You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Elasticsearch迁移至OpenSearch 2.17遇NotSslRecordException错误求助

解决方案:OpenSearch 2.17.0 NotSslRecordException 错误处理

核心问题分析

错误日志中的十六进制内容转明文为GET / HTTP/1.1...,说明客户端发送的是HTTP请求,但OpenSearch的9200端口仍在监听SSL/TLS连接。本质是安全插件及SSL配置未被完全禁用,存在配置冲突或优先级覆盖问题。

具体修复步骤

1. 统一自定义容器的环境变量配置

集成测试中的CustomOpenSearchContainer需明确添加禁用安全插件和SSL的环境变量,消除配置冲突:

@Override
protected void configure() {
    Path dockerFilePath = Paths.get("src/integration-test/resources/docker/Dockerfile");
    ImageFromDockerfile dockerImage = new ImageFromDockerfile().withDockerfile(dockerFilePath);

    setImage(dockerImage);

    log.info("Starting an opensearch container.");
    // 强制禁用安全插件及所有SSL相关配置
    withEnv("DISABLE_SECURITY_PLUGIN", "true");
    withEnv("DISABLE_INSTALL_DEMO_CONFIG", "true");
    withEnv("plugins.security.disabled", "true");
    withEnv("plugins.security.ssl.http.enabled", "false");
    withEnv("discovery.type", "single-node");
    // 安全插件禁用后无需设置管理员密码,移除该配置
    // withEnv("OPENSEARCH_INITIAL_ADMIN_PASSWORD", "admin");
    addExposedPorts(OPENSEARCH_DEFAULT_PORT);
    setWaitStrategy(new HttpWaitStrategy()
            .forPort(OPENSEARCH_DEFAULT_PORT)
            .forStatusCodeMatching(response -> response == HTTP_OK)
            .withStartupTimeout(Duration.ofMinutes(2)));
}

2. 修正opensearch.yml配置

如果挂载了自定义配置文件,确保配置无冲突,明确禁用SSL并适配单节点模式:

cluster.name: opensearch-cluster
node.name: opensearch-node1
path.data: /usr/share/opensearch/data
path.logs: /usr/share/opensearch/logs
network.host: 0.0.0.0
http.port: 9200

# 强制禁用安全插件及SSL
plugins.security.disabled: true
plugins.security.ssl.http.enabled: false
plugins.security.ssl.transport.enabled: false

# 单节点模式下无需集群发现配置,避免冲突
discovery.type: single-node
# 移除以下两行配置,与single-node模式冲突
# discovery.seed_hosts: ["opensearch-node1"]
# cluster.initial_master_nodes: ["opensearch-node1"]

3. 清理Docker缓存残留

旧镜像或容器可能缓存了无效配置,执行以下命令彻底清理:

# 停止并删除容器及关联卷
docker-compose down -v
# 删除自定义构建的镜像
docker rmi local_elastic
# 清理未使用的镜像、容器和卷
docker system prune -f

4. 验证客户端连接协议

确保集成测试中的OpenSearch客户端使用HTTP协议连接:

RestHighLevelClient client = new RestHighLevelClient(
        RestClient.builder(new HttpHost(opensearchContainer.getHost(), opensearchContainer.getMappedPort(9200), "http")));

关键注意事项

  • OpenSearch 2.x中,DISABLE_SECURITY_PLUGIN=true是最高优先级环境变量,会直接禁用安全插件,优先级高于opensearch.yml配置。
  • discovery.type: single-node模式下,无需配置集群发现相关参数,否则会触发节点初始化冲突。
  • 禁用安全插件后,不要设置OPENSEARCH_INITIAL_ADMIN_PASSWORD,该配置会触发无效的SSL初始化逻辑。

内容的提问来源于stack exchange,提问作者Richa sharma

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 09:59:49