You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Azure PostgreSQL以通过私有IP仅向Azure VM开放访问

Hey there! I've done this setup a few times, so let's walk through exactly how to switch your Azure PostgreSQL server to use only private IP access, restricting connections to just your Azure VMs on the private network. Here's the step-by-step process:

1. Set up Virtual Network (VNet) Integration for PostgreSQL

First, you need to attach your PostgreSQL server to the same VNet (or a peered VNet) where your Azure VM resides. If you already have a VNet for your VM, we can use that directly:

  • Log into the Azure Portal, navigate to your Azure Database for PostgreSQL server.
  • From the left sidebar, select Connection security.
  • In the Virtual networks section, click either + Add existing virtual network rule or + Create new virtual network:
    • For an existing VNet: Select your VM's VNet and the target subnet, then enable the Service endpoint (choose Microsoft.Sql—this is the endpoint type used by Azure PostgreSQL).
    • Pro tip: Make sure the subnet doesn't have conflicting service endpoints for other Azure services, and that its IP range has enough space for the integration.
2. Disable Public Network Access

Now let's turn off the public IP so no external connections can reach the server:

  • Still in the Connection security page, find the Public network access dropdown.
  • Select Disabled, then click Save.
    • Once saved, the server's public IP will be removed entirely—any public-facing connections will stop working immediately.
3. Test the Private IP Connection from Your Azure VM

Time to verify that your VM can connect via the private network:

  • Log into your Azure VM (use SSH for Linux, RDP for Windows).
  • Install the PostgreSQL client if you don't have it already:
    • For Ubuntu/Debian: sudo apt-get update && sudo apt-get install postgresql-client -y
    • For Windows: Download and install pgAdmin or the psql binary from the PostgreSQL website.
  • Connect using the server's private IP or private DNS name (format: <your-server-name>.private.postgres.database.azure.com):
    psql -h <postgres-private-ip-or-private-dns> -U <admin-username>@<server-name> -d <your-database-name>
    
    • You'll be prompted for your admin password—enter it, and you should be connected successfully.
Quick Notes to Keep in Mind
  • Ensure your Azure VM and PostgreSQL server are in the same VNet, or connected via VNet peering, VPN, or ExpressRoute. Cross-VNet connections without peering won't work here.
  • Any existing firewall rules for public access will automatically stop working once you disable public network access—you don't need to delete them manually.
  • If you ever need to re-enable public access later, you can just toggle the Public network access setting back to Allowed in the Connection security page.

内容的提问来源于stack exchange,提问作者Roni Baby

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:00:27