GCP虚拟机中Trino与Elasticsearch连接拒绝问题排查及正确配置方案
Hey there, let's break down why your Trino can't connect to Elasticsearch and fix it step by step.
Core Issue: Docker Network Isolation
The main problem here is that your Trino is running inside a Docker container, and when you set elasticsearch.host=localhost in the config, that points to the container's own localhost, not the GCP VM host where Elasticsearch is running. That's exactly why you're hitting the "Connection refused" error.
Step 1: Update Trino's Elasticsearch Connector Config
Modify your elasticsearch.properties to use your GCP VM's actual IP instead of localhost:
connector.name=elasticsearch # Replace this with your GCP VM's internal IP (e.g., 10.128.0.5) or external IP (if firewall allows) elasticsearch.host=YOUR_GCP_VM_IP elasticsearch.port=9200 elasticsearch.default-schema-name=default elasticsearch.ignore-publish-address=true
Pro Tip: Using the VM's internal IP is more secure than the external one, as it stays within GCP's private network.
Step 2: Ensure Elasticsearch Is Accessible from Docker
Check Elasticsearch's Network Binding
Open your Elasticsearchelasticsearch.ymlfile and make sure it's not only bound tolocalhost. Update this setting:network.host: 0.0.0.0 # Allows connections from any IP (adjust to VM's IP if you want stricter access)Restart Elasticsearch after making this change.
Verify GCP Firewall Rules
Confirm your GCP firewall allows incoming traffic on port 9200 from:- The Docker container's network range (usually
172.17.0.0/16for default bridge network) - Or your VM's internal IP range if using private networking
- The Docker container's network range (usually
Test Connectivity from Docker Container
Run this command inside your Trino Docker container to check if it can reach Elasticsearch:curl http://YOUR_GCP_VM_IP:9200If this returns Elasticsearch's metadata, the network is working correctly.
Step 3: Clean Up Unnecessary SSL Config (For Now)
You mentioned generating a .pem file, but since you were accessing Elasticsearch via http://localhost:9200 (not HTTPS), those SSL settings are likely causing extra issues. Let's disable them temporarily until the basic connection works:
- Remove any
elasticsearch.tls.*lines from yourelasticsearch.properties - Make sure
elasticsearch.tls.enabled=false(this is the default, but it's good to confirm)
If you want to enable SSL later, you'll need to fully configure Elasticsearch to use HTTPS first, then mirror those settings in Trino (including mounting the certificate files into the Docker container so Trino can access them).
Verify the Fix
Restart your Trino Docker container with the updated config. The "Error refreshing nodes" log should disappear, and you should be able to query Elasticsearch via Trino without issues.
内容的提问来源于stack exchange,提问作者sooriyaa pr

