You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用Search Guard后Spring-Data-Elasticsearch无法连接Elasticsearch节点

Hey there, let's dig into this problem you're hitting where your Spring Boot app can't connect to Elasticsearch after enabling Search Guard. I’ve dealt with this exact issue before, so here’s the breakdown and fix:

Why This Happens

Once Search Guard is enabled on your Elasticsearch cluster, it forces SSL/TLS encryption for all Transport layer communications (the layer Spring Data Elasticsearch uses by default). Your original setup was configured for an unencrypted cluster—no SSL or authentication settings were present—so when you try to connect now, the cluster rejects the plaintext connection. That "Someone speaks transport plaintext..." log line from Elasticsearch is its way of saying exactly that: your client is sending unencrypted traffic to a cluster that expects encrypted connections.

Step-by-Step Fix

Since you're on Spring Boot 2.0.0.RELEASE (which pairs with Spring Data Elasticsearch 3.0.x), here's how to update your setup to work with Search Guard:

1. Add the Search Guard SSL Dependency

First, you need the Search Guard SSL library to handle encrypted connections. Make sure the version matches your Elasticsearch cluster version exactly (e.g., if ES is 6.2.4, use the corresponding Search Guard version):

For Maven (pom.xml):

<dependency>
    <groupId>com.floragunn</groupId>
    <artifactId>search-guard-ssl</artifactId>
    <version>6.2.4-24.1</version> <!-- Replace with your matching ES/Search Guard version -->
</dependency>

For Gradle (build.gradle):

implementation 'com.floragunn:search-guard-ssl:6.2.4-24.1' // Match your ES version

2. Configure the Elasticsearch Client

Update your application.properties or application.yml with SSL and authentication settings tailored to your Search Guard setup:

application.properties:

# Basic cluster connection
spring.data.elasticsearch.cluster-nodes=your-es-host:9300

# Enable Search Guard SSL for transport layer
spring.data.elasticsearch.properties.searchguard.ssl.transport.enabled=true
# Path to the Search Guard root CA certificate (get this from your ES server)
spring.data.elasticsearch.properties.searchguard.ssl.transport.pemtrustedcas_filepath=classpath:root-ca.pem

# Optional: If using client certificate authentication (depends on your Search Guard config)
spring.data.elasticsearch.properties.searchguard.ssl.transport.pemcert_filepath=classpath:client-cert.pem
spring.data.elasticsearch.properties.searchguard.ssl.transport.pemkey_filepath=classpath:client-key.pem

# Optional: If using basic username/password authentication
spring.data.elasticsearch.properties.searchguard.auth.username=your-search-guard-user
spring.data.elasticsearch.properties.searchguard.auth.password=your-user-password

# Disable hostname verification if needed (adjust based on your cluster setup)
spring.data.elasticsearch.properties.searchguard.ssl.transport.enforce_hostname_verification=false

application.yml:

spring:
  data:
    elasticsearch:
      cluster-nodes: your-es-host:9300
      properties:
        searchguard:
          ssl:
            transport:
              enabled: true
              pemtrustedcas_filepath: classpath:root-ca.pem
              pemcert_filepath: classpath:client-cert.pem # Optional
              pemkey_filepath: classpath:client-key.pem # Optional
              enforce_hostname_verification: false
          auth:
            username: your-search-guard-user
            password: your-user-password

3. Critical Notes

  • Version Matching: Always use the Search Guard version that exactly matches your Elasticsearch version. Mismatched versions will cause cryptic compatibility errors.
  • Certificate Files: Grab the root CA certificate from your Elasticsearch server (it’s part of the Search Guard setup). If your cluster uses client certificate authentication, you’ll also need the client cert and key files—place these in your project’s resources folder so the app can access them.
  • Auth Method: Choose the authentication method that matches your Search Guard configuration (basic username/password or client certificates). You don’t need both unless your cluster requires it.
  • Port Check: Ensure you’re connecting to the Elasticsearch Transport port (default 9300), not the HTTP port (9200)—Spring Data Elasticsearch uses the Transport client by default.
Verify the Fix

Restart your Spring Boot app, and it should now establish an encrypted, authenticated connection to your Search Guard-protected Elasticsearch cluster. If you still run into issues, check the Elasticsearch logs for specific errors (like certificate mismatches or invalid credentials) to tweak your configuration further.

内容的提问来源于stack exchange,提问作者jm li

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:14:37