安装嵌入式ZooKeeper的非安全Nifi 1.5集群后GUI连接被拒绝
Hey there! Let's work through this NiFi GUI connection refused issue together. Since your cluster started up and leader election completed without obvious errors, the problem is most likely related to network or configuration missteps rather than core cluster functionality. Here are the key areas to investigate:
Head into the nifi.properties file on each node and verify these critical settings:
nifi.web.http.host: Make sure this is set to the node's publicly accessible IP address or resolvable hostname, notlocalhostor127.0.0.1(if you're accessing from a remote machine). If your nodes are spread across different hosts, using the actual network IP here is essential.nifi.web.http.port: Default is 8080—confirm this port isn't occupied by another process. Runnetstat -tulpn | grep 8080(orss -tulpn | grep 8080on newer systems) to check for conflicts.nifi.web.http.network.interface.default: If your node has multiple network interfaces, specify the correct one here to ensure NiFi binds to the right network adapter.
- Firewall checks: On each NiFi node, ensure the HTTP port (default 8080) is open in the firewall. For temporary testing, you can stop the firewall service:
systemctl stop firewalld(CentOS/RHEL) orufw disable(Ubuntu). If the GUI becomes accessible after this, add a permanent rule to allow traffic on the port. - Network connectivity: From the machine you're using to access the GUI, test basic connectivity first:
ping <nifi-node-ip>. Then verify port access withtelnet <nifi-node-ip> 8080ornc -zv <nifi-node-ip> 8080. If these commands fail, there's a network-level block preventing access.
Even though election went smoothly, it's worth confirming these cluster-related settings:
nifi.cluster.node.addressandnifi.cluster.node.protocol.port: Ensure each node's settings here point to a valid address/port that other cluster nodes can reach.nifi.zookeeper.connect.string: For embedded ZK, this should list all three nodes (e.g.,node1:2181,node2:2181,node3:2181). Also make sure the ZK port (2181) is open on all nodes' firewalls, as cluster health depends on ZK connectivity.
You mentioned errors in nifi-app.log and nifi-user.log—focus on these patterns:
- Look for
BindException: This indicates NiFi couldn't bind to the configured web port, usually due to a port conflict or invalid host address. - Trace the context around
Connection refusederrors: See if the failure is NiFi trying to connect to another cluster node, ZK, or its own web service. This can point to hidden connectivity issues. - Check
nifi-bootstrap.log: This log captures startup details, including whether the web service successfully launched and which address/port it bound to.
On each NiFi node, run a local test to confirm the web service is working:
- Use
curl http://localhost:8080/nifiorcurl http://<node-ip>:8080/nifi. If this works locally but fails remotely, the issue is definitely network/firewall-related. If it fails locally too, NiFi's web service didn't start properly—go back to checking configuration and startup logs.
If you still can't resolve the issue after these steps, sharing the exact error messages from the logs would help narrow things down further.
内容的提问来源于stack exchange,提问作者Setanta

