通过SSH隧道远程连接Docker中运行的MariaDB失败求助
Hey there! Let's break down what's going on here and walk through some practical fixes to get your DBeaver connection working.
First off, your core assumption about SSH tunneling is totally right—once the tunnel is up, your local client should be able to reach the remote host's 3306 port as if you were sitting on that server. The 31987 port in your error is just an ephemeral (temporary) port DBeaver auto-assigns for the tunnel, so that's not the root issue.
Let's start with the most likely culprits and work through them step by step:
1. First, rule out DBeaver-specific issues with a manual SSH tunnel
Sometimes GUI client configurations can have hidden quirks, so let's test with a plain terminal tunnel first:
- Open a local terminal and run this command to create a tunnel mapping your local port 3307 to the remote host's 127.0.0.1:3306:
ssh -i /path/to/your/mykey -L 3307:127.0.0.1:3306 user@your-hostname - Keep this terminal window open (don't close it—closing it drops the tunnel).
- Open another local terminal and try connecting directly with the MariaDB client:
Enter your database root password when prompted.mariadb -h 127.0.0.1 -P 3307 -uroot -p
If this works, the problem is definitely in your DBeaver configuration. If it doesn't, we'll dig into the remote server settings next.
2. Check your remote SSH server's port forwarding settings
It's possible your SSH server has TCP forwarding disabled (though this is rare by default):
- SSH into your remote host, then open the SSH config file:
sudo nano /etc/ssh/sshd_config - Look for the line
AllowTcpForwarding—make sure it's set toyes(not commented out or set tono). - Save the file and restart the SSH service:
sudo systemctl restart sshd
3. Verify your MariaDB container's listening address
Even though you can connect from the remote host itself, let's double-check the container's MariaDB is listening correctly:
- SSH into your remote host, then jump into the database container:
docker exec -it database bash - Log into MariaDB:
mariadb -uroot -p - Run this query to check the bind address:
SHOW VARIABLES LIKE 'bind_address';
If the result is 127.0.0.1, that's totally fine—Docker's port forwarding will still route traffic from the host's 3306 to the container's local 3306. If it's set to a specific IP, just make sure the container's port is accessible to the host (which it is, since you can connect locally).
4. Fix your DBeaver configuration
If the manual tunnel worked, let's tweak your DBeaver setup to match:
- Open your database connection settings in DBeaver, go to the SSH tab:
- Confirm your SSH host, username, and private key are correct (you said the SSH test passes, so this should be good).
- In the Port forwarding section, click Add:
- Local port: Pick a fixed number like
3307(avoid auto-assigned ephemeral ports to prevent mismatches) - Target host: Enter
127.0.0.1(this points to the remote host's localhost, where Docker exposes the database port) - Target port:
3306
- Local port: Pick a fixed number like
- Switch back to the Main tab:
- Host:
127.0.0.1(your local machine, since the tunnel routes to the remote host) - Port:
3307(the fixed local port you set in the SSH tab) - Database:
wordpress - Username:
root(orwordpress, whichever you want to use) - Password: The corresponding database password from your secrets
- Host:
- Click Test Connection—this should now work!
Extra Notes
- You don't need a separate SSH tunnel Docker service—your current approach is totally valid and more lightweight.
- Since you have the remote host's 3306 port firewalled, you're doing the right thing by using SSH tunneling instead of exposing it publicly.
Hope this gets you connected! Let me know if you hit any snags along the way.
备注:内容来源于stack exchange,提问作者newjunkcity

