You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JanusGraph连接开启认证的Elasticsearch报401未授权错误求助

JanusGraph连接开启认证的Elasticsearch报401未授权错误排查与解决

在Kubernetes集群中分别部署JanusGraph和Elasticsearch容器,Elasticsearch已启用认证(xpack.security.enabled: true),且已在JanusGraph配置中提供正确凭据,但JanusGraph日志出现以下401未授权错误:

15:15:42 WARN  org.janusgraph.diskstorage.es.rest.RestElasticSearchClient.getMajorVersion - Unable to determine Elasticsearch server version. Default to EIGHT.
org.elasticsearch.client.ResponseException: method [GET], host [http://elasticsearch-headless:9200], URI [/], status line [HTTP/1.1 401 Unauthorized]
{"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}}],"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}},"status":401}

已尝试操作

  • 验证Elasticsearch认证:从JanusGraph Pod手动用curl测试凭据可正常获取Elasticsearch响应:
    kubectl exec -it <janusgraph-pod-name> -- curl -u <elasticsearch-username>:<elasticsearch-password> http://cassandra-dravoka-elasticsearch-headless:9200 
    
  • 配置JanusGraph环境变量:在JanusGraph部署中设置以下环境变量:
    - name: INDEX_SEARCH_BACKEND
      value: "elasticsearch"
    - name: INDEX_SEARCH_HOSTNAME
      value: "elasticsearch-headless"
    - name: INDEX_SEARCH_PORT
      value: "9200"
    - name: INDEX_SEARCH_ELASTICSEARCH_USERNAME
      value: "<elasticsearch-username>"
    - name: INDEX_SEARCH_ELASTICSEARCH_PASSWORD
      value: "<elasticsearch-password>"
    - name: INDEX_SEARCH_ELASTICSEARCH_VERSION
      value: "7"
    
  • 检查Elasticsearch日志:未发现JanusGraph请求相关日志,推测请求未到达或被静默拒绝。
  • 验证网络连通性:从JanusGraph Pod测试到Elasticsearch的网络连通性。

环境详情

  • JanusGraph版本:0.6.3
  • Elasticsearch版本:8.x
  • Elasticsearch配置:xpack.security.enabled: true
  • JanusGraph配置:后端为Cassandra,索引后端为Elasticsearch

预期与实际行为

  • 预期行为:JanusGraph应使用提供的凭据完成与Elasticsearch的认证并成功连接。
  • 实际行为:JanusGraph认证失败,日志报401未授权错误。

疑问

  1. JanusGraph是否需额外配置以正确传递Authorization头?
  2. 如何进一步调试定位根本原因?

求助需求

需解决401未授权错误,确保JanusGraph可成功连接开启认证的Elasticsearch。


内容的提问来源于stack exchange,提问作者Ravindra Gupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 11:27:25