You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS服务器部署Elasticsearch与Enterprise Search的yml配置指引

Elasticsearch & Enterprise Search Configuration for AWS EC2

Let's walk through the key configuration tweaks you need for running these services on AWS EC2, plus cloud-specific considerations to avoid common pitfalls. Based on your current configs, here's what to adjust:

1. Elasticsearch.yml Critical Adjustments

Your current config has a solid foundation, but these changes will make it production-ready on AWS:

  • Network Binding: To allow Enterprise Search (or authorized external tools) to connect, set the network host to either your EC2 instance's private IP or 0.0.0.0 (to listen on all interfaces):
    network.host: 0.0.0.0
    http.port: 9200
    
  • Memory Lock: AWS EC2 instances can suffer severe performance hits if memory swaps to disk. Enable memory locking (you'll also need to update system limits like /etc/security/limits.conf to grant the elasticsearch user lock permissions):
    bootstrap.memory_lock: true
    
  • Data/Log Paths: Default paths use the root filesystem, which is often small on EC2. Mount an EBS volume and point these to it to avoid running out of space:
    path.data: /mnt/elasticsearch/data
    path.logs: /mnt/elasticsearch/logs
    
  • Disk Watermarks: Your fixed-size watermarks work for small volumes, but for larger EBS drives, percentage-based values are more flexible and scalable:
    cluster.routing.allocation.disk.watermark.low: 15%
    cluster.routing.allocation.disk.watermark.high: 10%
    cluster.routing.allocation.disk.watermark.flood_stage: 5%
    
  • Security: You already have xpack.security.enabled: true and API keys enabled—great practice. Just ensure you've set a strong, unique password for the elastic user (never keep the auto-generated default password long-term).

2. Enterprise Search.yml Critical Adjustments

Most defaults work, but these changes are mandatory for a functional AWS deployment:

  • Elasticsearch Connection: If both services run on the same EC2 instance, http://127.0.0.1:9200 is fine. If they're on separate instances, use the ES instance's private IP (e.g., http://10.0.0.5:9200) to avoid public network latency and security risks.
  • External Access URL: This is non-negotiable for the UI to load correctly. Set it to your EC2's public IP or assigned domain:
    ent_search.external_url: http://ec2-xx-xx-xx-xx.us-east-1.compute.amazonaws.com:3002
    
  • Listen Address: Allow external connections to the UI by setting:
    ent_search.listen_host: 0.0.0.0
    ent_search.listen_port: 3002
    
  • Encryption Keys: Replace the default secret_management.encryption_keys with a random key you generate (use openssl rand -hex 32 to create one—never use the sample value in production):
    secret_management.encryption_keys: [your-generated-32-byte-hex-key]
    
  • Credentials: Avoid hardcoding the Elasticsearch password. Use an environment variable instead (you can inject this via AWS EC2 user data or Secrets Manager):
    elasticsearch.password: ${ELASTICSEARCH_PASSWORD}
    
  • ES Settings Modification: Set allow_es_settings_modification: true only for the first startup (to let Enterprise Search configure required ES indices/templates). Once the service runs successfully, change this to false to prevent accidental ES config changes.
  • Session Key: Add a random session key to preserve user sessions across service restarts:
    secret_session_key: your-generated-64-byte-hex-key
    

AWS-Specific Special Considerations

  • Security Groups: Configure your EC2 security groups to allow:
    • Inbound port 9200 only from the Enterprise Search instance (or trusted admin IPs)
    • Inbound port 3002 from your user IP range (or public if you need open access)
  • EBS Volumes: Use IOPS-optimized volumes (gp3 or io2) for Elasticsearch data—this service is IO-heavy, and slow storage will cripple performance.
  • Heap Memory: Set Elasticsearch's heap to 50% of your EC2 instance's memory (max 32GB, since JVMs handle large heaps poorly). For example, on a 16GB instance:
    export ES_JAVA_OPTS="-Xms8g -Xmx8g"
    
  • File Permissions: Ensure the elasticsearch and enterprise-search system users have read/write access to their respective data directories (e.g., chown -R elasticsearch:elasticsearch /mnt/elasticsearch).

内容的提问来源于stack exchange,提问作者spadel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 10:42:56