多VPC架构下RDS实例公网访问设置的连通性疑问
Great question—this is a common point of confusion because the RDS wording around "VPC external access" can feel ambiguous. Let’s break this down clearly:
First, What Does the "Publicly Accessible" Option Actually Control?
The 「实例公网访问」(Publicly Accessible) toggle only manages whether your RDS instance gets assigned a public IP address. It has no impact on private network traffic between VPCs connected via VPC peering. When you set this to "No," you’re just blocking public internet access to the RDS instance—private connections (like those through peering) work perfectly fine.
Yes, You Can Still Connect from the Shared Services VPC (Here’s the Setup)
As long as you configure your private network correctly, your Jenkins instance in the shared services VPC will reach the dev RDS instance without issue, even with "Publicly Accessible" disabled. Here are the key requirements:
- VPC Peering Routing:
- Add a route to your dev VPC’s subnet route tables (the ones linked to your RDS subnets) that points the shared services VPC’s CIDR block to your VPC peering connection ID.
- Add a matching route in your shared services VPC’s route tables pointing the dev VPC’s CIDR block to the same peering connection.
- Security Group Rules:
- Update your dev RDS’s security group to allow inbound traffic on your database port (e.g., 3306 for MySQL, 5432 for PostgreSQL) from the shared services VPC’s CIDR block.
- Make sure your Jenkins instance’s security group allows outbound traffic to the dev RDS’s port and CIDR range.
- Network ACLs (NACLs):
- Confirm the dev RDS subnets’ NACLs allow inbound traffic from the shared services VPC’s CIDR on the database port, plus outbound return traffic (usually ephemeral ports).
- Ensure the shared services VPC’s subnets’ NACLs permit outbound traffic to the dev RDS’s CIDR and port, plus inbound return traffic.
Clearing Up the Ambiguous RDS Description
The line "VPC外的EC2实例或设备无法连接" (EC2 instances or devices outside the VPC cannot connect) is misleading when using VPC peering. In this context, "outside the VPC" refers to untrusted public internet or networks not linked via private connections like peering/Transit Gateway. VPC-peered VPCs are part of your private network fabric, so they don’t count as "outside" here.
Final Takeaway
Setting "Publicly Accessible" to No is actually the more secure choice—it cuts down your RDS instance’s attack surface by removing public internet exposure. As long as your private network configurations (peering, routes, security groups) are set up properly, your shared services VPC will connect to the dev RDS instance using its private IP address without any problems.
内容的提问来源于stack exchange,提问作者Luis Alvarado Day

