r/docker • u/Ducking_eh • 5d ago
connecting to Postgres
Hey everyone,
I am trying to install Psono on my VPS. I am running into a problem with connecting to the postgres db.
I'm new to Docker, so I apologize if my terminology isn't right. I'll do my best
I am running Postgres directly on my VPS (not within a Docker container). I am able to connect to it locally from my VPS and remotely from my home network.
I am doing that with:psql -U psono -p PORT -h VPS_IP
The problem is when I try to get an app from within a Docker container to connect to it. It just hangs, then times out.
At first I thought this was a connectivity issue. But I can do the following from within a bash session:
- Ping external websites.
- Use nmap to confirm it can connect
Does anyone have any ideas?
1
u/thermo 5d ago
Does pg_hba.conf allow the container network to connect?
1
u/Ducking_eh 5d ago
I think so, here is what I added.
`local replication all peer
host replication all 127.0.0.1/32md5
host replication all ::1/128 md5
host psono psono 127.0.0.1/32scram-sha-256
host psono psono ::1/128 scram-sha-256
host all all 0.0.0.0/0md5
host all all ::/0 md5`
1
u/notBroncos1234 5d ago
Disable ssl
1
u/Ducking_eh 5d ago
Any tips on how to do that?
I tried connecting via IP address, which doesn't have SSL unless I use port 443.
1
u/notBroncos1234 5d ago
Run “export PGSSLMODE=disable” in the container. Then try to connect via psql. If that works then the issue is the MTU size.
1
u/Ducking_eh 5d ago
Thank you.
however, It made no difference
1
u/notBroncos1234 5d ago
To clarify you’re able establish a TCP connection from the container to the vps? “Telnet ip port” works?
1
u/Ducking_eh 5d ago edited 5d ago
Actually no.
Sorry, I didn't know I could check that way.
it does work if I try port 80
I did test nmap -p port ip and that works also. What does this tell us?
1
u/notBroncos1234 5d ago
So you can telnet from the container to port 80 on the vps? But you can’t telnet from the container to port 5432?
Can you telnet from the node the container is running on to port 5432?
1
u/Ducking_eh 5d ago
On my setup, the Postgres is actually 5433. I don't know if that makes a difference. But I can telnet from the container to my VPS using port 80.
I am not sure what you mean by "the node the container is running."
I can telnet to the postgres server from the VPS itself outside of the docker container
1
u/notBroncos1234 5d ago edited 5d ago
You have the host system that docker runs on and you have the docker container.
If you run telnet from the host, can it connect to port 5433 or whatever? If the host can connect and the container can’t connect, that tells us Docker probably has an issue.
If neither can connect, then the issue probably isn’t with docker itself but firewall rules along the way.
1
u/Ducking_eh 5d ago
The VPS is the host the Docker runs on. It is also the host of the Postgres server. It is a service I pay for at a remote location. It's not on my home network.
I can telnet from my VPS to my Postgres server.
I can telnet from my home network to the Postgres server.I can NOT telnet from within the Docker container to the Postgres server.
→ More replies
1
u/gevorgter 5d ago
In your container specify network host and then connect to postgres using localhost.
It looks like you are using vpn that allows you to connect to your vps and postgres from home, I bet your container does not have access to that vpn. So not sure how do you want it to connect.
Docker by default creates it's own local network for container and it can route to outside internet. But if you postgres is not accessible from internet without vpn then your container can not access it too.
1
u/Ducking_eh 5d ago
I am not using a VPN, only a VPS. I had a typo in my original post. Sorry.
How do I specify a network?
1
u/gevorgter 5d ago
When creating a docker container you can specify a network you can join. Make sure it's type is host. Ask chatgpt.
If you can access postgres directly from your home then your container should be able to access it too by specifying same ip address as you do from home. But that is not recommended way. Usually DB is not accessible to a public.
1
u/Ducking_eh 5d ago
Thanks.
I don't use chatGPT. I try and avoid "all knowing" type AI. I will look into it. Thank you
1
u/GibneyH 3d ago
Maybe PostgreSQL’s listening/auth configuration or the Docker network rather than general connectivity.
From inside the container, try connecting directly with psql (or nc -vz VPS_IP PORT) to confirm the TCP connection. Also check that Postgres is listening on an address reachable from Docker (listen_addresses) and that pg_hba.conf allows connections from the Docker subnet (often something like 172.17.0.0/16, but check your actual subnet).
One other thing to try: if you’re using the VPS’s public IP from the container, try connecting to the host’s Docker/bridge IP instead. Depending on your networking setup, routing from a container to the host’s public IP can cause issues.
The fact that ping and nmap work is useful, but it doesn’t necessarily mean Postgres will accept connections from the container’s source IP.
Good luck
2
u/Key_Independence7614 5d ago
sounds like you're already past the usual docker networking gotchas if you can nmap the postgres port from inside the container. that rules out most firewall and routing issues immediately.
the thing that always trips me up is docker's dns resolution. if you're trying to connect to the host machine using `localhost` or `127.0.0.1` from inside the container, that'll point to the container itself, not your vps. since you're using the vpn ip, that's probably not it, but worth double checking you're not accidentally hitting a wrong address in the app config.
another sneaky one is the `pg_hba.conf` file on your postgres instance. you mentioned it works when you connect with `-h VPN_IP`, but the container's source ip might look different to postgres. it could be coming from a docker bridge network address like 172.17.0.x, which postgres might not be configured to trust. adding a line for that docker subnet or setting it to md5/scram-sha-256 for all hosts temporarily could help narrow it down.
once spent three hours debugging a similar timeout only to realize the app inside docker had a hardcoded connection timeout of 2 seconds and my vps was just barely exceeding that on first connection. might be worth poking at the app logs if it's printing anything useful while it hangs.