Oracle云跨VCN连接K8s与同基础设施数据库(非公网)示例及资源求助
Got it, let's walk through how to set up private connectivity between your OCI Kubernetes cluster and a database in a separate VCN—no public internet needed. I’ve done this a few times, so here’s a step-by-step breakdown with concrete config examples:
First, make sure you have these in place:
- Both your OKE cluster and database are in the same OCI region (VCN peering only works within a region)
- Your database is using a private subnet (no public IP attached)
- You have admin-level permissions to modify VCNs, security lists, and Kubernetes resources
This is the core of private cross-VCN connectivity. Here's how to configure it:
- Create Local Peering Gateways (LPGs)
- Go to the OCI Console → Networking → Virtual Cloud Networks
- For your OKE cluster's VCN: Create an LPG (give it a name like
oke-vcn-lpg) - Repeat for your database's VCN: Create another LPG (e.g.,
db-vcn-lpg)
- Establish the Peering Connection
- In your OKE VCN's LPG settings, click "Establish Peering Connection"
- Enter the OCID of the database VCN's LPG, then submit
- Switch to the database VCN's LPG and accept the peering request
- Update Route Tables
- For the OKE cluster's subnet route table:
Add a route rule where:- Target CIDR: The full CIDR block of your database VCN (e.g.,
10.1.0.0/16) - Next hop type:
Local Peering Gateway - Next hop: Select the OKE VCN's LPG
- Target CIDR: The full CIDR block of your database VCN (e.g.,
- For the database's subnet route table:
Add a reverse route rule where:- Target CIDR: The full CIDR block of your OKE VCN (e.g.,
10.2.0.0/16) - Next hop type:
Local Peering Gateway - Next hop: Select the database VCN's LPG
- Target CIDR: The full CIDR block of your OKE VCN (e.g.,
- For the OKE cluster's subnet route table:
You need to allow traffic between the two VCNs on the database port (default is 1521 for Oracle):
- OKE Cluster Subnet Security List
Add an outbound rule:- Source: Database VCN's CIDR
- Destination Port Range:
1521 - Protocol:
TCP
- Database Subnet Security List (or NSG)
Add an inbound rule:- Source: OKE VCN's CIDR
- Destination Port Range:
1521 - Protocol:
TCP
Note: If your database uses a Network Security Group (NSG), update that instead of the subnet security list.
Now let's set up your K8s workload to connect to the private database:
4.1 Store DB Credentials in a Kubernetes Secret
First, encode your DB username and password with base64 (run these commands locally):
echo -n "your-db-username" | base64 echo -n "your-db-password" | base64
Then create a secret YAML file (db-secret.yaml):
apiVersion: v1 kind: Secret metadata: name: db-credentials type: Opaque data: db-user: <base64-encoded-username> db-password: <base64-encoded-password>
Apply it to your cluster:
kubectl apply -f db-secret.yaml
4.2 Deploy an Application with Private DB Connection
Create a deployment YAML (db-app-deployment.yaml) that references the private DB endpoint:
apiVersion: apps/v1 kind: Deployment metadata: name: db-connected-app spec: replicas: 1 selector: matchLabels: app: db-app template: metadata: labels: app: db-app spec: containers: - name: app-container image: your-app-image:latest # Replace with your app's image env: - name: DB_HOST value: "private-your-db-name.your-db-subnet.region.oraclecloud.com" # Use the DB's private FQDN - name: DB_PORT value: "1521" - name: DB_SERVICE_NAME value: "your_db_service_name" # Get this from your DB console - name: DB_USER valueFrom: secretKeyRef: name: db-credentials key: db-user - name: DB_PASSWORD valueFrom: secretKeyRef: name: db-credentials key: db-password
Apply the deployment:
kubectl apply -f db-app-deployment.yaml
4.3 Verify the Connection
Test the connectivity by exec'ing into your pod:
kubectl exec -it $(kubectl get pods -l app=db-app -o jsonpath='{.items[0].metadata.name}') -- bash
Inside the pod, use sqlplus (or your app's testing tool) to confirm the connection:
sqlplus $(echo $DB_USER)/$(echo $DB_PASSWORD)@//$(echo $DB_HOST):$(echo $DB_PORT)/$(echo $DB_SERVICE_NAME)
If you get a SQL prompt, the private connection is working!
- For Autonomous Databases: Make sure you've enabled Private Endpoint in the DB's network settings (no public access allowed)
- Double-check route tables: Ensure all OKE node subnets are using the updated route table with the peering rule
- Troubleshoot with VCN Flow Logs: If connections fail, enable flow logs on both subnets to track where packets are being dropped
- Avoid hardcoding: Always use Kubernetes Secrets or OCI Vault for sensitive credentials instead of plain text
内容的提问来源于stack exchange,提问作者Thomas Seehofchen

