Docker Swarm configs挂载elasticsearch.yml报只读文件系统错误
Docker Swarm部署Elasticsearch自定义配置只读报错解决方案
问题现象
在Docker Swarm集群部署包含Mongo、Graylog、Elasticsearch的Graylog栈时,通过Swarm config将自定义elasticsearch.yml挂载到Elasticsearch容器的/usr/share/elasticsearch/config/elasticsearch.yml路径,服务启动失败,报错如下:
warning: no-jdk distributions that do not bundle a JDK are deprecated and will be removed in a future release chown: /usr/share/elasticsearch/config/elasticsearch.yml: Read-only file system
约束要求:解决方案不得使用volumes挂载、不得构建自定义镜像。
报错根因
- Docker Swarm的config资源默认以只读文件系统形式挂载到容器内,挂载后的文件不支持chown、chmod等修改属主、权限的操作,配置中写的
mode: 777仅作用于config挂载前的源端,不会改变挂载后的只读属性。 - 所用
secureimages/elasticsearch-oss:7.10.2-alpine-3.13.2镜像的入口启动脚本,会在服务启动前递归修改配置目录下所有文件的属主为Elasticsearch运行用户,碰到只读挂载的config文件时直接触发报错退出。
可行方案
方案一:调整配置挂载路径,通过环境变量指定配置目录
完全符合无volume、无自定义镜像的约束,操作步骤:
- 调整Swarm config的挂载目标路径,不要直接覆盖原配置目录下的
elasticsearch.yml,改为挂载到容器内独立的、不会被入口脚本扫描执行chown的路径,比如/custom-es-config/elasticsearch.yml - 为Elasticsearch服务添加
ES_PATH_CONF=/custom-es-config环境变量,指定Elasticsearch启动时从该路径加载配置 - 若需要保留镜像内置的jvm参数、日志配置等内容,可先启动临时容器导出原配置目录下的所有文件,和自定义配置合并后统一做成Swarm config挂载到
/custom-es-config目录下,避免配置缺失。
对应配置片段参考:
services: elasticsearch: image: secureimages/elasticsearch-oss:7.10.2-alpine-3.13.2 environment: - ES_PATH_CONF=/custom-es-config # 保留原有Elasticsearch相关环境变量,如集群名称、节点角色配置等 configs: - source: elasticsearch_config mode: 0444 target: /custom-es-config/elasticsearch.yml # 其余需要的配置文件(如jvm.options)同理挂载到/custom-es-config目录即可 ulimits: memlock: soft: -1 hard: -1 deploy: resources: limits: memory: 1g mode: replicated replicas: 1 placement: max_replicas_per_node: 1 constraints: - "node.labels.monitoring==true" restart_policy: condition: on-failure delay: 5s max_attempts: 3 window: 15s networks: - graylog configs: elasticsearch_config: name: elasticsearch_config file: ./elasticsearch.yml
方案二:通过环境变量传递所有自定义配置,无需挂载配置文件
Elasticsearch 7.x版本原生支持所有配置项通过环境变量传递,转换规则为:配置项key全大写,.替换为_,前缀加ES_。常见配置对应环境变量示例:
cluster.name: graylog对应ES_CLUSTER_NAME=graylognetwork.host: 0.0.0.0对应ES_NETWORK_HOST=0.0.0.0http.port: 9200对应ES_HTTP_PORT=9200discovery.type: single-node对应ES_DISCOVERY_TYPE=single-node- 数组类配置(如种子节点列表)多个值用逗号分隔即可。
该方案完全不需要挂载任何配置文件,从根源上避开只读文件系统chown报错,适合自定义配置项较少的场景。
内容的提问来源于stack exchange,提问作者kozmo
相关产品推荐
相关产品推荐

