Elasticsearch迁移至OpenSearch 2.17遇NotSslRecordException错误求助
解决方案:OpenSearch 2.17.0 NotSslRecordException 错误处理
核心问题分析
错误日志中的十六进制内容转明文为GET / HTTP/1.1...,说明客户端发送的是HTTP请求,但OpenSearch的9200端口仍在监听SSL/TLS连接。本质是安全插件及SSL配置未被完全禁用,存在配置冲突或优先级覆盖问题。
具体修复步骤
1. 统一自定义容器的环境变量配置
集成测试中的CustomOpenSearchContainer需明确添加禁用安全插件和SSL的环境变量,消除配置冲突:
@Override protected void configure() { Path dockerFilePath = Paths.get("src/integration-test/resources/docker/Dockerfile"); ImageFromDockerfile dockerImage = new ImageFromDockerfile().withDockerfile(dockerFilePath); setImage(dockerImage); log.info("Starting an opensearch container."); // 强制禁用安全插件及所有SSL相关配置 withEnv("DISABLE_SECURITY_PLUGIN", "true"); withEnv("DISABLE_INSTALL_DEMO_CONFIG", "true"); withEnv("plugins.security.disabled", "true"); withEnv("plugins.security.ssl.http.enabled", "false"); withEnv("discovery.type", "single-node"); // 安全插件禁用后无需设置管理员密码,移除该配置 // withEnv("OPENSEARCH_INITIAL_ADMIN_PASSWORD", "admin"); addExposedPorts(OPENSEARCH_DEFAULT_PORT); setWaitStrategy(new HttpWaitStrategy() .forPort(OPENSEARCH_DEFAULT_PORT) .forStatusCodeMatching(response -> response == HTTP_OK) .withStartupTimeout(Duration.ofMinutes(2))); }
2. 修正opensearch.yml配置
如果挂载了自定义配置文件,确保配置无冲突,明确禁用SSL并适配单节点模式:
cluster.name: opensearch-cluster node.name: opensearch-node1 path.data: /usr/share/opensearch/data path.logs: /usr/share/opensearch/logs network.host: 0.0.0.0 http.port: 9200 # 强制禁用安全插件及SSL plugins.security.disabled: true plugins.security.ssl.http.enabled: false plugins.security.ssl.transport.enabled: false # 单节点模式下无需集群发现配置,避免冲突 discovery.type: single-node # 移除以下两行配置,与single-node模式冲突 # discovery.seed_hosts: ["opensearch-node1"] # cluster.initial_master_nodes: ["opensearch-node1"]
3. 清理Docker缓存残留
旧镜像或容器可能缓存了无效配置,执行以下命令彻底清理:
# 停止并删除容器及关联卷 docker-compose down -v # 删除自定义构建的镜像 docker rmi local_elastic # 清理未使用的镜像、容器和卷 docker system prune -f
4. 验证客户端连接协议
确保集成测试中的OpenSearch客户端使用HTTP协议连接:
RestHighLevelClient client = new RestHighLevelClient( RestClient.builder(new HttpHost(opensearchContainer.getHost(), opensearchContainer.getMappedPort(9200), "http")));
关键注意事项
- OpenSearch 2.x中,
DISABLE_SECURITY_PLUGIN=true是最高优先级环境变量,会直接禁用安全插件,优先级高于opensearch.yml配置。 discovery.type: single-node模式下,无需配置集群发现相关参数,否则会触发节点初始化冲突。- 禁用安全插件后,不要设置
OPENSEARCH_INITIAL_ADMIN_PASSWORD,该配置会触发无效的SSL初始化逻辑。
内容的提问来源于stack exchange,提问作者Richa sharma
相关产品推荐
相关产品推荐

