咨询:如何在自建Kubernetes集群部署已验证的Elasticsearch镜像
Got it, let's walk through getting your Elasticsearch deployment fully set up on your GKE cluster. You’ve already checked off some key steps—running Elasticsearch locally via Docker, creating your GKE cluster, and starting a ReplicationController YAML. Let’s fill in the missing pieces and cover everything you need for a working deployment.
1. Finalize Your ReplicationController YAML
Your partial RC is a solid starting point, but we need to add container details, critical Elasticsearch environment variables, and basic resource controls to make it work in Kubernetes. Here’s the full, functional version:
apiVersion: v1 kind: ReplicationController metadata: name: elasticsearch labels: app: elasticsearch spec: replicas: 2 selector: app: elasticsearch template: metadata: labels: app: elasticsearch spec: containers: - name: elasticsearch image: elasticsearch:latest # Use the exact tag you pulled locally (e.g., 8.10.0) for consistency ports: - containerPort: 9200 name: rest-api - containerPort: 9300 name: inter-node-comm env: # For multi-node cluster (your 2 replicas), use these discovery settings - name: discovery.seed_hosts value: "elasticsearch" # Points to the service we'll create next - name: cluster.initial_master_nodes value: "elasticsearch-0,elasticsearch-1" # Matches pod names the RC will generate - name: ES_JAVA_OPTS value: "-Xms512m -Xmx512m" # Adjust based on your GKE node's available memory resources: requests: memory: "1Gi" cpu: "500m" limits: memory: "2Gi" cpu: "1"
If you want a simpler single-node cluster instead, replace the env block with:
env: - name: discovery.type value: "single-node" - name: ES_JAVA_OPTS value: "-Xms512m -Xmx512m"
2. Create a Service to Expose Elasticsearch
You need a Kubernetes Service to make Elasticsearch accessible—either within the cluster or externally. Create a file named elasticsearch-service.yaml with this content:
apiVersion: v1 kind: Service metadata: name: elasticsearch labels: app: elasticsearch spec: ports: - port: 9200 name: rest-api - port: 9300 name: inter-node-comm selector: app: elasticsearch type: ClusterIP # Use NodePort or LoadBalancer if you need external public access
For external access, change type: LoadBalancer—GKE will automatically provision a public IP for you to reach Elasticsearch from outside the cluster.
3. Deploy the Resources to GKE
Run these commands to apply your manifests to the cluster:
kubectl apply -f elasticsearch.yaml kubectl apply -f elasticsearch-service.yaml
4. Verify Your Deployment
Check if your Elasticsearch pods are running successfully:
kubectl get pods -l app=elasticsearch
Check the status of your Service:
kubectl get service elasticsearch
Test connectivity to Elasticsearch (from within the cluster, use a temporary curl pod):
kubectl run -it --rm --image=curlimages/curl curl-test -- curl elasticsearch:9200
You should see a JSON response with Elasticsearch version information if everything is working.
5. Production-Grade Recommendations (Optional)
- Switch to a Deployment instead of ReplicationController: Deployments support rolling updates and rollbacks, which are far better for managing stateful apps like Elasticsearch. Here’s a quick Deployment replacement for your RC:
apiVersion: apps/v1 kind: Deployment metadata: name: elasticsearch labels: app: elasticsearch spec: replicas: 2 selector: matchLabels: app: elasticsearch template: metadata: labels: app: elasticsearch spec: containers: - name: elasticsearch image: elasticsearch:latest ports: - containerPort: 9200 - containerPort: 9300 env: - name: discovery.seed_hosts value: "elasticsearch" - name: cluster.initial_master_nodes value: "elasticsearch-0,elasticsearch-1" - name: ES_JAVA_OPTS value: "-Xms512m -Xmx512m" resources: requests: memory: "1Gi" cpu: "500m" limits: memory: "2Gi" cpu: "1" - Add Persistent Storage: Elasticsearch needs persistent volumes to retain data across pod restarts. Add
volumeMountsandvolumessections to your pod template usingPersistentVolumeClaims. - Secure Your Cluster: Enable authentication, TLS encryption, and restrict access via NetworkPolicies—your current setup is unsecure for production use.
内容的提问来源于stack exchange,提问作者soundararajan.c

