You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法从外部连接AWS RDS Aurora (MySQL) Serverless集群问题排查

连接Aurora Serverless (v1) MySQL集群时握手超时问题

我通过Terraform创建了RDS Aurora Serverless (v1) MySQL集群,使用账号对应区域的默认VPC,但从外部源尝试连接时出现握手超时。

集群Terraform配置参数

cluster_identifier = "some-cluster-name",
engine = "aurora-mysql",
engine_mode = "serverless",
database_name = "db",
master_username = "********",
master_password = "********",
backup_retention_period = 5,
preferred_backup_window = "07:00-09:00",
skip_final_snapshot = true,
storage_encrypted = true,
scaling_configuration = {
    max_capacity = 4,
    min_capacity = 1,
    seconds_until_auto_pause = 300
},
vpc_security_group_ids = ["${aws_security_group.my_sg_defined_elsewhere.id}"]

安全组规则配置

入站规则

type = "ingress",
from_port = 3306,
to_port = 3306,
protocol = "tcp",
cidr_blocks = ["0.0.0.0/0"],
ipv6_cidr_blocks = ["::/0"],
security_group_id = "${aws_security_group.my_sg_defined_elsewhere.id}"

出站规则

type = "egress",
from_port = 0,
to_port = 0,
protocol = "-1",
cidr_blocks = ["0.0.0.0/0"],
ipv6_cidr_blocks = ["::/0"],
security_group_id = "${aws_security_group.my_sg_defined_elsewhere.id}"

我原本认为默认VPC包含公有子网,只要安全组规则满足MySQL公网访问要求就能正常连接,但使用集群生成的端点和正确凭证连接时,仍出现超时问题。


排查与修复方案

  • 启用集群公网访问:Aurora Serverless集群默认不会分配公网IP,必须在Terraform的aws_rds_cluster资源中添加publicly_accessible = true参数,这是最可能的核心问题。
  • 确认子网公网IP映射:默认VPC的子网虽为公有子网,但需确认子网的map_public_ip_on_launch属性为true,确保集群实例启动时能获取公网IP。
  • 验证安全组绑定:检查AWS控制台的集群详情页,确认vpc_security_group_ids关联的安全组已正确绑定到集群。
  • 检查集群状态:如果集群闲置超过300秒会自动暂停,连接前需先唤醒集群。可通过AWS控制台或CLI命令aws rds describe-db-clusters --db-cluster-identifier some-cluster-name查看集群状态是否为available。
  • 测试端口连通性:使用nc -zv <集群端点> 3306或telnet <集群端点> 3306测试端口是否可达,排查网络层面的阻断。

修正后的集群配置示例

resource "aws_rds_cluster" "aurora_serverless" {
  cluster_identifier      = "some-cluster-name"
  engine                  = "aurora-mysql"
  engine_mode             = "serverless"
  database_name           = "db"
  master_username         = "********"
  master_password         = "********"
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
  storage_encrypted       = true
  publicly_accessible     = true # 新增:启用公网访问
  scaling_configuration {
    max_capacity = 4
    min_capacity = 1
    seconds_until_auto_pause = 300
  }
  vpc_security_group_ids = [aws_security_group.my_sg_defined_elsewhere.id]
}

内容的提问来源于stack exchange,提问作者Dan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 05:20:49