OpenSearch Dashboards 를 tar 배포판으로 올린다. 버전은 OpenSearch 와 같은 3.8.0 을 쓴다. 2025년 3.8.0 에서 테스트 됨.
# Archive download
wget https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/3.8.0/opensearch-dashboards-3.8.0-linux-x64.tar.gz
tar -xvf opensearch-dashboards-3.8.0-linux-x64.tar.gz
mkdir /opt/apps
mv opensearch-dashboards-3.8.0 /opt/apps/
ln -s /opt/apps/opensearch-dashboards-3.8.0 /opt/opensearch-dashboard
chown -R opensearch:opensearch /opt/apps/*
chown -R opensearch:opensearch /opt/opensearch-dashboard
# disable swap and edit system config
swapoff -a
echo "vm.max_map_count=262144" >> /etc/sysctl.conf
sysctl -p
# mkdir /xvdb/opensearch-dashboard
# mkdir /var/log/opensearch-dashboard
cp -r /opt/opensearch-dashboard/config /etc/opensearch-dashboard
chown -R opensearch:opensearch /xvdb/opensearch-dashboard /etc/opensearch-dashboard /var/log/opensearch-dashboard
---
server.port: 5601
server.host: 0.0.0.0
# server.basePath: ""
# server.rewriteBasePath: false
# server.maxPayloadBytes: 1048576
server.name: "opensearch-dashboard"
opensearch.hosts: ["http://opensearch1:9200","http://opensearch2:9200"]
# opensearchDashboards.index: ".opensearch_dashboards"
# opensearchDashboards.defaultAppId: "home"
# opensearch.optimizedHealthcheckId: "cluster_id"
opensearch.username: "admin"
opensearch.password: "${REDACTED}"
server.ssl.enabled: false
# server.ssl.certificate: /path/to/your/server.crt
# server.ssl.key: /path/to/your/server.key
# opensearch server certs
# opensearch.ssl.certificate: /path/to/your/client.crt
# opensearch.ssl.key: /path/to/your/client.key
# opensearch.ssl.certificateAuthorities: [ "/path/to/your/CA.pem" ]
# To disregard the validity of SSL certificates, change this setting's value to 'none'.
# opensearch.ssl.verificationMode: full
# Time in milliseconds to wait for OpenSearch to respond to pings. Defaults to the value of
# the opensearch.requestTimeout setting.
# opensearch.pingTimeout: 1500
# Time in milliseconds to wait for responses from the back end or OpenSearch. This value
# must be a positive integer.
# opensearch.requestTimeout: 30000
# List of OpenSearch Dashboards client-side headers to send to OpenSearch. To send *no* client-side
# headers, set this value to [] (an empty list).
# opensearch.requestHeadersWhitelist: [ authorization ]
# Header names and values that are sent to OpenSearch. Any custom headers cannot be overwritten
# by client-side headers, regardless of the opensearch.requestHeadersWhitelist configuration.
# opensearch.customHeaders: {}
# Time in milliseconds for OpenSearch to wait for responses from shards. Set to 0 to disable.
# opensearch.shardTimeout: 30000
# Logs queries sent to OpenSearch. Requires logging.verbose set to true.
# opensearch.logQueries: false
# Specifies the path where OpenSearch Dashboards creates the process ID file.
pid.file: /xvdb/opensearch-dashboard/opensearchDashboards.pid
# Enables you to specify a file where OpenSearch Dashboards stores log output.
# logging.dest: stdout
logging.dest: /var/log/opensearch-dashboard
# logging.ignoreEnospcError: false
logging.silent: false
logging.quiet: false
logging.verbose: false
# Set the interval in milliseconds to sample system and process performance
# metrics. Minimum is 100ms. Defaults to 5000.
# ops.interval: 5000
# Specifies locale to be used for all localizable strings, dates and number formats.
# Supported languages are the following: English - en , by default , Chinese - zh-CN .
# i18n.locale: "en"
# opensearchDashboards.branding:
# logo:
# defaultUrl: ""
# darkModeUrl: ""
# mark:
# defaultUrl: ""
# darkModeUrl: ""
# loadingLogo:
# defaultUrl: ""
# darkModeUrl: ""
# faviconUrl: ""
# applicationTitle: ""
# map.showRegionBlockedWarning: false%
# data.search.usageTelemetry.enabled: false
# 2.4 renames 'wizard.enabled: false' to 'vis_builder.enabled: false'
# Set the value of this setting to false to disable VisBuilder
# functionality in Visualization.
# vis_builder.enabled: false
opensearch.ssl.verificationMode: none
opensearch.requestHeadersWhitelist: [authorization, securitytenant]
opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.preferred: [Private, Global]
opensearch_security.readonly_mode.roles: [kibana_read_only]
# Use this setting if you are running opensearch-dashboards without https
opensearch_security.cookie.secure: false
[Unit]
Description=OpenSearch Dashboards
Wants=network-online.target
After=network-online.target opensearch.service
[Service]
Type=simple
User=opensearch
Group=opensearch
Environment=OPENSEARCH_DASHBOARDS_HOME=/opt/opensearch-dashboard
Environment=OPENSEARCH_PATH_CONF=/etc/opensearch-dashboard
WorkingDirectory=/xvdb/opensearch-dashboard
ExecStart=/opt/opensearch-dashboard/bin/opensearch-dashboards
Restart=always
LimitNOFILE=65535
StandardOutput=stdout
StandardError=stdout
[Install]
WantedBy=multi-user.target
브라우저로 http://<호스트>:5601 에 붙어 admin 으로 로그인한다. OpenSearch 쪽 연결은 아래로 본다 (3.3.0 테스트 기록).
curl -u admin:DkWnRkdFurGksVoTmDnjEm00@@ http://opensearch2:9200
{
"name" : "opensearch2",
"cluster_name" : "opensearch",
"cluster_uuid" : "wbIKIEwbSCSYtKQ4AZ7t7g",
"version" : {
"distribution" : "opensearch",
"number" : "3.3.0",
"build_type" : "tar",
"build_hash" : "e972d15408320e6be84c64bb0fdc076ca7696ea2",
"build_date" : "2025-10-11T23:26:07.877318301Z",
"build_snapshot" : false,
"lucene_version" : "10.3.1",
"minimum_wire_compatibility_version" : "2.19.0",
"minimum_index_compatibility_version" : "2.0.0"
},
"tagline" : "The OpenSearch Project: https://opensearch.org/"
}