You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Airflow 2.1.3 Helm Chart部署pgbouncer连接PostgreSQL失败问题求助

问题根因

你遇到的问题由3个配置错误共同导致:

  1. 8.5.x版本Airflow Helm Chart的内置pgbouncer默认关联Chart自带的PostgreSQL实例,未开启外置数据库兼容配置时,不会读取你填写的externalDatabase参数,导致pgbouncer.ini的数据库指向错误的127.0.0.1地址
  2. pgbouncer默认开启OCSP证书校验,Azure PostgreSQL的SSL证书无法通过该校验,触发TLS握手失败
  3. 该版本Chart的pgbouncer监听端口配置参数名不是listen_port,你填写的配置未被模板渲染识别

解决方案

按如下内容修改values.yaml即可:

pgbouncer:
  enabled: true
  # 启用外置数据库兼容模式,强制读取externalDatabase配置
  postgresqlDisabled: true
  # 该版本Chart的监听端口配置参数为port
  port: 5432
  # 追加pgbouncer配置,禁用OCSP校验适配Azure PG
  extraIniConfigs: |
    [pgbouncer]
    server_tls_sslmode = require
    server_tls_ca_file = /etc/ssl/certs/ca-certificates.crt
    server_tls_ocsp = off

externalDatabase:
  type: postgres
  host: psql-hostname.postgres.database.azure.com
  port: 5432
  database: airflow
  user: username@psql-hostname
  passwordSecret: "airflow-postgres-redis-name"
  passwordSecretKey: "postgresql-password-key-name"
  # 追加sslmode配置适配Azure PG的强制SSL要求
  properties: "?sslmode=require"

验证方法

重新执行helm upgrade部署后:

  • 进入pgbouncer Pod查看/home/pgbouncer/pgbouncer.ini,[databases]段的地址应该为你的Azure PostgreSQL实例域名,而非127.0.0.1
  • 监听端口符合你配置的数值,Pod日志不再出现TLS握手报错,存活探针正常不会触发重启

内容的提问来源于stack exchange,提问作者soMuchToLearnAndShare

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 22:36:07