You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Fluentd向启用TLS的AWS DocumentDB写入数据?

配置方案

问题根因

你遇到的Mongo::Error::NoServerAvailable报错本质是DocumentDB默认强制开启TLS认证,原有面向EC2自建Mongo的配置未携带TLS证书参数,无法完成TLS握手导致服务端拒绝连接。

操作步骤

1. 准备CA证书

下载官方提供的rds-combined-ca-bundle.pem证书文件,上传到Fluentd所在机器的/etc/ssl/certs/路径下,执行命令设置全局可读权限:
chmod 644 /etc/ssl/certs/rds-combined-ca-bundle.pem

2. 修改td-agent.conf配置

只需调整match段中mongo_replset的<template>部分配置,参考如下:

<match test.**>
  @type copy
  <store>
    @type forest
    subtype mongo_replset
    <template>
      # 替换为你的DocumentDB集群端点,仅需填一个即可
      host your-docdb-cluster-name.xxx.docdb.amazonaws.com:27017
      # DocumentDB默认副本集名称固定为rs0,无需修改
      replica_set rs0 
      database ${tag_parts[-2]}
      collection ${tag_parts[-1]}
      user ********
      password ********
      replace_dot_in_key_with __dot__
      # 新增TLS相关配置
      ssl true
      ssl_ca_cert /etc/ssl/certs/rds-combined-ca-bundle.pem
      ssl_verify_hostname true
      <buffer>
        @type file
        path /var/log/test/buffer-mongo/${tag_parts[-2..-1]}
        chunk_limit_size 8m
        queued_chunks_limit_size 64
        flush_interval 1s
      </buffer>
    </template>
  </store>
</match>

校验检查项

  • 确认Fluentd所在实例的安全组允许出站到DocumentDB的27017端口,DocumentDB安全组允许来自Fluentd实例的27017端口入站
  • 若使用非默认VPC,需确认Fluentd与DocumentDB网络可达
  • 确认使用的DocumentDB账号拥有对应数据库的写入权限

配置修改完成后重启td-agent服务即可生效。

内容的提问来源于stack exchange,提问作者user31315

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 15:06:03