能否仅禁用OpenSearch的SSL/HTTPS而保留SecurityPlugin?
仅禁用OpenSearch HTTP SSL、保留SecurityPlugin的解决方案
要实现只关闭HTTP/HTTPS SSL、同时保留SecurityPlugin的需求,得确保Transport层SSL配置和HTTP层一致,还要覆盖Helm Chart默认的强制SSL设置。
问题根源
你碰到的报错,是因为Helm Chart默认可能强制开启了Transport SSL——哪怕你在opensearch.yml里设了plugins.security.ssl.transport.enabled=false,但Helm的环境变量或模板配置可能覆盖了这个值,导致Transport SSL仍被要求启用,却没提供证书路径。
修正步骤
1. 调整opensearch.yml配置
明确禁用Transport和HTTP的SSL,同时保留SecurityPlugin的基础配置:
opensearch.yml: | cluster.name: opensearch-cluster network.host: 0.0.0.0 plugins: security: ssl: transport: enabled: false enforce_hostname_verification: false http: enabled: false allow_unsafe_democertificates: false allow_default_init_securityindex: true audit.type: internal_opensearch enable_snapshot_restore_privilege: true check_snapshot_restore_write_privileges: true restapi: roles_enabled: ["all_access", "security_rest_api_access"] system_indices: enabled: true indices: [ ".opendistro-alerting-config", ".opendistro-alerting-alert*", ".opendistro-anomaly-results*", ".opendistro-anomaly-detector*", ".opendistro-anomaly-checkpoints", ".opendistro-anomaly-detection-state", ".opendistro-reports-*", ".opendistro-notifications-*", ".opendistro-notebooks", ".opendistro-asynchronous-search-response*", ]
2. 覆盖Helm的默认环境变量
在Helm的values.yaml里添加以下环境变量,避免SecurityPlugin强制启用SSL:
extraEnvs: - name: DISABLE_SECURITY_SSL_HTTP value: "true" - name: DISABLE_SECURITY_SSL_TRANSPORT value: "true"
3. 关闭Helm Chart的SSL开关
如果你的Helm Chart有单独的SSL启用配置,在values.yaml里关闭:
security: ssl: http: enabled: false transport: enabled: false
验证方法
部署完成后,检查OpenSearch日志,确认不再出现证书路径报错;同时访问HTTP端口(默认9200),验证仍需输入用户名密码(SecurityPlugin的身份验证生效),说明安全功能未被关闭。
内容的提问来源于stack exchange,提问作者JDev
相关产品推荐
相关产品推荐

