AWS服务器部署Elasticsearch与Enterprise Search的yml配置指引
Elasticsearch & Enterprise Search Configuration for AWS EC2
Let's walk through the key configuration tweaks you need for running these services on AWS EC2, plus cloud-specific considerations to avoid common pitfalls. Based on your current configs, here's what to adjust:
1. Elasticsearch.yml Critical Adjustments
Your current config has a solid foundation, but these changes will make it production-ready on AWS:
- Network Binding: To allow Enterprise Search (or authorized external tools) to connect, set the network host to either your EC2 instance's private IP or
0.0.0.0(to listen on all interfaces):network.host: 0.0.0.0 http.port: 9200 - Memory Lock: AWS EC2 instances can suffer severe performance hits if memory swaps to disk. Enable memory locking (you'll also need to update system limits like
/etc/security/limits.confto grant theelasticsearchuser lock permissions):bootstrap.memory_lock: true - Data/Log Paths: Default paths use the root filesystem, which is often small on EC2. Mount an EBS volume and point these to it to avoid running out of space:
path.data: /mnt/elasticsearch/data path.logs: /mnt/elasticsearch/logs - Disk Watermarks: Your fixed-size watermarks work for small volumes, but for larger EBS drives, percentage-based values are more flexible and scalable:
cluster.routing.allocation.disk.watermark.low: 15% cluster.routing.allocation.disk.watermark.high: 10% cluster.routing.allocation.disk.watermark.flood_stage: 5% - Security: You already have
xpack.security.enabled: trueand API keys enabled—great practice. Just ensure you've set a strong, unique password for theelasticuser (never keep the auto-generated default password long-term).
2. Enterprise Search.yml Critical Adjustments
Most defaults work, but these changes are mandatory for a functional AWS deployment:
- Elasticsearch Connection: If both services run on the same EC2 instance,
http://127.0.0.1:9200is fine. If they're on separate instances, use the ES instance's private IP (e.g.,http://10.0.0.5:9200) to avoid public network latency and security risks. - External Access URL: This is non-negotiable for the UI to load correctly. Set it to your EC2's public IP or assigned domain:
ent_search.external_url: http://ec2-xx-xx-xx-xx.us-east-1.compute.amazonaws.com:3002 - Listen Address: Allow external connections to the UI by setting:
ent_search.listen_host: 0.0.0.0 ent_search.listen_port: 3002 - Encryption Keys: Replace the default
secret_management.encryption_keyswith a random key you generate (useopenssl rand -hex 32to create one—never use the sample value in production):secret_management.encryption_keys: [your-generated-32-byte-hex-key] - Credentials: Avoid hardcoding the Elasticsearch password. Use an environment variable instead (you can inject this via AWS EC2 user data or Secrets Manager):
elasticsearch.password: ${ELASTICSEARCH_PASSWORD} - ES Settings Modification: Set
allow_es_settings_modification: trueonly for the first startup (to let Enterprise Search configure required ES indices/templates). Once the service runs successfully, change this tofalseto prevent accidental ES config changes. - Session Key: Add a random session key to preserve user sessions across service restarts:
secret_session_key: your-generated-64-byte-hex-key
AWS-Specific Special Considerations
- Security Groups: Configure your EC2 security groups to allow:
- Inbound port 9200 only from the Enterprise Search instance (or trusted admin IPs)
- Inbound port 3002 from your user IP range (or public if you need open access)
- EBS Volumes: Use IOPS-optimized volumes (gp3 or io2) for Elasticsearch data—this service is IO-heavy, and slow storage will cripple performance.
- Heap Memory: Set Elasticsearch's heap to 50% of your EC2 instance's memory (max 32GB, since JVMs handle large heaps poorly). For example, on a 16GB instance:
export ES_JAVA_OPTS="-Xms8g -Xmx8g" - File Permissions: Ensure the
elasticsearchandenterprise-searchsystem users have read/write access to their respective data directories (e.g.,chown -R elasticsearch:elasticsearch /mnt/elasticsearch).
内容的提问来源于stack exchange,提问作者spadel
相关产品推荐
相关产品推荐

