같은 "접속 안 됨"이라도 어디까지 갔다가 막혔는지가 문구에 드러난다. 이것을 먼저 읽으면 헛짚지 않는다.
| 문구 | 막힌 지점 |
|---|---|
Connection refused / Connection to host:5432 refused |
TCP 연결 자체가 안 됐다. 인증 이전이다 |
Connection timed out |
패킷이 목적지까지 가지 못했다. 방화벽·라우팅 |
no pg_hba.conf entry for host ... |
TCP 는 붙었고 규칙에 일치하는 줄이 없다 |
password authentication failed |
규칙까지 통과했고 비밀번호가 틀렸다 |
database "x" does not exist |
인증까지 끝났다 |
too many clients already |
max_connections 한도 |
org.postgresql.util.PSQLException: Connection to 10.0.0.5:5432 refused. Check that the hostname and port are correct and that the postmaster is accepting TCP/IP connections. 는 첫 줄에 해당한다. 비밀번호나 pg_hba.conf 를 먼저 보는 것은 순서가 틀렸다.
systemctl status postgresql-17
ps -ef | grep [p]ostgres
ss -lntp | grep 5432
127.0.0.1:5432 만 보이면 외부 접속은 전부 거부된다. listen_addresses 가 기본값(localhost)인 상태다.
listen_addresses = '*'
port = 5432
listen_addresses 는 재시작이 필요하다. reload 로는 반영되지 않는다.
systemctl restart postgresql-17
nc -zv 10.0.0.5 5432
timeout 3 bash -c 'cat < /dev/null > /dev/tcp/10.0.0.5/5432' && echo open
닿지 않으면 서버 쪽 방화벽부터 본다.
firewall-cmd --list-all
firewall-cmd --add-port=5432/tcp --permanent
firewall-cmd --reload
클라우드라면 보안 그룹·네트워크 ACL 도 함께 본다. 컨테이너·Kubernetes 라면 Service 와 NetworkPolicy 를 본다.
여기까지 통과했는데 no pg_hba.conf entry 가 나오면 규칙을 더한다. 파일은 위에서부터 읽고 첫 일치 줄에서 멈춘다는 점을 기억한다.
host appdb appuser 10.0.0.0/16 scram-sha-256
systemctl reload postgresql-17
SELECT * FROM pg_hba_file_rules WHERE error IS NOT NULL;
접속은 됐다가 중간에 끊기는 유형은 원인이 다르다. 다음을 본다.
tcp_keepalives_idle 을 그보다 짧게 잡는다.statement_timeout · idle_in_transaction_session_timeout 에 걸려 서버가 끊은 경우. 서버 로그에 사유가 남는다.dmesg 와 서버 로그에 server process was terminated by signal 9 가 함께 남는다.서버 로그를 반드시 함께 본다. 클라이언트 쪽 예외만으로는 구분되지 않는다.
tail -n 200 /var/lib/pgsql/17/data/log/postgresql-*.log