Ubuntu 22.04中ElasticSearch启动失败,求排查配置文件问题
Elasticsearch 8.4.3启动失败问题排查与修复
问题场景
在Ubuntu 22.04系统通过官方deb包安装Elasticsearch 8.4.3后,执行sudo systemctl start elasticsearch.service启动失败,错误信息如下:
systemctl状态输出
Job for elasticsearch.service failed because the control process exited with error code. sudo systemctl status elasticsearch.service: elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since Fri 2022-10-14 02:30:18 PKT; 4min 51s ago
日志报错
org.elasticsearch.ElasticsearchSecurityException: invalid configuration for xpack.security.transport.ssl - [xpack.security.transport.ssl.enabled] is > at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:67) ~[elasticsearch-8.4.3.jar:?]
当前elasticsearch.yml配置
======================== Elasticsearch Configuration ========================= NOTE: Elasticsearch comes with reasonable defaults for most settings. Before you set out to tweak and tune the configuration, make sure you understand what are you trying to accomplish and the consequences. The primary way of configuring a node is via this file. This template lists the most important settings you may want to configure for a production cluster. Please consult the documentation for further information on configuration options: https://www.elastic.co/guide/en/elasticsearch/reference/index.html ---------------------------------- Cluster ---------------------------------- Use a descriptive name for your cluster: cluster.name: my-application ------------------------------------ Node ------------------------------------ Use a descriptive name for the node: node.name: node-1 Add custom attributes to the node: node.attr.rack: r1 ----------------------------------- Paths ------------------------------------ Path to directory where to store the data (separate multiple locations by comma): path.data: /var/lib/elasticsearch Path to log files: path.logs: /var/log/elasticsearch ----------------------------------- Memory ----------------------------------- Lock the memory on startup: bootstrap.memory_lock: true Make sure that the heap size is set to about half the memory available on the system and that the owner of the process is allowed to use this limit. Elasticsearch performs poorly when the system is swapping the memory. ---------------------------------- Network ----------------------------------- By default Elasticsearch is only accessible on localhost. Set a different address here to expose this node on the network: network.host: localhost By default Elasticsearch listens for HTTP traffic on the first free port it finds starting at 9200. Set a specific HTTP port here: http.port: 9200 For more information, consult the network module documentation. --------------------------------- Discovery ---------------------------------- Pass an initial list of hosts to perform discovery when this node is started: The default list of hosts is ["127.0.0.1", "[::1]"] discovery.seed_hosts: ["host1", "host2"] Bootstrap the cluster using an initial set of master-eligible nodes: cluster.initial_master_nodes: ["node-1", "node-2"] For more information, consult the discovery and cluster formation module documentation. --------------------------------- Readiness ---------------------------------- Enable an unauthenticated TCP readiness endpoint on localhost readiness.port: 9399 ---------------------------------- Various ----------------------------------- Allow wildcard deletion of indices: action.destructive_requires_name: false
问题分析与修复方案
你的elasticsearch.yml存在两处关键问题,导致启动失败:
1. 集群发现配置错误
当前配置的discovery.seed_hosts: ["host1", "host2"]和cluster.initial_master_nodes: ["node-1", "node-2"]是多节点集群的配置,但你实际是单节点部署,无效的主机名会导致节点无法完成集群初始化,同时结合X-Pack默认安全配置触发SSL错误。
修改方式:
将这两行改为单节点适配的配置:
discovery.seed_hosts: ["127.0.0.1", "[::1]"] cluster.initial_master_nodes: ["node-1"]
2. X-Pack传输层SSL配置缺失
Elasticsearch 8.x版本默认启用了X-Pack安全模块的传输层SSL,但你的配置中未设置任何SSL相关参数,导致系统抛出ElasticsearchSecurityException。
提供两种修复方案:
方案一:禁用传输层SSL(仅适用于测试/开发环境)
在elasticsearch.yml末尾添加以下配置:
xpack.security.transport.ssl.enabled: false
方案二:配置SSL证书(适用于生产环境)
- 生成自签名SSL证书,执行以下命令:
sudo /usr/share/elasticsearch/bin/elasticsearch-certutil cert -out /etc/elasticsearch/certs/elastic-certificates.p12 -pass ""
- 修改证书目录权限:
sudo chown -R elasticsearch:elasticsearch /etc/elasticsearch/certs
- 在
elasticsearch.yml中添加SSL配置:
xpack.security.transport.ssl.enabled: true xpack.security.transport.ssl.verification_mode: certificate xpack.security.transport.ssl.client_authentication: required xpack.security.transport.ssl.keystore.path: certs/elastic-certificates.p12 xpack.security.transport.ssl.truststore.path: certs/elastic-certificates.p12
额外注意事项
- 若启用了
bootstrap.memory_lock: true,需确保系统已给elasticsearch用户分配足够的内存锁定权限,可在/etc/security/limits.conf中添加:
elasticsearch soft memlock unlimited elasticsearch hard memlock unlimited
- 修改配置后,重启Elasticsearch服务:
sudo systemctl restart elasticsearch.service
内容的提问来源于stack exchange,提问作者Asif khAn
相关产品推荐
相关产品推荐

