ClickHouse Keeper安全通道连接异常:无效四字命令与连接丢失
针对你在ClickHouse 23.1.3版本下测试SSL加密复制功能遇到的问题(无SSL时正常,启用后Keeper报"invalid four letter command"、"Connection loss",SSL连接意外关闭),可以按以下步骤排查:
检查四字命令的SSL适配配置
ClickHouse Keeper在SSL模式下默认可能限制四字命令的使用,需在config.xml的Keeper配置段显式开启:<keeper_server> <tcp_port>9181</tcp_port> <ssl> <enable>true</enable> <certificate_file>/path/to/server.crt</certificate_file> <private_key_file>/path/to/server.key</private_key_file> <ca_file>/path/to/ca.crt</ca_file> </ssl> <allow_4lw_commands>true</allow_4lw_commands> </keeper_server>同时确认证书文件路径正确,且ClickHouse进程有读取权限。
验证SSL证书有效性与兼容性
用openssl s_client -connect <keeper_host>:<ssl_port>手动测试SSL握手,确认证书链完整、无过期,私钥与证书匹配。注意23.x版本不支持带密码的私钥,需确保私钥未加密。核对复制节点的ZooKeeper客户端SSL配置
所有参与复制的ClickHouse节点必须正确配置SSL连接Keeper,示例配置:<zookeeper> <node> <host>keeper1</host> <port>9181</port> <ssl> <enable>true</enable> <certificate_file>/path/to/client.crt</certificate_file> <private_key_file>/path/to/client.key</private_key_file> <ca_file>/path/to/ca.crt</ca_file> </ssl> </node> </zookeeper>避免混合配置SSL与非SSL节点,确保客户端与Keeper端的CA证书一致。
测试SSL环境下的四字命令
非SSL环境的echo ruok | nc方式在SSL下无效,需用SSL隧道测试:openssl s_client -connect <host>:<port> -quiet <<< "ruok"若无法返回
imok,说明Keeper对SSL下的四字命令支持有问题,可尝试升级到23.8及以上版本(该版本修复了部分SSL四字命令的兼容性Bug)。分析Keeper日志定位细节
查看/var/log/clickhouse-server/clickhouse-keeper.log,寻找SSL握手失败的具体原因(如协议版本不匹配、证书验证错误),可在SSL配置中显式指定协议版本:<ssl> <enable>true</enable> <protocol>TLSv1.2</protocol> <!-- 其他证书配置 --> </ssl>排查网络与防火墙限制
确认两台服务器的SSL端口(默认9181)双向连通,防火墙/安全组未阻断该端口的TCP流量,可通过nc -zv <host> <port>测试端口可达性。
内容的提问来源于stack exchange,提问作者Jae

