RHEL 계열에 Elasticsearch 9.5.4 를 RPM 저장소로 설치한다. 9.x 는 설치와 동시에 TLS 와 인증이 켜지므로 설치 직후 출력되는 elastic 비밀번호를 반드시 챙긴다.
vm.max_map_count 262144 이상. RPM 설치가 /usr/lib/sysctl.d/elasticsearch.conf 로 넣어 준다.sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
/etc/yum.repos.d/elasticsearch.repo
[elasticsearch]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=0
type=rpm-md
enabled=0 은 공식 권장이다. 다른 패키지 갱신 때 같이 올라가지 않게 하고, 설치할 때만 --enablerepo 로 켠다.
sudo dnf install --enablerepo=elasticsearch elasticsearch
설치가 끝나면 아래 같은 출력이 나온다. 비밀번호와 등록 토큰을 파일로 저장해 둔다. 다시 보여 주지 않는다.
--------------------------- Security autoconfiguration information ------------------------------
Authentication and authorization are enabled.
TLS for the transport and HTTP layers is enabled and configured.
The generated password for the elastic built-in superuser is : <비밀번호>
If this node should join an existing cluster, you can reconfigure this with
'/usr/share/elasticsearch/bin/elasticsearch-reconfigure-node --enrollment-token <token-here>'
after creating an enrollment token on your existing cluster.
You can complete the following actions at any time:
Reset the password of the elastic built-in superuser with
'/usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic'.
Generate an enrollment token for Kibana instances with
'/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana'.
Generate an enrollment token for Elasticsearch nodes with
'/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node'.
-------------------------------------------------------------------------------------------------
비밀번호를 놓쳤으면 다시 만든다.
sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic
/etc/elasticsearch/elasticsearch.yml. 단일 노드면 아래 세 줄이면 된다. 자동 설정이 넣어 둔 xpack.security.* 블록은 건드리지 않는다.
cluster.name: elasticsearch
node.name: es01
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
여러 노드를 묶을 때는 첫 노드에서 토큰을 만들고, 다른 노드에서 설치 직후 elasticsearch-reconfigure-node --enrollment-token <토큰> 을 돌린다. discovery.seed_hosts 와 cluster.initial_master_nodes 는 이 과정에서 채워진다.
힙을 고정하려면 /etc/elasticsearch/jvm.options.d/heap.options 에 둔다.
-Xms4g
-Xmx4g
sudo systemctl daemon-reload
sudo systemctl enable elasticsearch.service
sudo systemctl start elasticsearch.service
sudo systemctl status elasticsearch.service
sudo firewall-cmd --permanent --add-port=9200/tcp --add-port=9300/tcp
sudo firewall-cmd --reload
HTTP 도 TLS 라 https 와 CA 인증서를 줘야 한다.
export ELASTIC_PASSWORD='<비밀번호>'
curl --cacert /etc/elasticsearch/certs/http_ca.crt -u elastic:$ELASTIC_PASSWORD https://localhost:9200
{
"name" : "es01",
"cluster_name" : "elasticsearch",
"cluster_uuid" : "u70idC6OQJy5pL3byaetNA",
"version" : {
"number" : "9.5.4",
"build_flavor" : "default",
"build_type" : "rpm",
"lucene_version" : "10.3.1",
"minimum_wire_compatibility_version" : "8.19.0",
"minimum_index_compatibility_version" : "8.0.0"
},
"tagline" : "You Know, for Search"
}
Kibana · Logstash · Filebeat 에서 붙을 때도 같은 http_ca.crt 를 복사해 CA 로 쓴다.
위 버전과 저장소는 오래된 것이라 저장소가 존재하지 않을 수 있다. 7.x 는 보안이 꺼진 채 설치되어
http://로 붙었다. 2020년 테스트 됨.
curl -L -O https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.10.1-x86_64.rpm
sudo rpm -i elasticsearch-7.10.1-x86_64.rpm
sudo service elasticsearch start
curl http://127.0.0.1:9200
/etc/elasticsearch/elasticsearch.yml
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 192.168.113.138
http.port: 9200
#discovery.seed_hosts: ["192.168.113.138"]
cluster.initial_master_nodes: ["node-1", "node-2"]
sudo service elasticsearch restart