NiFi 2.8 3 노드 클러스터(Kubernetes 또는 VM)를 재시작할 때마다 클러스터 멤버 수가 늘어나고, UI 는 An unexpected error has occurred 와 nifi-api/flow/current-user 오류를 낸다. 로그에는 ProtocolException: Failed marshalling 'CONNECTION_REQUEST' 와 TLS handshake 실패가 보인다.
nifi.cluster.node.address · nifi.web.https.host)가 재시작 때 달라지면(파드 이름 · 호스트명 변경) ZooKeeper 의 클러스터 상태에 이전 노드가 남아 멤버가 늘어난다.CONNECTION_REQUEST 마샬링과 handshake 가 실패한다.authorizations.xml · users.xml 을 비우면 초기 관리자와 노드 identity 가 다시 만들어지지만, nifi.security.identity.mapping 과 노드 identity(CN=nifi01.example.com, OU=NIFI)가 맞지 않으면 프록시 권한(/proxy)이 없어 UI 가 열리지 않는다./nifi/leaders, /nifi/components 아래)를 정리하거나 nifi.state.management.embedded.zookeeper 데이터를 비운다.nifi-2.nifi-headless.<ns>.svc.cluster.local)을 쓴다.tls-toolkit.sh 는 2.x 배포본에 없으므로 openssl 로 기존 ca.crt · ca.key 를 써서 발급한다. SAN 에 각 노드 FQDN 과 와일드카드(*.example.com)를 넣는다.openssl req -new -newkey rsa:2048 -nodes -keyout nifi01.key -out nifi01.csr -subj "/CN=nifi01.example.com/OU=NIFI"
openssl x509 -req -in nifi01.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out nifi01.crt -days 825 \
-extfile <(printf "subjectAltName=DNS:nifi01.example.com,DNS:*.example.com")
openssl pkcs12 -export -inkey nifi01.key -in nifi01.crt -certfile ca.crt -name nifi01 -out keystore.p12 -passout pass:${KEYSTORE_PASSWORD}
keytool -importcert -noprompt -alias ca -file ca.crt -keystore truststore.p12 -storetype PKCS12 -storepass ${TRUSTSTORE_PASSWORD}
nifi.properties 의 keystore · truststore · nifi.security.autoreload.enabled · 클러스터 주소를 세 노드에 같게 맞추고, authorizers.xml 의 Initial Admin Identity 와 Node Identity 를 인증서 DN 과 일치시킨다.nifi01 을 먼저 올려 flow election 이 끝난 뒤 나머지를 올린다. nifi.cluster.flow.election.max.candidates 를 노드 수로 두면 대기 시간이 줄어든다.원인을 좁히려면 세 노드를 nifi.web.http.port=8080 · nifi.cluster.protocol.is.secure=false · nifi.remote.input.secure=false 로 바꾸고 nifi.security.* 를 비운 상태로 클러스터가 형성되는지 본다. 이때 인증 · 인가는 꺼지므로 검증용으로만 쓴다. 이 과정에서 openssl s_client 는 -keyform P12 를 지원하지 않으므로 PKCS12 를 PEM 으로 풀어 확인한다.
대화는 인증서 재발급과 노드 재기동 스크립트 작성까지 진행되었고, 최종 안정 상태 확인 기록은 없다.