Networkingeasy0-2 years

A new ECS service cannot reach its RDS PostgreSQL database: the Hikari pool logs `connect timed out` after several seconds. A colleague says 'the database must be down'. What does a timeout tell you that a 'connection refused' would not, and how should the security groups be written?

A refused connection means the packet arrived and nothing was listening on that port: the process is the problem. A timeout means no answer came back at all: the network never delivered the packet, or dropped the reply. For a service reaching RDS, a timeout is almost always the database's security group not admitting the service, or a subnet the service's route table cannot reach. The database being 'down' would more often look like a refusal or a DNS failure. The fix is to write the rules by group, not by IP: the database's group allows 5432 from the service's group, the service's group allows 8080 from the load balancer's group. nc -zv <endpoint> 5432 from inside the service's network is the one-line test.

The lesson behind it →
More on Networking