargroup.location resource_group_name = azurerm_resource_group.sonargroup.name ip_address_type = "Private" os_type = "Linux" subnet_ids = [azurerm_subnet.example-sonar-subnet.id] container { name = local.sonarqube_container_name image = local.sonarqube_image_name cpu = 1 memory = 1.5 ports { port = 9000 } environment_variables = { SONARQUBE_JDBC_URL = "jdbc:postgresql://postgres-container:5432/sonarqube_db" SONARQUBE_JDBC_USERNAME = "example_user" SONARQUBE_JDBC_PASSWORD = "example_password" } } container { name = local.postgres_container_name image = "postgres:11" cpu = 1 memory = 2 ports { port = 5432 } environment_variables = { POSTGRES_DB = "example_db" POSTGRES_USER = "example_user" POSTGRES_PASSWORD = "example_password" } } } output "private_ip_address" { value = azurerm_container_group.sonarqube.ip_address }
一、Terraform配置问题修正
资源组引用错误:
NSG、VNet、Subnet、容器组均引用了azurerm_resource_group.sonargroup,但实际定义的资源组是azurerm_resource_group.examplegroup,需统一修改为azurerm_resource_group.examplegroup,否则会导致资源关联失败。子网地址前缀冲突:
子网address_prefixes = ["10.0.0.0/16"]与VNet的address_space = ["10.0.0.0/16"]完全重叠,不符合Azure子网配置规范,建议修改为["10.0.1.0/24"]这类细分网段。NSG未关联子网且缺少入站规则:
定义的NSG未绑定到子网,需添加关联资源,并配置允许9000端口入站的规则:resource "azurerm_subnet_network_security_group_association" "sonar-subnet-nsg" { subnet_id = azurerm_subnet.example-sonar-subnet.id network_security_group_id = azurerm_network_security_group.nsg-example-sonargroup.id } resource "azurerm_network_security_rule" "allow-sonarqube-9000" { name = "Allow-SonarQube-9000" priority = 100 direction = "Inbound" access = "Allow" protocol = "Tcp" source_port_range = "*" destination_port_range = "9000" source_address_prefix = "10.0.0.0/16" # 限制为VNet内部IP,更安全 destination_address_prefix = "*" resource_group_name = azurerm_resource_group.examplegroup.name network_security_group_name = azurerm_network_security_group.nsg-example-sonargroup.name }数据库配置不匹配:
SonarQube的SONARQUBE_JDBC_URL指定数据库为sonarqube_db,但Postgres的POSTGRES_DB是example_db,两者不一致,需统一为同一个数据库名。
二、运行时排查步骤
确认SonarQube容器状态:
执行命令查看容器运行状态:az container show --resource-group example-rg --name sonarqube-group --query 'containers[].instanceView.currentState'若状态异常,查看容器日志:
az container logs --resource-group example-rg --name sonarqube-group --container-name sonarqube-container在同VNet机器测试连通性:
私有IP仅支持同VNet/对等VNet内访问,确保测试机器与SonarQube在同一网络,然后执行:nc -zv <SonarQube私有IP> 9000 # 或用telnet测试 telnet <SonarQube私有IP> 9000检查SonarQube监听地址:
进入容器查看端口监听情况,确保绑定到0.0.0.0而非仅本地回环:az container exec --resource-group example-rg --name sonarqube-group --container-name sonarqube-container --command "netstat -tulpn | grep 9000"验证Postgres连接有效性:
检查SonarQube是否能正常连接数据库:az container exec --resource-group example-rg --name sonarqube-group --container-name sonarqube-container --command "psql -h postgres-container -U example_user -d sonarqube_db"
内容的提问来源于stack exchange,提问作者johnny3210

