Minikube中通过Helm安装Elasticsearch v8.5.1启动异常求助
问题描述
在本地Minikube通过Helm安装elastic/elasticsearch Chart后,Pod状态显示Running 0/1,已在开发环境设置xpack.security.enabled=false,但Pod仍无法就绪。
Pod状态信息
NAME READY STATUS RESTARTS AGE elasticsearch-master-0 0/1 Running 0 97m
日志警告信息
{"@timestamp":"2023-08-02T10:46:35.640Z", "log.level": "WARN", "message":"received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200, remoteAddress=/127.0.0.1:54200}", "ecs.version": "1.2.0","service.name":"ES_ECS","event.dataset":"elasticsearch.server","process.thread.name":"elasticsearch[elasticsearch-master-0][transport_worker][T#1]","log.logger":"org.elasticsearch.xpack.security.transport.netty4.SecurityNetty4HttpServerTransport","elasticsearch.cluster.uuid":"xjJ2up7zSGuEnCZ5cz5qDA","elasticsearch.node.id":"vF22sDghRwKJ1fe3sdQirQ","elasticsearch.node.name":"elasticsearch-master-0","elasticsearch.cluster.name":"elasticsearch"}
环境信息
- PVC:2Gi
- Minikube:Kubernetes 1.27.0
- Helm仓库:https://helm.elastic.co,Elasticsearch镜像版本:8.5.1
使用的Values.yml配置
--- clusterName: "elasticsearch" nodeGroup: "master" masterService: "" roles: - master replicas: 1 minimumMasterNodes: 1 esMajorVersion: "" esConfig: elasticsearch.yml: | xpack: security: http: ssl: enabled: false autoconfiguration: enabled: false enabled: false createCert: true esJvmOptions: {} extraEnvs: [] envFrom: [] secret: enabled: true password: "admin" secretMounts: [] hostAliases: [] image: "docker.elastic.co/elasticsearch/elasticsearch" imageTag: "8.1.1" imagePullPolicy: "IfNotPresent" podAnnotations: {} labels: {} esJavaOpts: "" resources: requests: cpu: "1000m" memory: "2Gi" limits: cpu: "1000m" memory: "2Gi" initResources: {} networkHost: "0.0.0.0" volumeClaimTemplate: accessModes: ["ReadWriteOnce"] resources: requests: storage: 2Gi rbac: create: false serviceAccountAnnotations: {} serviceAccountName: "" automountToken: true podSecurityPolicy: create: false name: "" spec: privileged: true fsGroup: rule: RunAsAny runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny volumes: - secret - configMap - persistentVolumeClaim - emptyDir persistence: enabled: true labels: enabled: false annotations: {} extraVolumes: [] extraVolumeMounts: [] extraContainers: [] extraInitContainers: [] priorityClassName: "" antiAffinityTopologyKey: "kubernetes.io/hostname" nodeAffinity: {} enableServiceLinks: true protocol: http httpPort: 9200 transportPort: 9300 service: enabled: true labels: {} labelsHeadless: {} type: ClusterIP publishNotReadyAddresses: false nodePort: "" annotations: {} httpPortName: http transportPortName: transport loadBalancerIP: "" loadBalancerSourceRanges: [] externalTrafficPolicy: "" updateStrategy: RollingUpdate maxUnavailable: 1 podSecurityContext: fsGroup: 1000 runAsUser: 1000 securityContext: capabilities: drop: - ALL runAsNonRoot: true runAsUser: 1000 terminationGracePeriod: 120 sysctlVmMaxMapCount: 262144 readinessProbe: failureThreshold: 3 initialDelaySeconds: 10 periodSeconds: 10 successThreshold: 3 timeoutSeconds: 5 schedulerName: "" imagePullSecrets: [] nodeSelector: {} tolerations: [] ingress: enabled: false annotations: {} className: "nginx" pathtype: ImplementationSpecific hosts: - host: chart-example.local paths: - path: / tls: [] nameOverride: "" fullnameOverride: "" healthNameOverride: "" lifecycle: {} sysctlInitContainer: enabled: true keystore: [] networkPolicy: elasticsearch-master-transport-client: "true" http: enabled: false transport: enabled: false tests: enabled: true
问题分析与修复方案
核心问题定位
日志警告received plaintext http traffic on an https channel表明:虽然禁用了xpack.security,但仍有SSL相关配置残留,导致就绪探针的HTTP请求被拒绝,Pod无法进入就绪状态。此外配置中存在几个冲突点:
- 镜像版本不一致:环境声明用8.5.1镜像,但Values.yml里
imageTag设为8.1.1,版本不兼容可能引发配置问题 createCert仍为true:禁用安全功能后,证书生成会导致Elasticsearch尝试启用HTTPS监听- 未完全禁用transport层SSL:仅关闭HTTP层SSL,transport层仍可能残留SSL配置
具体修复步骤
1. 统一镜像版本
将Values.yml中的imageTag修改为与环境一致的版本:
imageTag: "8.5.1"
2. 关闭证书生成
把createCert设为false,避免生成不必要的SSL证书:
createCert: false
3. 完全禁用SSL
在esConfig中补充禁用transport层SSL,确保所有SSL功能关闭:
esConfig: elasticsearch.yml: | xpack: security: http: ssl: enabled: false transport: ssl: enabled: false autoconfiguration: enabled: false enabled: false
4. 调整就绪探针(可选)
若上述修改后仍未就绪,明确指定就绪探针使用HTTP访问:
readinessProbe: failureThreshold: 3 initialDelaySeconds: 30 periodSeconds: 10 successThreshold: 3 timeoutSeconds: 5 httpGet: path: /_cluster/health?local=true port: http scheme: HTTP
5. 重新部署
执行Helm升级命令应用修改:
helm upgrade elasticsearch elastic/elasticsearch -f your-values.yml
额外验证点
- 检查PVC状态:执行
kubectl get pvc确认状态为Bound - 进入Pod内部验证服务:
kubectl exec -it elasticsearch-master-0 -- curl http://localhost:9200/_cluster/health?pretty
内容的提问来源于stack exchange,提问作者Olahzzz
相关产品推荐
相关产品推荐

