启用Search Guard后Spring-Data-Elasticsearch无法连接Elasticsearch节点
Hey there, let's dig into this problem you're hitting where your Spring Boot app can't connect to Elasticsearch after enabling Search Guard. I’ve dealt with this exact issue before, so here’s the breakdown and fix:
Once Search Guard is enabled on your Elasticsearch cluster, it forces SSL/TLS encryption for all Transport layer communications (the layer Spring Data Elasticsearch uses by default). Your original setup was configured for an unencrypted cluster—no SSL or authentication settings were present—so when you try to connect now, the cluster rejects the plaintext connection. That "Someone speaks transport plaintext..." log line from Elasticsearch is its way of saying exactly that: your client is sending unencrypted traffic to a cluster that expects encrypted connections.
Since you're on Spring Boot 2.0.0.RELEASE (which pairs with Spring Data Elasticsearch 3.0.x), here's how to update your setup to work with Search Guard:
1. Add the Search Guard SSL Dependency
First, you need the Search Guard SSL library to handle encrypted connections. Make sure the version matches your Elasticsearch cluster version exactly (e.g., if ES is 6.2.4, use the corresponding Search Guard version):
For Maven (pom.xml):
<dependency> <groupId>com.floragunn</groupId> <artifactId>search-guard-ssl</artifactId> <version>6.2.4-24.1</version> <!-- Replace with your matching ES/Search Guard version --> </dependency>
For Gradle (build.gradle):
implementation 'com.floragunn:search-guard-ssl:6.2.4-24.1' // Match your ES version
2. Configure the Elasticsearch Client
Update your application.properties or application.yml with SSL and authentication settings tailored to your Search Guard setup:
application.properties:
# Basic cluster connection spring.data.elasticsearch.cluster-nodes=your-es-host:9300 # Enable Search Guard SSL for transport layer spring.data.elasticsearch.properties.searchguard.ssl.transport.enabled=true # Path to the Search Guard root CA certificate (get this from your ES server) spring.data.elasticsearch.properties.searchguard.ssl.transport.pemtrustedcas_filepath=classpath:root-ca.pem # Optional: If using client certificate authentication (depends on your Search Guard config) spring.data.elasticsearch.properties.searchguard.ssl.transport.pemcert_filepath=classpath:client-cert.pem spring.data.elasticsearch.properties.searchguard.ssl.transport.pemkey_filepath=classpath:client-key.pem # Optional: If using basic username/password authentication spring.data.elasticsearch.properties.searchguard.auth.username=your-search-guard-user spring.data.elasticsearch.properties.searchguard.auth.password=your-user-password # Disable hostname verification if needed (adjust based on your cluster setup) spring.data.elasticsearch.properties.searchguard.ssl.transport.enforce_hostname_verification=false
application.yml:
spring: data: elasticsearch: cluster-nodes: your-es-host:9300 properties: searchguard: ssl: transport: enabled: true pemtrustedcas_filepath: classpath:root-ca.pem pemcert_filepath: classpath:client-cert.pem # Optional pemkey_filepath: classpath:client-key.pem # Optional enforce_hostname_verification: false auth: username: your-search-guard-user password: your-user-password
3. Critical Notes
- Version Matching: Always use the Search Guard version that exactly matches your Elasticsearch version. Mismatched versions will cause cryptic compatibility errors.
- Certificate Files: Grab the root CA certificate from your Elasticsearch server (it’s part of the Search Guard setup). If your cluster uses client certificate authentication, you’ll also need the client cert and key files—place these in your project’s
resourcesfolder so the app can access them. - Auth Method: Choose the authentication method that matches your Search Guard configuration (basic username/password or client certificates). You don’t need both unless your cluster requires it.
- Port Check: Ensure you’re connecting to the Elasticsearch Transport port (default 9300), not the HTTP port (9200)—Spring Data Elasticsearch uses the Transport client by default.
Restart your Spring Boot app, and it should now establish an encrypted, authenticated connection to your Search Guard-protected Elasticsearch cluster. If you still run into issues, check the Elasticsearch logs for specific errors (like certificate mismatches or invalid credentials) to tweak your configuration further.
内容的提问来源于stack exchange,提问作者jm li

