You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Composer跨项目私有连接CloudSQL的实现及故障排查

Google Cloud Composer(独立VPC)私有连接共享VPC中CloudSQL的可行性与问题排查

问题描述

我们的场景是:某项目中的Google Cloud Composer使用独立VPC,而CloudSQL数据库部署在另一个项目的共享VPC中。想确认CloudComposer是否能通过私有方式连接CloudSQL,以及具体实现步骤。

更新说明:
已完成CloudComposer所在VPC与共享VPC的VPC对等连接配置,并在CloudComposer的VPC中创建了测试虚拟机,但使用Cloud SQL Auth Proxy连接CloudSQL时失败,报错信息如下:

kshk@test-instance-1:~$ ./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:3307 -credential_file=access-1.json -ip_address_types=PRIVATE &

kshk@test-instance-1:~$ psql -h 127.0.0.1 -p 3307 -U testuser postgres
     2022/11/15 16:06:53 New connection for "mgcp-xxxx-xcxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres"
     2022/11/15 16:06:53 refreshing ephemeral certificate for instance mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres
     2022/11/15 16:06:53 Scheduling refresh of ephemeral certificate in 54m59
     
     2022/11/15 16:09:04 couldn't connect to "mgcp-xxxx-xxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres": dial tcp 10.12.121.5:3307: connect: connection timed out
     psql: error: server closed the connection unexpectedly
             This probably means the server terminated abnormally
             before or while processing the request.

报错翻译:

kshk@test-instance-1:~$ ./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:3307 -credential_file=access-1.json -ip_address_types=PRIVATE &

kshk@test-instance-1:~$ psql -h 127.0.0.1 -p 3307 -U testuser postgres
     2022/11/15 16:06:53 为实例"mgcp-xxxx-xcxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres"建立新连接
     2022/11/15 16:06:53 刷新实例mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres的临时证书
     2022/11/15 16:06:53 计划在54分59秒后刷新临时证书
     
     2022/11/15 16:09:04 无法连接到"mgcp-xxxx-xxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres": dial tcp 10.12.121.5:3307: connect: 连接超时
     psql: error: 服务器意外关闭连接
             这可能意味着服务器在处理请求之前或处理过程中异常终止。

可行性结论

CloudComposer完全可以通过私有方式连接跨项目共享VPC中的CloudSQL,核心依赖VPC对等连接或共享VPC权限配置,结合CloudSQL的私有IP访问策略实现。

当前报错的排查与解决步骤

从报错信息看,证书刷新成功说明认证无问题,连接超时是网络层面的阻断导致,按以下步骤逐一排查:

1. 验证VPC对等连接配置

  • 确认对等连接双向状态均为已激活:在两个项目的VPC对等连接页面检查状态,确保双方都完成了接受操作。
  • 确认CloudComposer VPC与共享VPC的IP地址段无重叠:重叠IP段会引发路由冲突,导致通信失败。
  • 检查路由传播设置:确保CloudComposer VPC的路由表中存在指向共享VPC内CloudSQL私有IP段的路由,反之亦然。

2. 检查CloudSQL私有网络配置

  • 确认CloudSQL实例已启用私有IP,且所属子网为目标共享VPC的子网。
  • 配置CloudSQL访问控制:在实例的「连接」设置中,明确添加CloudComposer VPC的IP段到授权列表(即使配置了VPC对等,CloudSQL仍需手动授权源IP访问)。

3. 排查防火墙规则

  • 共享VPC侧:创建入站防火墙规则,允许来自CloudComposer VPC IP段的TCP流量访问CloudSQL端口(PostgreSQL默认5432)。
  • CloudComposer VPC侧:创建出站防火墙规则,允许流量访问共享VPC内CloudSQL的私有IP段及对应端口(5432)。
  • 测试VM所在子网:确保防火墙允许VM出站到5432端口,以及本地3307端口(用于psql连接代理)。

4. 调整Cloud SQL Auth Proxy命令参数

你的命令中-ip_address_types=PRIVATE参数正确,但需修正以下内容:

  • 确认access-1.json对应的服务账号拥有Cloud SQL Client角色(roles/cloudsql.client),且角色授权范围覆盖目标CloudSQL实例所在项目。
  • 避免混淆代理端口与CloudSQL原生端口,推荐使用默认端口5432,修正后的命令示例:
    ./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:5432 -credential_file=access-1.json -ip_address_types=PRIVATE &
    
    连接命令同步调整:
    psql -h 127.0.0.1 -p 5432 -U testuser postgres
    

5. CloudComposer环境的额外配置

如果测试VM连接正常后,CloudComposer仍无法连接,需补充:

  • 确保Composer环境启用私有IP,且所属VPC与对等连接的VPC一致。
  • 在Composer的DAG或环境变量中,采用Cloud SQL Auth Proxy方式连接,或直接使用私有IP连接(需将Composer节点IP段添加到CloudSQL访问控制列表)。
  • 确认Composer服务账号拥有访问目标CloudSQL实例的权限(Cloud SQL Client角色)。

内容的提问来源于stack exchange,提问作者krisdigitx

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 13:56:04