VPC内AWS Lambda无法连接Amazon DocDB等资源故障排查
VPC内Lambda无法访问Amazon DocDB故障排查
在VPC内部署了用于访问Amazon DocDB的Lambda函数,但该函数无法访问VPC内任何资源,查阅多日官方配置指南仍未解决问题。已按照官方Lambda VPC配置指南逐一核对所有VPC配置项,仍未定位故障。
该Lambda在创建时已完成VPC关联配置。
现整理相关配置、代码、报错信息如下,求Lambda配置相关的排查建议。
函数业务代码
def access_mongodb(event, context): url = event.get('url') if url: db = event.get('db') coll = event.get('collection') query = event.get('query') limit = int(event.get('limit')) try: with Mongo(url=url, db=db) as conn: logger.info('Lambda Start query with Mongo') for row in conn[coll].find(query).limit(limit): logger.info(f'got row => {json.dumps(row, default=str)}') except Exception as e: logger.error(f'Got exception {e}') else: logger.info('Lambda End with out Mongo')
报错信息
Got exception No servers found yet, Timeout: 2.0s, Topology Description: <TopologyDescription id: 62b5186720247fb7d69a0765, topology_type: Single, servers: [<ServerDescription ('docdb-test.xxxx-southeast-1.docdb.amazonaws.com', 27017) server_type: Unknown, rtt: None>]>
相关配置信息
- Lambda函数配置
执行aws lambda get-function-configuration --function-name hello_py3返回结果:
{ "FunctionName": "hello_py3", "FunctionArn": "arn:aws:lambda:ap-southeast-1:592017647781:function:hello_py3", "Runtime": "python3.9", "Role": "arn:aws:iam::592017647781:role/service-role/hello_py3-role-xh39m23g", "Handler": "lambda_function.lambda_handler", "CodeSize": 5701329, "Description": "", "Timeout": 10, "MemorySize": 128, "LastModified": "2022-06-24T01:26:48.000+0000", "CodeSha256": "VLwda8fP2DM62/y4Ouy9/U3KpzvfSRWoH7ocCwl1G6g=", "Version": "$LATEST", "VpcConfig": { "SubnetIds": [ "subnet-08dacd9b6970624aa", "subnet-09f80e8227735f6cf", "subnet-028392620db2f9753" ], "SecurityGroupIds": [ "sg-0002ee69773ca6f9d" ], "VpcId": "vpc-0eee2636f691ad96b" }, "TracingConfig": { "Mode": "PassThrough" }, "RevisionId": "55af10eb-f777-4ba9-aea5-05a010ce7637", "State": "Active", "LastUpdateStatus": "Successful", "PackageType": "Zip", "Architectures": [ "x86_64" ], "EphemeralStorage": { "Size": 512 } }
- Lambda执行角色关联策略
执行aws iam list-attached-role-policies --role-name hello_py3-role-xh39m23g返回结果:
{ "AttachedPolicies": [ { "PolicyName": "AWSLambdaVPCAccessExecutionRole-2400d95b-c83c-4fce-8e12-b1a8c5c4b503", "PolicyArn": "arn:aws:iam::592017647781:policy/service-role/AWSLambdaVPCAccessExecutionRole-2400d95b-c83c-4fce-8e12-b1a8c5c4b503" }, { "PolicyName": "AWSLambdaBasicExecutionRole-a8dac45b-b9f1-4eab-8170-2c9b9f9358ce", "PolicyArn": "arn:aws:iam::592017647781:policy/service-role/AWSLambdaBasicExecutionRole-a8dac45b-b9f1-4eab-8170-2c9b9f9358ce" } ] }
- 关联VPC信息
执行aws ec2 describe-vpcs --vpc-ids vpc-0eee2636f691ad96b返回结果:
{ "Vpcs": [ { "CidrBlock": "172.31.0.0/16", "DhcpOptionsId": "dopt-0b9edd5b6deafa0db", "State": "available", "VpcId": "vpc-0eee2636f691ad96b", "OwnerId": "592017647781", "InstanceTenancy": "default", "CidrBlockAssociationSet": [ { "AssociationId": "vpc-cidr-assoc-0200675b36f061104", "CidrBlock": "172.31.0.0/16", "CidrBlockState": { "State": "associated" } } ], "IsDefault": true } ] }
- 关联安全组信息
执行aws ec2 describe-security-groups --group-ids sg-0002ee69773ca6f9d返回结果:
{ "SecurityGroups": [ { "Description": "default VPC security group", "GroupName": "default", "IpPermissions": [ { "FromPort": 80, "IpProtocol": "tcp", "IpRanges": [ { "CidrIp": "0.0.0.0/0" } ], "Ipv6Ranges": [], "PrefixListIds": [], "ToPort": 80, "UserIdGroupPairs": [] }, { "IpProtocol": "-1", "IpRanges": [], "Ipv6Ranges": [], "PrefixListIds": [], "UserIdGroupPairs": [ { "GroupId": "sg-0047473f289f0ffd3", "UserId": "592017647781" }, { "GroupId": "sg-031e0901b061eb92d", "UserId": "592017647781" }, { "GroupId": "sg-03f39f48c7887e46b", "UserId": "592017647781" }, { "GroupId": "sg-07d8dbe45e3e81e44", "UserId": "592017647781" } ] } ], "OwnerId": "592017647781", "GroupId": "sg-0002ee69773ca6f9d", "IpPermissionsEgress": [ { "IpProtocol": "-1", "IpRanges": [ { "CidrIp": "0.0.0.0/0" } ], "Ipv6Ranges": [], "PrefixListIds": [], "UserIdGroupPairs": [] } ], "VpcId": "vpc-0eee2636f691ad96b" } ] }
问题解决更新
最终通过VPC可达性分析工具定位并解决了问题,故障原因是混淆了相关配置项。遇到同类VPC内资源连通性问题的用户,可以优先使用该工具自行排查端到端路径连通性,快速定位故障点。
感谢John的帮助。
内容的提问来源于stack exchange,提问作者Evans Y.
相关产品推荐
相关产品推荐

