You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Oracle云跨VCN连接K8s与同基础设施数据库(非公网)示例及资源求助

Got it, let's walk through how to set up private connectivity between your OCI Kubernetes cluster and a database in a separate VCN—no public internet needed. I’ve done this a few times, so here’s a step-by-step breakdown with concrete config examples:

1. Prerequisites

First, make sure you have these in place:

  • Both your OKE cluster and database are in the same OCI region (VCN peering only works within a region)
  • Your database is using a private subnet (no public IP attached)
  • You have admin-level permissions to modify VCNs, security lists, and Kubernetes resources
2. Set Up VCN Local Peering

This is the core of private cross-VCN connectivity. Here's how to configure it:

  • Create Local Peering Gateways (LPGs)
    • Go to the OCI Console → Networking → Virtual Cloud Networks
    • For your OKE cluster's VCN: Create an LPG (give it a name like oke-vcn-lpg)
    • Repeat for your database's VCN: Create another LPG (e.g., db-vcn-lpg)
  • Establish the Peering Connection
    • In your OKE VCN's LPG settings, click "Establish Peering Connection"
    • Enter the OCID of the database VCN's LPG, then submit
    • Switch to the database VCN's LPG and accept the peering request
  • Update Route Tables
    • For the OKE cluster's subnet route table:
      Add a route rule where:
      • Target CIDR: The full CIDR block of your database VCN (e.g., 10.1.0.0/16)
      • Next hop type: Local Peering Gateway
      • Next hop: Select the OKE VCN's LPG
    • For the database's subnet route table:
      Add a reverse route rule where:
      • Target CIDR: The full CIDR block of your OKE VCN (e.g., 10.2.0.0/16)
      • Next hop type: Local Peering Gateway
      • Next hop: Select the database VCN's LPG
3. Update Security Rules

You need to allow traffic between the two VCNs on the database port (default is 1521 for Oracle):

  • OKE Cluster Subnet Security List
    Add an outbound rule:
    • Source: Database VCN's CIDR
    • Destination Port Range: 1521
    • Protocol: TCP
  • Database Subnet Security List (or NSG)
    Add an inbound rule:
    • Source: OKE VCN's CIDR
    • Destination Port Range: 1521
    • Protocol: TCP
      Note: If your database uses a Network Security Group (NSG), update that instead of the subnet security list.
4. Configure Kubernetes for Private DB Access

Now let's set up your K8s workload to connect to the private database:

4.1 Store DB Credentials in a Kubernetes Secret

First, encode your DB username and password with base64 (run these commands locally):

echo -n "your-db-username" | base64
echo -n "your-db-password" | base64

Then create a secret YAML file (db-secret.yaml):

apiVersion: v1
kind: Secret
metadata:
  name: db-credentials
type: Opaque
data:
  db-user: <base64-encoded-username>
  db-password: <base64-encoded-password>

Apply it to your cluster:

kubectl apply -f db-secret.yaml

4.2 Deploy an Application with Private DB Connection

Create a deployment YAML (db-app-deployment.yaml) that references the private DB endpoint:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: db-connected-app
spec:
  replicas: 1
  selector:
    matchLabels:
      app: db-app
  template:
    metadata:
      labels:
        app: db-app
    spec:
      containers:
      - name: app-container
        image: your-app-image:latest # Replace with your app's image
        env:
        - name: DB_HOST
          value: "private-your-db-name.your-db-subnet.region.oraclecloud.com" # Use the DB's private FQDN
        - name: DB_PORT
          value: "1521"
        - name: DB_SERVICE_NAME
          value: "your_db_service_name" # Get this from your DB console
        - name: DB_USER
          valueFrom:
            secretKeyRef:
              name: db-credentials
              key: db-user
        - name: DB_PASSWORD
          valueFrom:
            secretKeyRef:
              name: db-credentials
              key: db-password

Apply the deployment:

kubectl apply -f db-app-deployment.yaml

4.3 Verify the Connection

Test the connectivity by exec'ing into your pod:

kubectl exec -it $(kubectl get pods -l app=db-app -o jsonpath='{.items[0].metadata.name}') -- bash

Inside the pod, use sqlplus (or your app's testing tool) to confirm the connection:

sqlplus $(echo $DB_USER)/$(echo $DB_PASSWORD)@//$(echo $DB_HOST):$(echo $DB_PORT)/$(echo $DB_SERVICE_NAME)

If you get a SQL prompt, the private connection is working!

5. Pro Tips
  • For Autonomous Databases: Make sure you've enabled Private Endpoint in the DB's network settings (no public access allowed)
  • Double-check route tables: Ensure all OKE node subnets are using the updated route table with the peering rule
  • Troubleshoot with VCN Flow Logs: If connections fail, enable flow logs on both subnets to track where packets are being dropped
  • Avoid hardcoding: Always use Kubernetes Secrets or OCI Vault for sensitive credentials instead of plain text

内容的提问来源于stack exchange,提问作者Thomas Seehofchen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 09:37:51