tar 배포판으로 OpenSearch 2노드 클러스터(opensearch1 · opensearch2) 를 올린다. 현행 3.8.0 기준이고, 같은 절차를 2025년 3.8.0 에서 테스트했다. 데모 보안 설정(opensearch-tar-install.sh) 을 쓰므로 운영 전에는 인증서를 바꾼다.
# Archive download
wget https://artifacts.opensearch.org/releases/bundle/opensearch/3.8.0/opensearch-3.8.0-linux-x64.tar.gz
tar -xvf opensearch-3.8.0-linux-x64.tar.gz
mkdir /opt/apps
mv opensearch-3.8.0 /opt/apps/
ln -s /opt/apps/opensearch-3.8.0 /opt/opensearch
chown -R opensearch:opensearch /opt/apps/*
chown -R opensearch:opensearch /opt/opensearch
# disable swap and edit system config
swapoff -a
echo "vm.max_map_count=262144" >> /etc/sysctl.conf
sysctl -p
# mkdir /xvdb/opensearch
# mkdir /var/log/opensearch
cp -r /opt/opensearch/config /etc/opensearch
chown -R opensearch:opensearch /xvdb/opensearch /etc/opensearch /var/log/opensearch
# ---------------------------------- Cluster -----------------------------------
# Use a descriptive name for your cluster:
cluster.name: opensearch
# ------------------------------------ Node ------------------------------------
# Use a descriptive name for the node:
node.name: opensearch1
# Add custom attributes to the node:
#node.attr.rack: r1
# ----------------------------------- Paths ------------------------------------
# Path to directory where to store the data (separate multiple locations by comma):
path.data: /xvdb/opensearch/data,/xvdc/opensearch/data
# Path to log files:
path.logs: /var/log/opensearch
# ----------------------------------- Memory -----------------------------------
# Lock the memory on startup:
#bootstrap.memory_lock: true
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
# OpenSearch performs poorly when the system is swapping the memory.
# ---------------------------------- Network -----------------------------------
# Set the bind address to a specific IP (IPv4 or IPv6):
network.host: 0.0.0.0
# Set a custom port for HTTP:
#http.port: 9200
# --------------------------------- Discovery ----------------------------------
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"] 각 노드의 호스트에 맞게 수정
# discovery.type: single-node
discovery.seed_hosts: ["opensearch1", "opensearch2"]
# Bootstrap the cluster using an initial set of cluster-manager-eligible nodes:
cluster.initial_cluster_manager_nodes: ["opensearch1", "opensearch2"]
# ---------------------------------- Gateway -----------------------------------
# Block initial recovery after a full cluster restart until N nodes are started:
#gateway.recover_after_data_nodes: 3
# ---------------------------------- Various -----------------------------------
# Require explicit names when deleting indices:
#action.destructive_requires_name: true
# ---------------------------------- Remote Store -----------------------------------
# Controls whether cluster imposes index creation only with remote store enabled
# cluster.remote_store.enabled: true
# Repository to use for segment upload while enforcing remote store for an index
# node.attr.remote_store.segment.repository: my-repo-1
# Repository to use for translog upload while enforcing remote store for an index
# node.attr.remote_store.translog.repository: my-repo-1
######## Start OpenSearch Security Demo Configuration ########
# WARNING: revise all the lines below before you go into production
plugins.security.ssl.transport.pemcert_filepath: esnode.pem
plugins.security.ssl.transport.pemkey_filepath: esnode-key.pem
