Overview
By default, TCBase instances are deployed in a virtual private cloud (VPC), isolated from the public network, and do not have the ability to directly access the public network.
If an instance needs to access the public network, for example, when a database UDF calls a third-party API, you can create a NAT gateway to forward the instance's public network traffic through the NAT gateway, thereby achieving secure access to the public network.
Operation Steps
Step 1: Creating a NAT Gateway
Attention:
The VPC configured for the NAT gateway must be consistent with the VPC of the TCBase instance. Otherwise, instance traffic cannot be routed to the NAT gateway.
Step 2: Configuring a Route Table
After creating a NAT gateway, you need to add a routing policy to direct public network traffic from the subnet where the instance resides to the NAT gateway. For detailed operations, see Step 2: Configuring the Route Table Associated with the Relevant Subnets in the Tencent Cloud document Getting Started with NAT Gateway, where: Destination: Enter the IP range corresponding to the destination public network.
Next Hop Type: Select Public NAT gateway.
Next Hop: Select the ID of the NAT gateway created in step 1.
Attention:
For the destination of the new route, it is recommended that you use the IP range corresponding to the destination public network. Do not configure 0.0.0.0/0 to avoid security risks caused by an excessively broad public network access scope for the instance.
Verifying Public Network Access
After the configuration is complete, you can verify whether the instance can access the public network normally by calling a third-party API through a database UDF.