You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot应用在GKE中连接Elasticsearch遭连接拒绝问题求助

解决GKE中Spring Boot连接Elasticsearch的Connection Refused问题

核心问题

你的Spring Boot应用配置里,spring.elasticsearch.uris设为https://localhost:9200——在Kubernetes集群环境下,Pod内部的localhost指向容器自身,而非Elasticsearch所在的Pod,这直接导致连接被拒绝。

解决方案

1. 改用Kubernetes内部服务名访问Elasticsearch

通过ECK部署的Elasticsearch会自动生成对应的Service,你需要用这个Service的名称作为访问地址:

  • 先执行命令查看Elasticsearch的HTTP服务名:
    kubectl get svc -n <你的命名空间>
    
    ECK部署的ES HTTP服务命名格式通常为<ES实例名称>-es-http,比如实例名为quickstart,服务名就是quickstart-es-http。
  • 修改Spring Boot配置中的uris:
    spring.elasticsearch.uris=https://<ES服务名>:9200
    
    示例(假设服务名为quickstart-es-http):
    spring.elasticsearch.uris=https://quickstart-es-http:9200
    

2. 处理TLS证书验证(ECK默认启用HTTPS)

ECK部署的Elasticsearch默认使用自签证书开启HTTPS,Spring Boot需要信任该证书才能正常连接:

方式一:挂载ECK生成的CA证书(生产环境推荐)

  • 获取ECK生成的CA证书:
    kubectl get secret <ES实例名称>-es-ca-cert -n <你的命名空间> -o jsonpath='{.data.ca\.crt}' | base64 -d > ca.crt
    
  • 将证书作为Volume挂载到Spring Boot Pod,再在配置中指定信任证书路径:
    spring.elasticsearch.ssl.truststore-location=file:/path/to/mounted/ca.crt
    spring.elasticsearch.ssl.truststore-type=PEM
    

方式二:禁用证书验证(仅测试环境使用)

添加配置跳过证书验证:

spring.elasticsearch.ssl.verification-mode=none

3. 跨命名空间访问的额外配置

如果Spring Boot和Elasticsearch不在同一个Kubernetes命名空间,需要使用完整的服务域名:

spring.elasticsearch.uris=https://<ES服务名>.<ES所在命名空间>.svc.cluster.local:9200

验证修改

更新Spring Boot应用配置并重新部署后,检查应用日志是否仍存在连接拒绝异常。

内容的提问来源于stack exchange,提问作者kafrlust

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 11:56:00