本地开发时Docker中Elasticsearch禁用SSL失败求助
解决Elasticsearch Docker Compose禁用SSL后无法启动的问题
问题根源
官方默认docker-compose.yml包含大量依赖SSL和安全功能的配置,仅修改三个xpack开关不足以适配禁用SSL的场景,关键冲突点包括:
setup服务仍尝试通过HTTPS连接Elasticsearch,且执行证书生成、密码设置等不必要操作- Elasticsearch、Kibana、Enterprise Search的配置仍保留SSL相关参数
- 健康检查脚本仍使用HTTPS请求
修正后的完整配置
以下是适配无SSL、无安全认证的docker-compose.yml(供开发环境使用):
version: "2.2" services: es01: image: docker.elastic.co/elasticsearch/elasticsearch:${STACK_VERSION} volumes: - esdata01:/usr/share/elasticsearch/data ports: - ${ES_PORT}:9200 environment: - node.name=es01 - cluster.name=${CLUSTER_NAME} - cluster.initial_master_nodes=es01,es02,es03 - discovery.seed_hosts=es02,es03 - bootstrap.memory_lock=true - xpack.security.enabled=false - xpack.security.http.ssl.enabled=false - xpack.security.transport.ssl.enabled=false - xpack.license.self_generated.type=${LICENSE} mem_limit: ${MEM_LIMIT} ulimits: memlock: soft: -1 hard: -1 healthcheck: test: [ "CMD-SHELL", "curl -s http://localhost:9200 | grep -q 'You Know, for Search'" ] interval: 10s timeout: 10s retries: 120 es02: depends_on: - es01 image: docker.elastic.co/elasticsearch/elasticsearch:${STACK_VERSION} volumes: - esdata02:/usr/share/elasticsearch/data environment: - node.name=es02 - cluster.name=${CLUSTER_NAME} - cluster.initial_master_nodes=es01,es02,es03 - discovery.seed_hosts=es01,es03 - bootstrap.memory_lock=true - xpack.security.enabled=false - xpack.security.http.ssl.enabled=false - xpack.security.transport.ssl.enabled=false - xpack.license.self_generated.type=${LICENSE} mem_limit: ${MEM_LIMIT} ulimits: memlock: soft: -1 hard: -1 healthcheck: test: [ "CMD-SHELL", "curl -s http://localhost:9200 | grep -q 'You Know, for Search'" ] interval: 10s timeout: 10s retries: 120 es03: depends_on: - es02 image: docker.elastic.co/elasticsearch/elasticsearch:${STACK_VERSION} volumes: - esdata03:/usr/share/elasticsearch/data environment: - node.name=es03 - cluster.name=${CLUSTER_NAME} - cluster.initial_master_nodes=es01,es02,es03 - discovery.seed_hosts=es01,es02 - bootstrap.memory_lock=true - xpack.security.enabled=false - xpack.security.http.ssl.enabled=false - xpack.security.transport.ssl.enabled=false - xpack.license.self_generated.type=${LICENSE} mem_limit: ${MEM_LIMIT} ulimits: memlock: soft: -1 hard: -1 healthcheck: test: [ "CMD-SHELL", "curl -s http://localhost:9200 | grep -q 'You Know, for Search'" ] interval: 10s timeout: 10s retries: 120 kibana: depends_on: es01: condition: service_healthy es02: condition: service_healthy es03: condition: service_healthy image: docker.elastic.co/kibana/kibana:${STACK_VERSION} volumes: - kibanadata:/usr/share/kibana/data ports: - ${KIBANA_PORT}:5601 environment: - SERVERNAME=kibana - ELASTICSEARCH_HOSTS=http://es01:9200 - ENTERPRISESEARCH_HOST=http://enterprisesearch:${ENTERPRISE_SEARCH_PORT} mem_limit: ${MEM_LIMIT} healthcheck: test: [ "CMD-SHELL", "curl -s -I http://localhost:5601 | grep -q 'HTTP/1.1 302 Found'" ] interval: 10s timeout: 10s retries: 120 enterprisesearch: depends_on: es01: condition: service_healthy kibana: condition: service_healthy image: docker.elastic.co/enterprise-search/enterprise-search:${STACK_VERSION} volumes: - enterprisesearchdata:/usr/share/enterprise-search/config ports: - ${ENTERPRISE_SEARCH_PORT}:3002 environment: - SERVERNAME=enterprisesearch - secret_management.encryption_keys=[${ENCRYPTION_KEYS}] - allow_es_settings_modification=true - elasticsearch.host=http://es01:9200 - elasticsearch.ssl.enabled=false - kibana.external_url=http://kibana:5601 mem_limit: ${MEM_LIMIT} healthcheck: test: [ "CMD-SHELL", "curl -s -I http://localhost:3002 | grep -q 'HTTP/1.1 302 Found'" ] interval: 10s timeout: 10s retries: 120 volumes: esdata01: driver: local esdata02: driver: local esdata03: driver: local enterprisesearchdata: driver: local kibanadata: driver: local
关键修改说明
- 移除setup服务:该服务仅用于证书生成和密码配置,禁用安全后完全不需要
- Elasticsearch调整:
- 删除所有SSL相关配置项(如
xpack.security.http.ssl.key等) - 修改健康检查为HTTP请求,验证Elasticsearch默认响应文本
- 删除所有SSL相关配置项(如
- Kibana调整:
- 将
ELASTICSEARCH_HOSTS改为HTTP协议 - 删除安全认证相关的
ELASTICSEARCH_USERNAME、ELASTICSEARCH_PASSWORD和SSL证书配置
- 将
- Enterprise Search调整:
- 将
elasticsearch.host改为HTTP协议 - 设置
elasticsearch.ssl.enabled=false并移除证书路径配置
- 将
注意事项
- 该配置仅适用于开发环境,生产环境必须启用SSL和安全认证
- 启动前需确保
.env文件中的环境变量(如STACK_VERSION、MEM_LIMIT等)已正确设置 - 若需要保留用户名密码认证但禁用SSL,需保持
xpack.security.enabled=true,仅关闭SSL相关开关,并调整原setup服务的curl请求为HTTP
内容的提问来源于stack exchange,提问作者Dživo Jelić
相关产品推荐
相关产品推荐

