You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非ECK环境下K8s中Elasticsearch 8.5.3账号密码自动配置咨询

为Kubernetes上的Elasticsearch 8.5.3(非ECK)自动配置用户密码

一、ELASTIC_PASSWORD环境变量无效的原因

Elasticsearch 8.x默认启用自动安全配置,启动时会自动生成内置用户的密码并存储在集群内部,手动设置的ELASTIC_PASSWORD会被自动生成的密码覆盖,因此无法生效。要自定义密码,需跳过自动安全配置或使用预配置的用户凭证文件。

二、推荐方案:通过Secret挂载预生成的用户凭证文件

Elasticsearch的内置用户、密码及角色存储在config/users和config/users_roles文件(文件型认证),可预先生成这些文件,通过Kubernetes Secret挂载到Pod中实现自动化配置。

1. 生成加密后的用户凭证

使用ES官方工具生成符合格式的密码哈希:

  • 临时启动同版本ES容器:
docker run --rm -it elasticsearch:8.5.3 bash
  • 在容器内生成用户哈希(以elastic和自定义用户custom_user为例):
# 生成elastic用户密码哈希,输入密码后输出哈希值,分配superuser角色
elasticsearch-users useradd elastic -p your_elastic_password -r superuser

# 生成custom_user用户密码哈希,分配editor角色
elasticsearch-users useradd custom_user -p your_custom_password -r editor
  • 导出凭证文件到本地:
# 替换<container_id>为实际容器ID
docker cp <container_id>/usr/share/elasticsearch/config/users ./
docker cp <container_id>/usr/share/elasticsearch/config/users_roles ./

2. 创建Kubernetes Secret

用导出的文件创建Secret:

kubectl create secret generic es-users-secret \
  --from-file=users=./users \
  --from-file=users_roles=./users_roles

3. 修改Elasticsearch Deployment清单

在Pod模板中挂载Secret,并禁用自动安全配置:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: elasticsearch
spec:
  replicas: 1
  selector:
    matchLabels:
      app: elasticsearch
  template:
    metadata:
      labels:
        app: elasticsearch
    spec:
      containers:
      - name: elasticsearch
        image: elasticsearch:8.5.3
        env:
        - name: discovery.type
          value: single-node
        # 禁用自动安全配置,避免覆盖预配置用户
        - name: xpack.security.enrollment.enabled
          value: "false"
        - name: xpack.security.autoconfiguration.enabled
          value: "false"
        # 明确启用文件型认证(默认已启用)
        - name: xpack.security.authc.realms.file.file1.enabled
          value: "true"
        ports:
        - containerPort: 9200
        volumeMounts:
        - name: es-users-volume
          mountPath: /usr/share/elasticsearch/config/users
          subPath: users
        - name: es-users-volume
          mountPath: /usr/share/elasticsearch/config/users_roles
          subPath: users_roles
        resources:
          limits:
            memory: 4Gi
            cpu: 2
      volumes:
      - name: es-users-volume
        secret:
          secretName: es-users-secret
          defaultMode: 0600 # ES要求凭证文件权限必须为600

三、验证配置

部署完成后,通过以下命令验证用户有效性(若启用HTTPS,需添加--insecure跳过证书验证):

# 验证elastic用户
curl -u elastic:your_elastic_password http://<es-service-ip>:9200/

# 验证自定义用户
curl -u custom_user:your_custom_password http://<es-service-ip>:9200/_cat/indices?v

内容的提问来源于stack exchange,提问作者khteh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 20:15:34