首页 > 解决方案 > 尽管遵循文档,但使用代理连接到云 SQL 失败

问题描述

我将教义 ORM 与 PHP 框架 Symfony 一起使用。尝试使用 GKE 连接到云 SQL 时,我遇到了奇怪的行为。

我可以通过命令行上的学说连接到数据库,例如php bin/console doctrine:database:create成功,我可以看到代理 pod 日志中打开了一个连接。

但是当我尝试通过我的应用程序中的学说连接到数据库时,我毫无疑问地遇到了这个错误:

An exception occurred in driver: SQLSTATE[HY000] [2002] php_network_getaddresses: getaddrinfo failed: Name or service not known

我一直在努力解决这个问题,但这没有意义,为什么我可以通过命令行连接但不能在我的应用程序中连接?

我按照此处的文档使用云代理设置数据库连接。这是我的 Kubernetes 部署:

---
apiVersion: "extensions/v1beta1"
kind: "Deployment"
metadata:
  name: "riptides-api"
  namespace: "default"
  labels:
    app: "riptides-api"
    microservice: "riptides"
spec:
  replicas: 3
  selector:
    matchLabels:
      app: "riptides-api"
      microservice: "riptides"
  template:
    metadata:
      labels:
        app: "riptides-api"
        microservice: "riptides"
    spec:
      containers:
        - name: "api-sha256"
          image: "eu.gcr.io/riptides/api@sha256:ce0ead9d1dd04d7bfc129998eca6efb58cb779f4f3e41dcc3681c9aac1156867"
          env:
            - name: DB_HOST
              value: 127.0.0.1:3306
            - name: DB_USER
              valueFrom:
                secretKeyRef:
                  name: riptides-mysql-user-skye
                  key: user
            - name: DB_PASSWORD
              valueFrom:
                secretKeyRef:
                  name: riptides-mysql-user-skye
                  key: password
            - name: DB_NAME
              value: riptides
          lifecycle:
            postStart:
              exec:
                command: ["/bin/bash", "-c", "php bin/console doctrine:migrations:migrate -n"]
          volumeMounts:
            - name: keys
              mountPath: "/app/config/jwt"
              readOnly: true
        - name: cloudsql-proxy
          image: gcr.io/cloudsql-docker/gce-proxy:1.11
          command: ["/cloud_sql_proxy",
                    "-instances=riptides:europe-west4:riptides-sql=tcp:3306",
                    "-credential_file=/secrets/cloudsql/credentials.json"]
          # [START cloudsql_security_context]
          securityContext:
            runAsUser: 2  # non-root user
            allowPrivilegeEscalation: false
          # [END cloudsql_security_context]
          volumeMounts:
            - name: riptides-mysql-service-account
              mountPath: /secrets/cloudsql
              readOnly: true
      volumes:
        - name: keys
          secret:
            secretName: riptides-api-keys
            items:
            - key: private.pem
              path: private.pem
            - key: public.pem
              path: public.pem
        - name: riptides-mysql-service-account
          secret:
            secretName: riptides-mysql-service-account
---
apiVersion: "autoscaling/v2beta1"
kind: "HorizontalPodAutoscaler"
metadata:
  name: "riptides-api-hpa"
  namespace: "default"
  labels:
    app: "riptides-api"
    microservice: "riptides"
spec:
  scaleTargetRef:
    kind: "Deployment"
    name: "riptides-api"
    apiVersion: "apps/v1beta1"
  minReplicas: 1
  maxReplicas: 5
  metrics:
    - type: "Resource"
      resource:
        name: "cpu"
        targetAverageUtilization: 70

如果有人有任何建议,我会永远感激不尽

标签: doctrine-ormgoogle-cloud-platformgoogle-cloud-sqlcloud-sql-proxy

解决方案


您的 k8s yaml 看起来没有任何问题,但更有可能是您使用 Symfony 进行连接的方式。根据此处的文档,Symfony 期望 DB URI 通过名为“DATABASE_URL”的环境变量传入。请参见以下示例:

# customize this line!
DATABASE_URL="postgres://db_user:db_password@127.0.0.1:5432/db_name"

推荐阅读