部署Django应用至AWS时连接RDS MySQL实例遇1045权限错误求助
Hey there, let's break down how to fix that 1045 Access Denied error you're hitting with your Django + AWS RDS setup. I've dealt with this exact issue a few times, so here's what to check and adjust step by step:
First, let's rule out RDS-side issues:
- Head to the AWS RDS Console, select your instance, and go to the Connectivity & security tab. Confirm your VPC security group has an inbound rule allowing your app server's IP (or your local IP for testing) to access port 3306.
- Use the RDS Query Editor to log into your database and verify the
wsgiuser has the right permissions:
You should see a grant likeSHOW GRANTS FOR 'wsgi'@'%';GRANT ALL PRIVILEGES ON your_database_name.* TO 'wsgi'@'%'. If not, run these commands to fix it:
ReplaceGRANT ALL PRIVILEGES ON your_database_name.* TO 'wsgi'@'%' IDENTIFIED BY 'your_actual_password'; FLUSH PRIVILEGES;your_database_nameandyour_actual_passwordwith your real values. The%wildcard lets the user connect from any IP—if you locked it to a specific IP, make sure that IP matches your app server's current address.
settings.py This is the most common culprit. Make sure your DATABASES block matches your RDS details exactly:
DATABASES = { 'default': { 'ENGINE': 'django.db.backends.mysql', 'NAME': 'your_rds_database_name', # This is the DB name you created in RDS, NOT the instance name 'USER': 'wsgi', 'PASSWORD': 'your_rds_user_password', # Watch out for typos or special characters (like $) that might break env vars 'HOST': 'your_rds_full_endpoint', # e.g., my-db-instance.abc123.us-east-1.rds.amazonaws.com 'PORT': '3306', 'OPTIONS': { # Critical for AWS RDS: SSL is required by default 'ssl': {'ca': '/path/to/rds-combined-ca-bundle.pem'}, }, } }
- Don't skip the SSL option—AWS RDS enforces SSL connections for MySQL, and missing this can trigger access denied errors even if your credentials are correct. You can download the RDS CA bundle from AWS and place it in your project directory.
- If you're using environment variables (best practice for secrets), make sure you're reading them correctly:
If your password has special characters, wrap it in quotes in your env file (e.g.,import os DATABASES['default']['PASSWORD'] = os.environ.get('DB_PASSWORD')DB_PASSWORD="my$ecurePass!").
requirements.txt Play a Role? Absolutely—it can cause connection issues if you're using an incompatible MySQL driver:
- Avoid outdated packages like
MySQL-python. Use the maintainedmysqlclientinstead. Update yourrequirements.txtto include:mysqlclient>=2.2.0 - If you're deploying on Amazon Linux 2 (EC2 or Elastic Beanstalk), you'll need system dependencies first. Run this before installing your Python packages:
Missing these can lead to incompletesudo yum install mysql-devel gcc python3-develmysqlclientinstallations that fail to connect properly.
To narrow down the issue, test the connection directly from your app server using the MySQL command line:
mysql -h your_rds_full_endpoint -P 3306 -u wsgi -p
- If this works, the problem is in your Django configuration (double-check settings.py for typos or missing SSL).
- If this fails, go back to checking RDS security groups and user permissions.
Start with the command line test—it'll quickly tell you whether the issue is with RDS itself or your Django setup. More often than not, it's either a missing SSL option in settings.py or incorrect user grants in RDS.
内容的提问来源于stack exchange,提问作者Matt Strong

