Auf Datenbanken in einer VPC zugreifen
Lernen Sie Best Practices für die Verbindung von Lambda-Funktionen mit relationalen Datenbanken (z. B. RDS) und anderen Datenspeichern in Ihrem privaten VPC-Netzwerk kennen
Auf Datenbanken in einer VPC zugreifen ist eine kostenlose Serverless AWS Lambda Development-Lektion auf CoddyKit. Dies ist Lektion 2 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Serverless AWS Lambda Development-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Serverless AWS Lambda Development-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
Connect Lambda to Private DBs
Welcome! In this lesson, you'll learn how to securely connect your Lambda functions to databases that reside within your private Amazon Virtual Private Cloud (VPC).
This is crucial for serverless applications that need to interact with sensitive or internal data stores like Amazon RDS or other databases that aren't publicly accessible.
Lambda & Your Private Database
You've already configured your Lambda function to operate within a VPC (from the previous lesson). Now, we'll focus on how that Lambda can reach a database that's also inside the same VPC.
This setup ensures secure, internal communication, keeping your database isolated from the public internet.
Security Groups: The Gatekeepers
Security Groups are fundamental here. Think of them as virtual firewalls for your instances and resources within a VPC.
- They control both inbound (incoming) and outbound (outgoing) traffic.
- Both your Lambda function and your database will have associated security groups.
- These groups must be configured to explicitly allow communication between them.
Database Inbound Rules
Your database's security group needs an inbound rule to allow connections from your Lambda function.
- Type: Custom TCP
- Port Range: The specific port your database listens on (e.g.,
3306for MySQL,5432for PostgreSQL). - Source: Crucially, this should be the Security Group ID of your Lambda function.
This ensures only your Lambda can initiate connections to the database.
Lambda Outbound Rules
Conversely, your Lambda function's security group needs an outbound rule to allow it to send traffic to your database.
- Type: Custom TCP
- Port Range: Again, the database's specific port (e.g.,
3306). - Destination: This should be the Security Group ID of your database.
This allows your Lambda to successfully reach out and connect to the database.
Subnets & Network Reachability
Beyond security groups, ensure your Lambda function is deployed into subnets that have proper network routing access to the subnets where your database instances reside.
- Typically, both Lambda and the database will be placed in private subnets within the same VPC.
- AWS handles the internal routing within the VPC, but proper subnet association is key for reachability.
Connecting from Lambda Code
Inside your Lambda function's code, you'll use standard database drivers and connection strings, just like any other application.
You'll need these key details:
- Database endpoint: (e.g.,
your-db.xxxx.rds.amazonaws.com) - Port: (e.g.,
3306) - Database name
- Username
- Password
Java DB Connection Example
Here's a conceptual Java snippet demonstrating how a Lambda might attempt to connect to a database. In a real application, you would handle credentials securely.
This example shows the basic structure; it won't run successfully without a live database and environment variables set.
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.SQLException;
public class Main {
public static void main(String[] args) {
String dbUrl = System.getenv("DB_URL");
String dbUser = System.getenv("DB_USER");
String dbPass = System.getenv("DB_PASS");
if (dbUrl == null || dbUser == null || dbPass == null) {
System.out.println("Error: DB environment variables not set.");
return;
}
try {
System.out.println("Attempting to connect to database...");
Connection conn = DriverManager.getConnection(dbUrl, dbUser, dbPass);
System.out.println("Connection successful!");
conn.close();
} catch (SQLException se) {
System.err.println("Database connection error: " + se.getMessage());
} catch (Exception e) {
System.err.println("An unexpected error occurred: " + e.getMessage());
}
}
}Securely Manage Credentials
Never hardcode database credentials directly in your Lambda code! This is a major security risk.
Best practices for managing sensitive information:
- AWS Secrets Manager: The recommended way to store, retrieve, and rotate database credentials securely.
- Environment Variables: Suitable for non-sensitive configuration, but not for passwords or API keys.
Always prioritize security for sensitive data.
Check Your Understanding
Imagine your Lambda function (associated with Security Group SG-A) needs to connect to an RDS database (associated with Security Group SG-B) on port 3306.
Which inbound rule must be configured on SG-B (the database's security group) to allow this connection?
Recap: Database Access in VPC
Great job! You've learned the essentials of connecting your Lambda functions to private databases within your VPC.
- Both your Lambda and database must be in the same VPC.
- Security groups are vital for controlling traffic flow between them.
- Configure inbound rules on the database's SG and outbound rules on Lambda's SG.
- Always manage database credentials securely, ideally using AWS Secrets Manager.
This knowledge is key to building secure and robust serverless applications!
Häufig gestellte Fragen
Ist die Lektion „Auf Datenbanken in einer VPC zugreifen“ kostenlos?
Ja — der vollständige Text von „Auf Datenbanken in einer VPC zugreifen“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Serverless AWS Lambda Development-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Serverless AWS Lambda Development-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Auf Datenbanken in einer VPC zugreifen“?
Lernen Sie Best Practices für die Verbindung von Lambda-Funktionen mit relationalen Datenbanken (z. B. RDS) und anderen Datenspeichern in Ihrem privaten VPC-Netzwerk kennen Du übst Serverless AWS Lambda Development mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Serverless AWS Lambda Development zu starten?
Keine Vorkenntnisse erforderlich. Serverless AWS Lambda Development auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 2 von 4.
Wie lange dauert die Lektion „Auf Datenbanken in einer VPC zugreifen“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Serverless AWS Lambda Development-Lektion Code schreiben und ausführen?
Ja. Jede Serverless AWS Lambda Development-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Lambda in einer VPC für private Ressourcen
- Auf Datenbanken in einer VPC zugreifen
- Best Practices für Netzwerksicherheit
- NAT-Gateways und Internetzugriff aus einer VPC