私有子网AWS Postgres无VPN且堡垒机受限,如何本地连接?
Connecting to Private Subnet AWS Postgres via Bastion & App Server
Got it, let's figure out how to get your local machine connected to that private Postgres instance. Since you can SSH into your app server through the Bastion, we'll use SSH tunneling to route your Postgres traffic through both nodes—this is the standard approach for accessing private resources in AWS without a VPN. Here are two straightforward methods:
Method 1: Multi-hop SSH Tunnel with ProxyJump (Recommended)
This is the cleanest way if your SSH client supports ProxyJump (most modern versions do, like OpenSSH 7.3+).
- First, simplify your SSH connections by adding this to your local
~/.ssh/configfile. This lets you reference the Bastion and app server by name instead of typing full IPs every time:
Host bastion HostName <your-bastion-public-ip-or-domain> User <bastion-ssh-username> IdentityFile <path-to-your-bastion-private-key.pem> Host app-server HostName <your-app-server-private-ip> User <app-server-ssh-username> IdentityFile <path-to-your-app-server-private-key.pem> ProxyJump bastion
- Next, run this command in your local terminal to establish the port tunnel. We'll forward your local port
5433to the Postgres instance's5432port via the app server:
ssh -L 5433:<postgres-private-ip>:5432 app-server
- Leave this terminal window open (don't close the SSH session!). Now you can connect to Postgres using your local client (like psql, pgAdmin, or your dev tool) with these details:
- Host:
localhost - Port:
5433 - Username:
- Password:
- Host:
Method 2: Manual Two-Step Tunnel (For Older SSH Versions)
If ProxyJump isn't available on your system, you can set up the tunnel in two separate steps:
- First, establish a tunnel from your local machine to the Bastion, forwarding your local port
2222to the app server's SSH port (22):
ssh -L 2222:<app-server-private-ip>:22 <bastion-username>@<bastion-public-ip> -i <bastion-private-key.pem>
- Keep that window open, then open a new terminal. Use the local
2222port to SSH into the app server, and set up the Postgres port forward at the same time:
ssh -L 5433:<postgres-private-ip>:5432 <app-server-username>@localhost -p 2222 -i <app-server-private-key.pem>
- Just like before, connect locally to
localhost:5433with your Postgres credentials once the tunnel is up.
Critical Notes to Ensure This Works
- Security Group Rules: Make sure your Postgres instance's security group allows incoming traffic on port
5432from your app server's private IP address. The app server's security group should also allow incoming SSH traffic from the Bastion's private IP, and the Bastion's security group allows SSH from your local machine's public IP. - Port Availability: If
5433is already in use on your local machine, replace it with any unused port (like5434)—just make sure your client uses the same port when connecting. - Persistent Tunnels: If you want to avoid running the SSH command every time, add
LocalForward 5433 <postgres-private-ip>:5432to theapp-serversection in your~/.ssh/config. Now every time you SSH intoapp-server, the tunnel will be created automatically.
内容的提问来源于stack exchange,提问作者santosh verma
相关产品推荐
相关产品推荐

