部署Rails 5应用至EC2时遇到RDS数据库连接错误
Hey there, it’s frustrating when you hit a connection error after successfully running db:create and db:migrate—let’s walk through the most likely culprits and fixes for your AWS RDS + Rails setup on Ubuntu 16.04:
1. Double-Check RDS Security Group Rules
Even though your initial database commands worked, it’s possible the security group rules for your RDS instance changed, or your Ubuntu server’s network context shifted (e.g., if it’s an EC2 instance with a dynamic public IP).
- Head to the AWS RDS Console, select your instance, and go to Connectivity & security.
- Look at the attached VPC security groups, then verify the inbound rules allow traffic from your Ubuntu server’s private IP (or the EC2 instance’s security group, if using VPC peering) on your database port (3306 for MySQL, 5432 for PostgreSQL).
- If you used a public IP for the security group rule earlier, confirm your server’s public IP hasn’t changed (EC2 instances with default dynamic IPs can reset on reboot).
2. Audit Your database.yml Production Config
A tiny misconfiguration here can break post-migration connections, even if initial commands worked:
- For MySQL: Remove any
socketparameter—RDS is a remote database, so local sockets don’t apply. Double-check thehostendpoint, username, and password for typos. A valid config looks like this:production: adapter: mysql2 host: your-rds-instance.abc123.us-east-1.rds.amazonaws.com database: your_prod_db username: your_db_user password: your_secure_password port: 3306 encoding: utf8mb4 pool: 5 - For PostgreSQL: Add
sslmode: require—AWS RDS PostgreSQL enforces SSL by default, and omitting this can cause connection failures after initial setup. - Avoid special characters in your password without escaping them (e.g., wrap the password in quotes if it has
#or:).
3. Verify Ubuntu Server Firewall (UFW) Rules
Your server’s UFW might have blocked outbound traffic to RDS after your initial commands. Check the status with:
sudo ufw status
If you don’t see an allow rule for your RDS port, add it with:
# For MySQL sudo ufw allow out to your-rds-endpoint port 3306 proto tcp # For PostgreSQL sudo ufw allow out to your-rds-endpoint port 5432 proto tcp
4. Test RDS Endpoint Connectivity Directly
Rule out network issues entirely by testing port access from your Ubuntu server:
# Using nc (install with sudo apt install netcat if missing) nc -zv your-rds-endpoint 3306 # Or telnet telnet your-rds-endpoint 3306
If this fails, go back to security groups and UFW—there’s a network block somewhere. If it succeeds, the issue is application-level.
5. Check RDS Database User Permissions
It’s possible your database user is restricted to a specific IP that’s no longer valid. Log into your RDS instance (using tools like mysql or psql) and run:
-- For MySQL SELECT user, host FROM mysql.user WHERE user = 'your_db_user'; -- For PostgreSQL SELECT usename, connlimit FROM pg_user WHERE usename = 'your_db_user';
If the host value is a specific IP instead of % (or your VPC’s CIDR range), update it to allow access from your server’s network.
6. Restart Your Rails Application Server
If you modified database.yml after running migrate but didn’t restart your app server (Puma, Unicorn, etc.), the app is still using old connection settings. Restart it with something like:
# Example for Puma managed by systemd sudo systemctl restart puma # Example for Unicorn sudo systemctl restart unicorn
One of these steps should get your connection working again!
内容的提问来源于stack exchange,提问作者Ali Ammaar

