求助:通过CloudFormation配置AWS Aurora Serverless v2公网可访问后无法连接
Let’s walk through targeted fixes and checks based on your CloudFormation configuration to resolve the connection problem:
1. Enable Public Access for the Aurora Cluster
Your RDSCluster resource is missing the critical PubliclyAccessible property. Even if the cluster is deployed to public subnets, Aurora won’t assign a reachable public endpoint unless this setting is explicitly enabled.
Update your RDSCluster Properties section with:
PubliclyAccessible: !If [CreateDevResources, true, false]
2. Fix Security Group Inbound Rules
Your current security group ingress only allows traffic from within the same security group (for internal service-to-service communication). It doesn’t open PostgreSQL’s default port (5432) to your local machine where pgAdmin is running.
Add a dedicated ingress rule for dev environment database traffic:
DBSecurityGroupIngress: Type: "AWS::EC2::SecurityGroupIngress" Condition: CreateDevResources Properties: GroupId: !Ref "InstanceSecurityGroup" IpProtocol: "tcp" FromPort: 5432 ToPort: 5432 CidrIp: YOUR_LOCAL_PUBLIC_IP/32 # Replace with your actual public IP, or use 0.0.0.0/0 for temporary testing (avoid in production)
3. Ensure Public Subnets Auto-Assign Public IPs
Your PublicSubnetA and PublicSubnetB don’t have MapPublicIpOnLaunch enabled. For Aurora’s public endpoint to be reachable, resources in these subnets need automatic public IP assignment. Add this property to both public subnets:
PublicSubnetA: Type: "AWS::EC2::Subnet" Condition: CreateDevResources Properties: # ... existing properties ... MapPublicIpOnLaunch: true PublicSubnetB: Type: "AWS::EC2::Subnet" Condition: CreateDevResources Properties: # ... existing properties ... MapPublicIpOnLaunch: true
4. Verify Network Reachability
After deploying the updated configuration:
- Check the Aurora cluster’s endpoint in the AWS RDS console: it should display a public-facing endpoint (confirm by checking for an associated public IP).
- Test connectivity from your local machine using:
ortelnet <cluster-endpoint> 5432
A timeout means network rules are still blocking traffic; check your local firewall or corporate network restrictions (some block outbound port 5432).nc -zv <cluster-endpoint> 5432
5. Validate Database Credentials and Instance Status
- Confirm both
DBInstance1andDBInstance2show an Available state in the RDS console. - Use the
psqlcommand line tool to get precise error messages:
"Authentication failed" points to incorrect credentials; "connection refused/timeout" means network issues are still unresolved.psql -h <cluster-endpoint> -U ${self:custom.resources.databaseUser} -d ${self:custom.resources.databaseName}
内容的提问来源于stack exchange,提问作者William Estrada

