Ubuntu 22.04中Elasticsearch生成Kibana注册令牌失败问题求助
Elasticsearch生成Kibana注册令牌失败问题排查与解决
问题场景
在Ubuntu 22.04虚拟机中部署Elasticsearch和Kibana 8.4.0,执行令牌生成命令时出现两类错误:
kibana@kibana:/usr/share/elasticsearch/bin$ ./elasticsearch-create-enrollment-token -s kibana ./elasticsearch-env: line 78: /etc/default/elasticsearch: Permission denied kibana@kibana:/usr/share/elasticsearch/bin$ sudo ./elasticsearch-create-enrollment-token -s kibana 17:02:36.334 [main] ERROR org.elasticsearch.xpack.security.enrollment.ExternalEnrollmentTokenGenerator - Error 429when calling GET https://192.168.43.157:9200/_security/api_key. ResponseBody: {error={reason=index [.security-7] blocked by: [TOO_MANY_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];, type=cluster_block_exception, root_cause=[{reason=index [.security-7] blocked by: [TOO_MANY_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block];, type=cluster_block_exception}]}, status=429} Unable to create enrollment token for scope [kibana]
错误原因分析
权限拒绝错误:
普通用户kibana没有读取/etc/default/elasticsearch配置文件的权限,该文件属于root或elasticsearch用户组,执行令牌生成脚本需要读取此配置。429集群阻塞错误:
Elasticsearch检测到磁盘使用量超过洪水阶段水位线(flood-stage watermark),自动给核心安全索引.security-7添加了read-only-allow-delete只读限制,导致生成令牌所需的_security/api_key接口无法正常执行写入操作,返回429错误。
解决方案
1. 解决磁盘空间不足问题
优先清理虚拟机磁盘释放空间(删除日志、临时文件、未使用的软件包等);若临时无法清理,可临时调整Elasticsearch磁盘水位线阈值:
# 替换为你的elastic用户密码,水位线百分比按需修改 curl -XPUT -u elastic:你的elastic密码 "https://192.168.43.157:9200/_cluster/settings" -H "Content-Type: application/json" -d '{ "persistent": { "cluster.routing.allocation.disk.watermark.low": "70%", "cluster.routing.allocation.disk.watermark.high": "80%", "cluster.routing.allocation.disk.watermark.flood_stage": "85%" } }'
2. 解除索引只读限制
磁盘空间恢复或阈值调整后,解除所有索引的只读限制:
curl -XPUT -u elastic:你的elastic密码 "https://192.168.43.157:9200/_all/_settings" -H "Content-Type: application/json" -d '{ "index.blocks.read_only_allow_delete": null }'
3. 正确生成Kibana注册令牌
使用elasticsearch用户身份执行命令,避免权限问题:
# 方式1:sudo切换用户执行 sudo -u elastic /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana # 方式2:切换到elasticsearch用户后执行 su - elastic cd /usr/share/elasticsearch/bin ./elasticsearch-create-enrollment-token -s kibana
内容的提问来源于stack exchange,提问作者morad della3
相关产品推荐
相关产品推荐

