Solr 9.1集群创建Collection失败:solr.XSLTResponseWriter异常求助
解决Solr 9.1云集群创建Collection时XSLTResponseWriter认证失败问题
核心原因
启用BasicAuth后,Solr节点内部跨节点请求(如分片副本创建时的资源访问)未携带认证凭证,或配置集/权限设置未允许XSLT资源的访问权限,导致XSLTResponseWriter初始化失败。
步骤1:配置Solr节点内部通信的认证凭证
每个Solr节点的solr.in.sh文件中添加以下配置,确保节点间调用自动携带BasicAuth信息:
# 启用BasicAuth SOLR_AUTH_TYPE="basic" SOLR_AUTHENTICATION_OPTS="-Dbasicauth=admin:your_admin_password" # 配置内部请求的认证参数 SOLR_INTERNAL_AUTH_CLIENT_CONFIG="basicAuthUser=admin&basicAuthPassword=your_admin_password"
修改完成后重启所有Solr节点。
步骤2:更新权限配置,允许XSLT资源访问
- 编辑
security.json,为管理员角色添加XSLT相关权限及核心管理、配置编辑权限:
{ "authentication": { "class": "solr.BasicAuthPlugin", "credentials": { "admin": "your_hashed_password" } }, "authorization": { "class": "solr.RuleBasedAuthorizationPlugin", "permissions": [ {"name": "config-edit", "role": "admin"}, {"name": "core-admin", "role": "admin"}, {"name": "xslt-read", "role": "admin"}, {"name": "collection-admin", "role": "admin"} ], "user-role": { "admin": ["admin"] } } }
- 将更新后的
security.json上传到ZooKeeper:
bin/solr zk putfile -z your_zk_host:2181 /solr/security.json /path/to/your/security.json
步骤3:验证ZooKeeper认证同步(若ZK启用认证)
如果ZooKeeper启用了Digest认证,在solr.in.sh中添加ZK凭证配置,确保Solr节点能正常访问ZK集群:
SOLR_ZK_CREDS_AND_ACLS="-DzkACLProvider=org.apache.solr.common.cloud.VMParamsAllAndReadonlyDigestZkACLProvider -DzkCredentialsProvider=org.apache.solr.common.cloud.VMParamsSingleSetCredentialsDigestZkCredentialsProvider -DzkDigestUsername=zk_admin -DzkDigestPassword=zk_password"
重启Solr节点生效。
步骤4:检查配置集的XSLT配置
确认calls配置集的solrconfig.xml中XSLTResponseWriter的配置正确,且引用的XSL文件存在于配置集目录中:
<queryResponseWriter name="xslt" class="solr.XSLTResponseWriter"> <lst name="defaults"> <str name="stylesheet">default.xsl</str> </lst> </queryResponseWriter>
若不需要XSLT功能,可临时注释该配置,测试Collection创建是否成功,排除XSLT资源问题。
步骤5:重新发起Collection创建请求
使用带BasicAuth的请求重新创建Collection,并检查请求状态:
# 创建请求 curl -u admin:your_password "http://solr_host:8983/solr/admin/collections?action=CREATE&name=calls&numShards=3&replicationFactor=2&collection.configName=calls&async=create_calls" # 查看请求状态 curl -u admin:your_password "http://solr_host:8983/solr/admin/collections?action=REQUESTSTATUS&requestid=create_calls"
若仍失败,查看Solr节点日志server/logs/solr.log,定位具体的认证缺失环节。
内容的提问来源于stack exchange,提问作者laloumen
相关产品推荐
相关产品推荐

