You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Lambda连接EC2实例MySQL遇SequelizeConnectionError超时

Troubleshooting SequelizeConnectionError (ETIMEDOUT) Between Lambda and EC2 MySQL

Hey there, let's work through this connection timeout issue together. The ETIMEDOUT error you're seeing typically points to a network-level block or misconfiguration—even if you've already aligned Lambda and EC2 on the same VPC, subnets, and security groups. Here's a step-by-step breakdown of checks and fixes to resolve this:

1. Confirm MySQL is listening on the correct network interface

First, make sure MySQL isn't restricted to local connections only:

  • SSH into your EC2 instance and run this command to check where MySQL is binding:
    netstat -tulpn | grep mysql
    
  • Look for a line like 0.0.0.0:3306 (allows all IPs) or your EC2's private IP. If it shows 127.0.0.1:3306, MySQL is only accepting local connections.
  • Fix this by editing your MySQL config file (usually /etc/mysql/my.cnf or /etc/mysql/mysql.conf.d/mysqld.cnf):
    • Update the bind-address value to 0.0.0.0 or your EC2's private IP
    • Restart MySQL to apply changes:
      sudo systemctl restart mysql
      

2. Verify Lambda's VPC permissions and subnet health

Even with matching VPC/subnets, Lambda needs the right permissions to access network resources:

  • Ensure your Lambda execution role has the AWSLambdaVPCAccessExecutionRole managed policy attached. This role lets Lambda create elastic network interfaces (ENIs) to connect to the VPC—without it, Lambda can't establish network connections.
  • Check if your target subnet has available IP addresses. If the subnet is exhausted, Lambda can't assign an ENI, leading to timeouts. You can check this in the AWS VPC Console under Subnets > [Your Subnet] > IPv4 CIDR block.

3. Double-check security group rules (even shared ones)

Shared security groups don't always mean the right rules are in place:

  • Inbound rules for EC2's security group: Add a rule allowing TCP traffic on port 3306 (MySQL default) from either:
    • The same security group ID (so resources in the group can communicate with each other)
    • Your VPC's CIDR range (e.g., 10.0.0.0/16)
  • Outbound rules for Lambda's security group: Ensure it allows TCP traffic on port 3306 to the EC2 instance's private IP or VPC CIDR. Most default security groups allow all outbound traffic, but it's worth confirming.

4. Test connectivity from within the VPC

Isolate whether the issue is with Lambda or the network itself:

  • Launch a temporary EC2 instance in the same VPC, subnet, and security group as your Lambda.
  • Install the MySQL client and try connecting to your target EC2's MySQL:
    mysql -h <EC2_PRIVATE_IP> -u <DB_USERNAME> -p
    
  • If this connection times out too, the problem is with your EC2/network setup (not Lambda). If it works, focus on Lambda-specific configurations.

5. Validate your Sequelize configuration

Make sure your Lambda's Sequelize setup is using the right network details:

  • Use your EC2's private IP (not public IP or domain) in the connection config—VPC internal traffic should always use private IPs.
  • Example correct configuration:
    const { Sequelize } = require('sequelize');
    
    const sequelize = new Sequelize('your_db_name', 'db_user', 'db_password', {
      host: '10.0.0.123', // Replace with EC2's private IP
      dialect: 'mysql',
      port: 3306,
      dialectOptions: {
        connectTimeout: 15000 // Optional: Increase timeout temporarily for testing
      }
    });
    
  • Also, check if EC2 has a local firewall (like iptables or ufw) blocking port 3306. Run sudo iptables -L to view rules, and add an allow rule if needed:
    sudo iptables -A INPUT -p tcp --dport 3306 -s <VPC_CIDR> -j ACCEPT
    

6. Check Lambda dependencies and runtime compatibility

Sometimes dependency issues can mimic network problems:

  • Ensure your deployment package includes compatible versions of mysql2 and sequelize for your Lambda runtime (e.g., Node.js 18.x). If you built dependencies locally on an x86 machine but are running Lambda on ARM (Graviton2), you might need to rebuild dependencies for ARM or use Lambda layers.

Start with the first three checks—they're the most common causes of this timeout error. If you still run into issues, share the results of the VPC connectivity test and we can dive deeper!

内容的提问来源于stack exchange,提问作者Dinesh Rawat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:44:26