plugins.security.ssl.transport.pemtrustedcas_filepath: root-ca.pem
plugins.security.ssl.transport.enforce_hostname_verification: false
#plugins.security.ssl.http.enabled: true
plugins.security.ssl.http.enabled: false
plugins.security.ssl.http.pemcert_filepath: esnode.pem
plugins.security.ssl.http.pemkey_filepath: esnode-key.pem
plugins.security.ssl.http.pemtrustedcas_filepath: root-ca.pem
plugins.security.allow_unsafe_democertificates: true
plugins.security.allow_default_init_securityindex: true
plugins.security.authcz.admin_dn: ['CN=kirk,OU=client,O=client,L=test,C=de']
plugins.security.audit.type: internal_opensearch
plugins.security.enable_snapshot_restore_privilege: true
plugins.security.check_snapshot_restore_write_privileges: true
plugins.security.restapi.roles_enabled: [all_access, security_rest_api_access]
plugins.security.system_indices.enabled: true
plugins.security.system_indices.indices: [.plugins-ml-agent, .plugins-ml-config, .plugins-ml-connector,
.plugins-ml-controller, .plugins-ml-model-group, .plugins-ml-model, .plugins-ml-task,
.plugins-ml-conversation-meta, .plugins-ml-conversation-interactions, .plugins-ml-memory-meta,
.plugins-ml-memory-message, .plugins-ml-stop-words, .opendistro-alerting-config,
.opendistro-alerting-alert*, .opendistro-anomaly-results*, .opendistro-anomaly-detector*,
.opendistro-anomaly-checkpoints, .opendistro-anomaly-detection-state, .opendistro-reports-*,
.opensearch-notifications-*, .opensearch-notebooks, .opensearch-observability, .ql-datasources,
.opendistro-asynchronous-search-response*, .replication-metadata-store, .opensearch-knn-models,
.geospatial-ip2geo-data*, .plugins-flow-framework-config, .plugins-flow-framework-templates,
.plugins-flow-framework-state, .plugins-search-relevance-experiment, .plugins-search-relevance-judgment-cache]
node.max_local_storage_nodes: 3
######## End OpenSearch Security Demo Configuration ########
# set password
# export OPENSEARCH_INITIAL_ADMIN_PASSWORD=<custom-admin-password>
export OPENSEARCH_INITIAL_ADMIN_PASSWORD=${REDACTED}
# install
cd /opt/opensearch
./opensearch-tar-install.sh
# OPENSEARCH_INITIAL_ADMIN_PASSWORD=${REDACTED} ./opensearch-tar-install.sh
[Unit]
Description=OpenSearch
Wants=network-online.target
After=network-online.target
[Service]
Type=forking
Environment=OPENSEARCH_HOME=/opt/opensearch
Environment=OPENSEARCH_JAVA_OPTS="-Xms2g -Xmx2g"
Environment=OPENSEARCH_PATH_CONF=/etc/opensearch
RuntimeDirectory=data
WorkingDirectory=/opt/opensearch
ExecStart=/opt/opensearch/bin/opensearch -d
User=opensearch
Group=opensearch
StandardOutput=journal
StandardError=inherit
LimitNOFILE=65535
LimitNPROC=4096
LimitAS=infinity
LimitFSIZE=infinity
TimeoutStopSec=0
KillSignal=SIGTERM
KillMode=process
SendSIGKILL=no
SuccessExitStatus=143
TimeoutStartSec=75
[Install]
WantedBy=multi-user.target
아래 출력은 3.3.0 에서 테스트한 기록이라 빌드 해시 · 날짜가 다르다.
curl -u admin:DkWnRkdFurGksVoTmDnjEm00@@ http://opensearch2:9200
{
"name" : "opensearch2",
"cluster_name" : "opensearch",
"cluster_uuid" : "wbIKIEwbSCSYtKQ4AZ7t7g",
"version" : {
"distribution" : "opensearch",
"number" : "3.3.0",
"build_type" : "tar",
"build_hash" : "e972d15408320e6be84c64bb0fdc076ca7696ea2",
"build_date" : "2025-10-11T23:26:07.877318301Z",
"build_snapshot" : false,
"lucene_version" : "10.3.1",
"minimum_wire_compatibility_version" : "2.19.0",
"minimum_index_compatibility_version" : "2.0.0"
},
"tagline" : "The OpenSearch Project: https://opensearch.org/"
}