Elasticsearch与Curator集群连接失败问题求助
问题描述
Elasticsearch(7.17.9)和Curator(8.0.14)部署在同一Kubernetes集群的同一命名空间内,已在Curator配置文件中指定了Elasticsearch的主机名、NodePort端口及HTTP认证信息,但Curator Job运行时仍默认尝试连接localhost:9200,导致连接被拒绝。相同的URL和认证信息可通过浏览器、Elastic View正常访问Elasticsearch,尝试使用Kubernetes DNS服务发现也未能解决问题。
报错信息
Traceback (most recent call last): File "/usr/local/lib/python3.11/site-packages/elastic_transport/_transport.py", line 342, in perform_request File "/usr/local/lib/python3.11/site-packages/elastic_transport/_node/_http_urllib3.py", line 202, in perform_request elastic_transport.ConnectionError: Connection error caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f5c78b74cd0>: Failed to establish a new connection: [Errno 111] Connection refused) 2024-04-21 09:05:18,198 INFO GET http://127.0.0.1:9200/ [status:N/A duration:0.000s] 2024-04-21 09:05:18,198 WARNING Node <Urllib3HttpNode(http://127.0.0.1:9200)> has failed for 4 times in a row, putting on 8 second timeout 2024-04-21 09:05:18,198 CRITICAL Unable to establish client connection to Elasticsearch! 2024-04-21 09:05:18,198 CRITICAL Exception encountered: Connection error caused by: ConnectionError(Connection error caused by: NewConnectionError(<urllib3.connection.HTTPConnection object at 0x7f5c79554390>: Failed to establish a new connection: [Errno 111] Connection refuse
当前Curator配置
client: hosts: - <my_cluster_master_hostname> port: <nodeport> url_prefix: use_ssl: False certificate: client_cert: client_key: ssl_no_validate: False http_auth: "username:password" timeout: 30 master_only: False
排查与解决方法
确认配置文件加载路径
Curator默认读取~/.curator/curator.yml,如果你的配置文件放在其他路径,运行Job时必须通过--config参数指定路径,示例命令:curator --config /path/to/your/curator.yml /path/to/actions.yml多数情况下问题源于Job未加载到正确的配置文件,导致使用默认的
localhost:9200。验证Kubernetes内部DNS解析
进入Curator Pod执行nslookup <my_cluster_master_hostname>,确认能解析到Elasticsearch Service的ClusterIP。如果解析失败,检查ES Service的名称和命名空间是否正确,确保Curator Pod与ES Service处于同一命名空间。改用ES Service的ClusterIP而非NodePort
同一集群内的Pod访问Elasticsearch,应直接使用Service的ClusterIP和容器默认端口(9200),NodePort是用于集群外部访问的。修改配置中的port为ES容器端口,hosts改为ES Service的名称(例如elasticsearch-master),Kubernetes DNS会自动解析到对应ClusterIP。检查YAML配置格式
YAML对缩进要求严格,确保client下的所有子项缩进一致(推荐用2个空格,禁止混合制表符和空格)。缩进错误会导致Curator无法读取配置项,进而使用默认值。手动测试Pod内连接
进入Curator Pod,执行curl http://<my_cluster_master_hostname>:<port> -u username:password,确认能正常返回ES集群信息。如果curl能通但Curator不行,说明配置未被正确加载;如果curl也不通,排查网络策略是否允许Curator Pod访问ES Service。
内容的提问来源于stack exchange,提问作者Devi Vakada

