You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Minikube中通过Helm安装Elasticsearch v8.5.1启动异常求助

问题描述

在本地Minikube通过Helm安装elastic/elasticsearch Chart后,Pod状态显示Running 0/1,已在开发环境设置xpack.security.enabled=false,但Pod仍无法就绪。

Pod状态信息

NAME                     READY   STATUS    RESTARTS   AGE
elasticsearch-master-0   0/1     Running   0          97m

日志警告信息

{"@timestamp":"2023-08-02T10:46:35.640Z", "log.level": "WARN", "message":"received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200, remoteAddress=/127.0.0.1:54200}", "ecs.version": "1.2.0","service.name":"ES_ECS","event.dataset":"elasticsearch.server","process.thread.name":"elasticsearch[elasticsearch-master-0][transport_worker][T#1]","log.logger":"org.elasticsearch.xpack.security.transport.netty4.SecurityNetty4HttpServerTransport","elasticsearch.cluster.uuid":"xjJ2up7zSGuEnCZ5cz5qDA","elasticsearch.node.id":"vF22sDghRwKJ1fe3sdQirQ","elasticsearch.node.name":"elasticsearch-master-0","elasticsearch.cluster.name":"elasticsearch"}

环境信息

  • PVC:2Gi
  • Minikube:Kubernetes 1.27.0
  • Helm仓库:https://helm.elastic.co,Elasticsearch镜像版本:8.5.1

使用的Values.yml配置

---
clusterName: "elasticsearch"
nodeGroup: "master"

masterService: ""

roles:
  - master


replicas: 1
minimumMasterNodes: 1

esMajorVersion: ""

esConfig: 
 elasticsearch.yml: |
  xpack:
    security:
      http:
        ssl:
          enabled: false
      autoconfiguration:
        enabled: false
      enabled: false


createCert: true

esJvmOptions: {}
extraEnvs: []

envFrom: []



secret:
  enabled: true
  password: "admin" 


secretMounts: []

hostAliases: []


image: "docker.elastic.co/elasticsearch/elasticsearch"
imageTag: "8.1.1"
imagePullPolicy: "IfNotPresent"

podAnnotations: {}


labels: {}

esJavaOpts: "" 
resources:
  requests:
    cpu: "1000m"
    memory: "2Gi"
  limits:
    cpu: "1000m"
    memory: "2Gi"

initResources: {}

networkHost: "0.0.0.0"

volumeClaimTemplate:
  accessModes: ["ReadWriteOnce"]
  resources:
    requests:
      storage: 2Gi

rbac:
  create: false
  serviceAccountAnnotations: {}
  serviceAccountName: ""
  automountToken: true

podSecurityPolicy:
  create: false
  name: ""
  spec:
    privileged: true
    fsGroup:
      rule: RunAsAny
    runAsUser:
      rule: RunAsAny
    seLinux:
      rule: RunAsAny
    supplementalGroups:
      rule: RunAsAny
    volumes:
      - secret
      - configMap
      - persistentVolumeClaim
      - emptyDir

persistence:
  enabled: true
  labels:
    enabled: false
  annotations: {}

extraVolumes: []


extraVolumeMounts: []


extraContainers: []


extraInitContainers: []

priorityClassName: ""

antiAffinityTopologyKey: "kubernetes.io/hostname"

nodeAffinity: {}

enableServiceLinks: true

protocol: http
httpPort: 9200
transportPort: 9300

service:
  enabled: true
  labels: {}
  labelsHeadless: {}
  type: ClusterIP

  publishNotReadyAddresses: false
  nodePort: ""
  annotations: {}
  httpPortName: http
  transportPortName: transport
  loadBalancerIP: ""
  loadBalancerSourceRanges: []
  externalTrafficPolicy: ""

updateStrategy: RollingUpdate


maxUnavailable: 1

podSecurityContext:
  fsGroup: 1000
  runAsUser: 1000

securityContext:
  capabilities:
    drop:
      - ALL
  runAsNonRoot: true
  runAsUser: 1000


terminationGracePeriod: 120

sysctlVmMaxMapCount: 262144

readinessProbe:
  failureThreshold: 3
  initialDelaySeconds: 10
  periodSeconds: 10
  successThreshold: 3
  timeoutSeconds: 5




schedulerName: ""

imagePullSecrets: []
nodeSelector: {}
tolerations: []


ingress:
  enabled: false
  annotations: {}
  className: "nginx"
  pathtype: ImplementationSpecific
  hosts:
    - host: chart-example.local
      paths:
        - path: /
  tls: []


nameOverride: ""
fullnameOverride: ""
healthNameOverride: ""

lifecycle: {}
sysctlInitContainer:
  enabled: true
keystore: []
networkPolicy:
  elasticsearch-master-transport-client: "true"

  http:
    enabled: false
  transport:
    enabled: false


tests:
  enabled: true
问题分析与修复方案

核心问题定位

日志警告received plaintext http traffic on an https channel表明:虽然禁用了xpack.security,但仍有SSL相关配置残留,导致就绪探针的HTTP请求被拒绝,Pod无法进入就绪状态。此外配置中存在几个冲突点:

  1. 镜像版本不一致:环境声明用8.5.1镜像,但Values.yml里imageTag设为8.1.1,版本不兼容可能引发配置问题
  2. createCert仍为true:禁用安全功能后,证书生成会导致Elasticsearch尝试启用HTTPS监听
  3. 未完全禁用transport层SSL:仅关闭HTTP层SSL,transport层仍可能残留SSL配置

具体修复步骤

1. 统一镜像版本

将Values.yml中的imageTag修改为与环境一致的版本:

imageTag: "8.5.1"

2. 关闭证书生成

把createCert设为false,避免生成不必要的SSL证书:

createCert: false

3. 完全禁用SSL

在esConfig中补充禁用transport层SSL,确保所有SSL功能关闭:

esConfig: 
 elasticsearch.yml: |
  xpack:
    security:
      http:
        ssl:
          enabled: false
      transport:
        ssl:
          enabled: false
      autoconfiguration:
        enabled: false
      enabled: false

4. 调整就绪探针(可选)

若上述修改后仍未就绪,明确指定就绪探针使用HTTP访问:

readinessProbe:
  failureThreshold: 3
  initialDelaySeconds: 30
  periodSeconds: 10
  successThreshold: 3
  timeoutSeconds: 5
  httpGet:
    path: /_cluster/health?local=true
    port: http
    scheme: HTTP

5. 重新部署

执行Helm升级命令应用修改:

helm upgrade elasticsearch elastic/elasticsearch -f your-values.yml

额外验证点

  • 检查PVC状态:执行kubectl get pvc确认状态为Bound
  • 进入Pod内部验证服务:
kubectl exec -it elasticsearch-master-0 -- curl http://localhost:9200/_cluster/health?pretty

内容的提问来源于stack exchange,提问作者Olahzzz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 15:44:53