You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

私有子网AWS Postgres无VPN且堡垒机受限,如何本地连接?

Connecting to Private Subnet AWS Postgres via Bastion & App Server

Got it, let's figure out how to get your local machine connected to that private Postgres instance. Since you can SSH into your app server through the Bastion, we'll use SSH tunneling to route your Postgres traffic through both nodes—this is the standard approach for accessing private resources in AWS without a VPN. Here are two straightforward methods:

This is the cleanest way if your SSH client supports ProxyJump (most modern versions do, like OpenSSH 7.3+).

  1. First, simplify your SSH connections by adding this to your local ~/.ssh/config file. This lets you reference the Bastion and app server by name instead of typing full IPs every time:
Host bastion
  HostName <your-bastion-public-ip-or-domain>
  User <bastion-ssh-username>
  IdentityFile <path-to-your-bastion-private-key.pem>

Host app-server
  HostName <your-app-server-private-ip>
  User <app-server-ssh-username>
  IdentityFile <path-to-your-app-server-private-key.pem>
  ProxyJump bastion
  1. Next, run this command in your local terminal to establish the port tunnel. We'll forward your local port 5433 to the Postgres instance's 5432 port via the app server:
ssh -L 5433:<postgres-private-ip>:5432 app-server
  1. Leave this terminal window open (don't close the SSH session!). Now you can connect to Postgres using your local client (like psql, pgAdmin, or your dev tool) with these details:
    • Host: localhost
    • Port: 5433
    • Username:
    • Password:

Method 2: Manual Two-Step Tunnel (For Older SSH Versions)

If ProxyJump isn't available on your system, you can set up the tunnel in two separate steps:

  1. First, establish a tunnel from your local machine to the Bastion, forwarding your local port 2222 to the app server's SSH port (22):
ssh -L 2222:<app-server-private-ip>:22 <bastion-username>@<bastion-public-ip> -i <bastion-private-key.pem>
  1. Keep that window open, then open a new terminal. Use the local 2222 port to SSH into the app server, and set up the Postgres port forward at the same time:
ssh -L 5433:<postgres-private-ip>:5432 <app-server-username>@localhost -p 2222 -i <app-server-private-key.pem>
  1. Just like before, connect locally to localhost:5433 with your Postgres credentials once the tunnel is up.

Critical Notes to Ensure This Works

  • Security Group Rules: Make sure your Postgres instance's security group allows incoming traffic on port 5432 from your app server's private IP address. The app server's security group should also allow incoming SSH traffic from the Bastion's private IP, and the Bastion's security group allows SSH from your local machine's public IP.
  • Port Availability: If 5433 is already in use on your local machine, replace it with any unused port (like 5434)—just make sure your client uses the same port when connecting.
  • Persistent Tunnels: If you want to avoid running the SSH command every time, add LocalForward 5433 <postgres-private-ip>:5432 to the app-server section in your ~/.ssh/config. Now every time you SSH into app-server, the tunnel will be created automatically.

内容的提问来源于stack exchange,提问作者santosh verma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 22:07:42