You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VPC内AWS Lambda无法连接Amazon DocDB等资源故障排查

VPC内Lambda无法访问Amazon DocDB故障排查

在VPC内部署了用于访问Amazon DocDB的Lambda函数,但该函数无法访问VPC内任何资源,查阅多日官方配置指南仍未解决问题。已按照官方Lambda VPC配置指南逐一核对所有VPC配置项,仍未定位故障。

该Lambda在创建时已完成VPC关联配置。
现整理相关配置、代码、报错信息如下,求Lambda配置相关的排查建议。

函数业务代码

def access_mongodb(event, context):
    url = event.get('url')

    if url:
        db = event.get('db')
        coll = event.get('collection')
        query = event.get('query')
        limit = int(event.get('limit'))

        try:
            with Mongo(url=url, db=db) as conn:
                logger.info('Lambda Start query with Mongo')
                for row in conn[coll].find(query).limit(limit):
                    logger.info(f'got row => {json.dumps(row, default=str)}')
        except Exception as e:
            logger.error(f'Got exception {e}')

    else:
        logger.info('Lambda End with out Mongo')

报错信息

Got exception No servers found yet, Timeout: 2.0s, Topology Description: <TopologyDescription id: 62b5186720247fb7d69a0765, topology_type: Single, servers: [<ServerDescription ('docdb-test.xxxx-southeast-1.docdb.amazonaws.com', 27017) server_type: Unknown, rtt: None>]>

相关配置信息

  • Lambda函数配置
    执行aws lambda get-function-configuration --function-name hello_py3返回结果:
{
    "FunctionName": "hello_py3",
    "FunctionArn": "arn:aws:lambda:ap-southeast-1:592017647781:function:hello_py3",
    "Runtime": "python3.9",
    "Role": "arn:aws:iam::592017647781:role/service-role/hello_py3-role-xh39m23g",
    "Handler": "lambda_function.lambda_handler",
    "CodeSize": 5701329,
    "Description": "",
    "Timeout": 10,
    "MemorySize": 128,
    "LastModified": "2022-06-24T01:26:48.000+0000",
    "CodeSha256": "VLwda8fP2DM62/y4Ouy9/U3KpzvfSRWoH7ocCwl1G6g=",
    "Version": "$LATEST",
    "VpcConfig": {
        "SubnetIds": [
            "subnet-08dacd9b6970624aa",
            "subnet-09f80e8227735f6cf",
            "subnet-028392620db2f9753"
        ],
        "SecurityGroupIds": [
            "sg-0002ee69773ca6f9d"
        ],
        "VpcId": "vpc-0eee2636f691ad96b"
    },
    "TracingConfig": {
        "Mode": "PassThrough"
    },
    "RevisionId": "55af10eb-f777-4ba9-aea5-05a010ce7637",
    "State": "Active",
    "LastUpdateStatus": "Successful",
    "PackageType": "Zip",
    "Architectures": [
        "x86_64"
    ],
    "EphemeralStorage": {
        "Size": 512
    }
}
  • Lambda执行角色关联策略
    执行aws iam list-attached-role-policies --role-name hello_py3-role-xh39m23g返回结果:
{
    "AttachedPolicies": [
        {
            "PolicyName": "AWSLambdaVPCAccessExecutionRole-2400d95b-c83c-4fce-8e12-b1a8c5c4b503",
            "PolicyArn": "arn:aws:iam::592017647781:policy/service-role/AWSLambdaVPCAccessExecutionRole-2400d95b-c83c-4fce-8e12-b1a8c5c4b503"
        },
        {
            "PolicyName": "AWSLambdaBasicExecutionRole-a8dac45b-b9f1-4eab-8170-2c9b9f9358ce",
            "PolicyArn": "arn:aws:iam::592017647781:policy/service-role/AWSLambdaBasicExecutionRole-a8dac45b-b9f1-4eab-8170-2c9b9f9358ce"
        }
    ]
}
  • 关联VPC信息
    执行aws ec2 describe-vpcs --vpc-ids vpc-0eee2636f691ad96b返回结果:
{
    "Vpcs": [
        {
            "CidrBlock": "172.31.0.0/16",
            "DhcpOptionsId": "dopt-0b9edd5b6deafa0db",
            "State": "available",
            "VpcId": "vpc-0eee2636f691ad96b",
            "OwnerId": "592017647781",
            "InstanceTenancy": "default",
            "CidrBlockAssociationSet": [
                {
                    "AssociationId": "vpc-cidr-assoc-0200675b36f061104",
                    "CidrBlock": "172.31.0.0/16",
                    "CidrBlockState": {
                        "State": "associated"
                    }
                }
            ],
            "IsDefault": true
        }
    ]
}
  • 关联安全组信息
    执行aws ec2 describe-security-groups --group-ids sg-0002ee69773ca6f9d返回结果:
{
    "SecurityGroups": [
        {
            "Description": "default VPC security group",
            "GroupName": "default",
            "IpPermissions": [
                {
                    "FromPort": 80,
                    "IpProtocol": "tcp",
                    "IpRanges": [
                        {
                            "CidrIp": "0.0.0.0/0"
                        }
                    ],
                    "Ipv6Ranges": [],
                    "PrefixListIds": [],
                    "ToPort": 80,
                    "UserIdGroupPairs": []
                },
                {
                    "IpProtocol": "-1",
                    "IpRanges": [],
                    "Ipv6Ranges": [],
                    "PrefixListIds": [],
                    "UserIdGroupPairs": [
                        {
                            "GroupId": "sg-0047473f289f0ffd3",
                            "UserId": "592017647781"
                        },
                        {
                            "GroupId": "sg-031e0901b061eb92d",
                            "UserId": "592017647781"
                        },
                        {
                            "GroupId": "sg-03f39f48c7887e46b",
                            "UserId": "592017647781"
                        },
                        {
                            "GroupId": "sg-07d8dbe45e3e81e44",
                            "UserId": "592017647781"
                        }
                    ]
                }
            ],
            "OwnerId": "592017647781",
            "GroupId": "sg-0002ee69773ca6f9d",
            "IpPermissionsEgress": [
                {
                    "IpProtocol": "-1",
                    "IpRanges": [
                        {
                            "CidrIp": "0.0.0.0/0"
                        }
                    ],
                    "Ipv6Ranges": [],
                    "PrefixListIds": [],
                    "UserIdGroupPairs": []
                }
            ],
            "VpcId": "vpc-0eee2636f691ad96b"
        }
    ]
}

问题解决更新

最终通过VPC可达性分析工具定位并解决了问题,故障原因是混淆了相关配置项。遇到同类VPC内资源连通性问题的用户,可以优先使用该工具自行排查端到端路径连通性,快速定位故障点。
感谢John的帮助。

内容的提问来源于stack exchange,提问作者Evans Y.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.29 02:24:34