You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

cqlsh无法连接集群部分节点,求排查遗漏点

Cassandra集群部分节点cqlsh连接认证超时问题排查补充点

问题背景

cqlsh连接Cassandra集群内部分机器时持续出现认证超时错误,但连接其他节点正常。已将故障节点移出集群,system_auth键空间采用NetworkTopologyStrategy,两个数据中心的复制因子均设置为5,需排查遗漏的问题点。

错误信息

Connection error: ('Unable to connect to any servers', {'0.0.0.0': AuthenticationFailed('Failed to authenticate to 0.0.0.0: Error from server: code=0100 [Bad credentials] message="Unable to perform authentication: Operation timed out - received only 0 responses."',)})

调试命令及输出

./cqlsh --debug --ssl
Using CQL driver: <module 'cassandra' from '/usr/local/akamai/dart_apache_cassandra/bin/../lib/cassandra-driver-internal-only-3.11.0-bb96859b.zip/cassandra-driver-3.11.0-bb96859b/cassandra/__init__.py'>
Using connect timeout: 5 seconds
Using 'utf-8' encoding
Using ssl: True
Connection error: ('Unable to connect to any servers', {'0.0.0.0': AuthenticationFailed('Failed to authenticate to 0.0.0.0: Error from server: code=0100 [Bad credentials] message="Unable to perform authentication: Operation timed out - received only 0 responses."',)})

已完成的排查动作

  • 多次尝试cqlsh连接故障节点,均触发上述错误
  • nodetool status输出显示所有节点状态正常,均为UN(Up/Normal)状态
  • describecluster验证所有节点schema版本一致;系统日志存在以下警告:
    WARN  [OptionalTasks:1] 2024-02-15 14:48:59,872 CassandraRoleManager.java:379 - CassandraRoleManager跳过默认角色初始化:部分节点未就绪
    INFO  [OptionalTasks:1] 2024-02-15 14:48:59,872 CassandraRoleManager.java:418 - 初始化任务执行失败,已重新调度
    

补充排查点

  • 检查故障节点cassandra.yaml中的authenticator配置是否为PasswordAuthenticator,且与集群其他节点完全一致
  • 验证故障节点与集群内其他节点的网络连通性:在故障节点执行nc -zv <其他节点IP> 9042(CQL端口)、nc -zv <其他节点IP> 7000(Gossip端口),确认端口可正常访问
  • 手动同步故障节点的system_auth数据:执行nodetool repair system_auth,强制同步认证数据后再尝试连接
  • 检查故障节点JVM堆内存使用情况:通过nodetool info查看Heap Memory指标,内存不足可能导致认证请求处理超时
  • 验证SSL证书配置一致性:确认cqlshrc或命令行指定的SSL证书,与故障节点cassandra.yaml中client_encryption_options配置的证书匹配,且证书未过期
  • 深挖故障节点系统日志:搜索AuthenticationFailed、timeout关键词,确认是否存在节点内部处理认证请求时的底层异常
  • 确认system_auth复制策略生效:执行DESCRIBE KEYSPACE system_auth,检查输出中的复制策略及各DC复制因子是否正确设置为5
  • 尝试故障节点本地连接:执行cqlsh localhost,若本地连接也失败,说明节点自身认证服务存在问题,需检查Cassandra进程是否正常处理本地请求

内容的提问来源于stack exchange,提问作者Solver

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 07:27:50