You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API向AWS OpenSearch添加文档及所需认证说明

AWS OpenSearch API添加文档:操作方法与认证说明

一、支持的认证方式

AWS OpenSearch域的API调用主要用两种认证方式,根据你的域配置选择:

  • IAM身份认证:如果域开启了IAM访问控制,所有请求必须携带AWS V4签名。适合用AWS SDK、CLI,或拥有对应IAM权限的用户/角色调用。需要确保IAM实体(用户/角色)有es:ESHttpPut、es:ESHttpPost等操作权限。
  • HTTP基本认证:如果域配置了主用户(Master User),可以用主用户的账号密码做Base64编码,放在请求头的Authorization字段里。适合快速测试或非AWS环境的调用。

二、具体操作步骤

1. 先确认索引存在(无则创建)

OpenSearch要求文档必须存入已创建的索引。如果还没建对应索引,先调用创建接口:

IAM认证(curl示例,需配置AWS凭证):

curl -XPUT "https://your-domain-endpoint/your-index-name" \
  --aws-sigv4 "aws:amz:your-region:es" \
  -u "AKIAYOURACCESSKEY:YOURSECRETKEY" \
  -H "Content-Type: application/json" \
  -d '{
    "settings": {
      "number_of_shards": 1,
      "number_of_replicas": 0
    },
    "mappings": {
      "properties": {
        "id": {"type": "keyword"},
        "content": {"type": "text"},
        "tag": {"type": "keyword"}
      }
    }
  }'

基本认证(curl示例):

curl -XPUT "https://your-domain-endpoint/your-index-name" \
  -u "your-master-username:your-master-password" \
  -H "Content-Type: application/json" \
  -d '{
    "settings": {
      "number_of_shards": 1,
      "number_of_replicas": 0
    },
    "mappings": {
      "properties": {
        "id": {"type": "keyword"},
        "content": {"type": "text"},
        "tag": {"type": "keyword"}
      }
    }
  }'

2. 添加指定格式的文档

方式1:手动指定文档ID(用你示例中的123)

IAM认证curl示例:
curl -XPUT "https://your-domain-endpoint/your-index-name/_doc/123" \
  --aws-sigv4 "aws:amz:your-region:es" \
  -u "AKIAYOURACCESSKEY:YOURSECRETKEY" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "123",
    "content" : "some text content to search",
    "tag": "identifier for document type"
  }'
基本认证curl示例:
curl -XPUT "https://your-domain-endpoint/your-index-name/_doc/123" \
  -u "your-master-username:your-master-password" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "123",
    "content" : "some text content to search",
    "tag": "identifier for document type"
  }'

方式2:自动生成文档ID(改用POST请求)

如果不需要指定ID,用POST请求,OpenSearch会自动生成唯一ID:

# IAM认证示例
curl -XPOST "https://your-domain-endpoint/your-index-name/_doc" \
  --aws-sigv4 "aws:amz:your-region:es" \
  -u "AKIAYOURACCESSKEY:YOURSECRETKEY" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "123",
    "content" : "some text content to search",
    "tag": "identifier for document type"
  }'

3. 验证文档是否添加成功

调用搜索接口查询:

# IAM认证
curl -XGET "https://your-domain-endpoint/your-index-name/_search?q=id:123" \
  --aws-sigv4 "aws:amz:your-region:es" \
  -u "AKIAYOURACCESSKEY:YOURSECRETKEY"

# 基本认证
curl -XGET "https://your-domain-endpoint/your-index-name/_search?q=id:123" \
  -u "your-master-username:your-master-password"

三、关键注意点

  • 替换所有示例中的your-domain-endpoint为你的OpenSearch域实际端点(在AWS控制台域详情页的“Endpoint”字段获取)。
  • your-index-name替换为你自定义的索引名,比如docs。
  • 使用IAM认证时,确保你的IAM用户/角色的策略包含对应索引的操作权限,示例策略片段:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["es:ESHttpPut", "es:ESHttpPost", "es:ESHttpGet"],
      "Resource": "arn:aws:es:your-region:your-account-id:domain/your-domain-name/your-index-name/*"
    }
  ]
}
  • 如果域部署在VPC内,需确保调用API的环境(本地机器/EC2实例)能访问VPC,比如通过VPN、VPC peering或中转实例。

内容的提问来源于stack exchange,提问作者Jakao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 23:39:52