Google Cloud Composer跨项目私有连接CloudSQL的实现及故障排查
Google Cloud Composer(独立VPC)私有连接共享VPC中CloudSQL的可行性与问题排查
问题描述
我们的场景是:某项目中的Google Cloud Composer使用独立VPC,而CloudSQL数据库部署在另一个项目的共享VPC中。想确认CloudComposer是否能通过私有方式连接CloudSQL,以及具体实现步骤。
更新说明:
已完成CloudComposer所在VPC与共享VPC的VPC对等连接配置,并在CloudComposer的VPC中创建了测试虚拟机,但使用Cloud SQL Auth Proxy连接CloudSQL时失败,报错信息如下:kshk@test-instance-1:~$ ./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:3307 -credential_file=access-1.json -ip_address_types=PRIVATE & kshk@test-instance-1:~$ psql -h 127.0.0.1 -p 3307 -U testuser postgres 2022/11/15 16:06:53 New connection for "mgcp-xxxx-xcxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres" 2022/11/15 16:06:53 refreshing ephemeral certificate for instance mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres 2022/11/15 16:06:53 Scheduling refresh of ephemeral certificate in 54m59 2022/11/15 16:09:04 couldn't connect to "mgcp-xxxx-xxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres": dial tcp 10.12.121.5:3307: connect: connection timed out psql: error: server closed the connection unexpectedly This probably means the server terminated abnormally before or while processing the request.报错翻译:
kshk@test-instance-1:~$ ./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:3307 -credential_file=access-1.json -ip_address_types=PRIVATE & kshk@test-instance-1:~$ psql -h 127.0.0.1 -p 3307 -U testuser postgres 2022/11/15 16:06:53 为实例"mgcp-xxxx-xcxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres"建立新连接 2022/11/15 16:06:53 刷新实例mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres的临时证书 2022/11/15 16:06:53 计划在54分59秒后刷新临时证书 2022/11/15 16:09:04 无法连接到"mgcp-xxxx-xxx-pay-svc-sbx:europe-west2:xxxxx-sbx-postgres": dial tcp 10.12.121.5:3307: connect: 连接超时 psql: error: 服务器意外关闭连接 这可能意味着服务器在处理请求之前或处理过程中异常终止。
可行性结论
CloudComposer完全可以通过私有方式连接跨项目共享VPC中的CloudSQL,核心依赖VPC对等连接或共享VPC权限配置,结合CloudSQL的私有IP访问策略实现。
当前报错的排查与解决步骤
从报错信息看,证书刷新成功说明认证无问题,连接超时是网络层面的阻断导致,按以下步骤逐一排查:
1. 验证VPC对等连接配置
- 确认对等连接双向状态均为已激活:在两个项目的VPC对等连接页面检查状态,确保双方都完成了接受操作。
- 确认CloudComposer VPC与共享VPC的IP地址段无重叠:重叠IP段会引发路由冲突,导致通信失败。
- 检查路由传播设置:确保CloudComposer VPC的路由表中存在指向共享VPC内CloudSQL私有IP段的路由,反之亦然。
2. 检查CloudSQL私有网络配置
- 确认CloudSQL实例已启用私有IP,且所属子网为目标共享VPC的子网。
- 配置CloudSQL访问控制:在实例的「连接」设置中,明确添加CloudComposer VPC的IP段到授权列表(即使配置了VPC对等,CloudSQL仍需手动授权源IP访问)。
3. 排查防火墙规则
- 共享VPC侧:创建入站防火墙规则,允许来自CloudComposer VPC IP段的TCP流量访问CloudSQL端口(PostgreSQL默认5432)。
- CloudComposer VPC侧:创建出站防火墙规则,允许流量访问共享VPC内CloudSQL的私有IP段及对应端口(5432)。
- 测试VM所在子网:确保防火墙允许VM出站到5432端口,以及本地3307端口(用于psql连接代理)。
4. 调整Cloud SQL Auth Proxy命令参数
你的命令中-ip_address_types=PRIVATE参数正确,但需修正以下内容:
- 确认
access-1.json对应的服务账号拥有Cloud SQL Client角色(roles/cloudsql.client),且角色授权范围覆盖目标CloudSQL实例所在项目。 - 避免混淆代理端口与CloudSQL原生端口,推荐使用默认端口5432,修正后的命令示例:
连接命令同步调整:./cloud_sql_proxy -instances=mgcp-xxxx-xxxx-pay-svc-sbx:europe-west2:xxxx-sbx-postgres=tcp:5432 -credential_file=access-1.json -ip_address_types=PRIVATE &psql -h 127.0.0.1 -p 5432 -U testuser postgres
5. CloudComposer环境的额外配置
如果测试VM连接正常后,CloudComposer仍无法连接,需补充:
- 确保Composer环境启用私有IP,且所属VPC与对等连接的VPC一致。
- 在Composer的DAG或环境变量中,采用Cloud SQL Auth Proxy方式连接,或直接使用私有IP连接(需将Composer节点IP段添加到CloudSQL访问控制列表)。
- 确认Composer服务账号拥有访问目标CloudSQL实例的权限(Cloud SQL Client角色)。
内容的提问来源于stack exchange,提问作者krisdigitx
相关产品推荐
相关产品推荐

