From c5ec70ca0fb206a844d184fb696bcb4dd55b7c8e Mon Sep 17 00:00:00 2001 From: Leo Sok Date: Mon, 16 Jun 2025 19:24:02 +0300 Subject: [PATCH] elastic return back --- elasticsearch/templates/statefulset.yaml | 14 +- elasticsearch/values.yaml | 399 ++++++++++++++++++----- 2 files changed, 324 insertions(+), 89 deletions(-) diff --git a/elasticsearch/templates/statefulset.yaml b/elasticsearch/templates/statefulset.yaml index 22f78e6..64fd423 100644 --- a/elasticsearch/templates/statefulset.yaml +++ b/elasticsearch/templates/statefulset.yaml @@ -242,10 +242,10 @@ spec: set -e # Exit if ELASTIC_PASSWORD in unset - #if [ -z "${ELASTIC_PASSWORD}" ]; then - # echo "ELASTIC_PASSWORD variable is missing, exiting" - # exit 1 - #fi + if [ -z "${ELASTIC_PASSWORD}" ]; then + echo "ELASTIC_PASSWORD variable is missing, exiting" + exit 1 + fi # If the node is starting up wait for the cluster to be ready (request params: "{{ .Values.clusterHealthCheckParams }}" ) # Once it has started only check that the node itself is responding @@ -264,9 +264,9 @@ spec: set -- "$@" $args fi - #set -- "$@" -u "elastic:${ELASTIC_PASSWORD}" - curl --output /dev/null -k "{{ .Values.protocol }}://127.0.0.1:{{ .Values.httpPort }}${path}" - #curl --output /dev/null -k "$@" "{{ .Values.protocol }}://127.0.0.1:{{ .Values.httpPort }}${path}" + set -- "$@" -u "elastic:${ELASTIC_PASSWORD}" + + curl --output /dev/null -k "$@" "{{ .Values.protocol }}://127.0.0.1:{{ .Values.httpPort }}${path}" } if [ -f "${START_FILE}" ]; then diff --git a/elasticsearch/values.yaml b/elasticsearch/values.yaml index 633b4ec..7ae5c31 100644 --- a/elasticsearch/values.yaml +++ b/elasticsearch/values.yaml @@ -28,13 +28,14 @@ esMajorVersion: "" # Allows you to add any config files in /usr/share/elasticsearch/config/ # such as elasticsearch.yml and log4j2.properties -esConfig: - elasticsearch.yml: | - xpack.security.enabled: false # Disable Elasticsearch security - xpack.security.http.ssl.enabled: false # Disable HTTP SSL - xpack.security.transport.ssl.enabled: false # Disable transport SSL +esConfig: {} +# elasticsearch.yml: | +# key: +# nestedkey: value +# log4j2.properties: | +# key = value -createCert: false +createCert: true esJvmOptions: {} # processors.options: | @@ -45,21 +46,19 @@ esJvmOptions: {} # syntax here extraEnvs: - name: ES_USERNAME - value: "elastic" -# valueFrom: -# secretKeyRef: -# name: elasticsearch-master-credentials -# key: username + valueFrom: + secretKeyRef: + name: elasticsearch-master-credentials + key: username - name: ES_PASSWORD - value: "test" -# valueFrom: -# secretKeyRef: -# name: elasticsearch-master-credentials -# key: password + valueFrom: + secretKeyRef: + name: elasticsearch-master-credentials + key: password - name: CA_CERT value: "/usr/share/elasticsearch/config/http-certs/ca.crt" - name: ES_URL - value: "http://elasticsearch-master:9200" + value: "https://elasticsearch-master:9200" - name: TEMPLATE_PATH_1 value: "/usr/share/elasticsearch/templates/chat_v1_idx.json" - name: TEMPLATE_PATH_2 @@ -168,23 +167,298 @@ extraVolumeMounts: - name: index-template mountPath: /usr/share/elasticsearch/templates readOnly: true -# - name: http-cert -# mountPath: /usr/share/elasticsearch/config/http-certs -# readOnly: true -# + - name: http-cert + mountPath: /usr/share/elasticsearch/config/http-certs + readOnly: true + extraContainers: [] +# - name: do-something +# image: busybox +# command: ['do', 'something'] extraInitContainers: [] +# - name: es-index-init +# image: alpine/curl:latest +# command: ['/bin/sh', '-c'] +# args: +# - | +# ES_HOST="elasticsearch-master" # Match your ES service name +# ES_PORT="9200" +# ELASTIC_PASSWORD=$(cat /etc/elasticsearch-password/password) +# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/chat_v1_idx?pretty" -H 'Content-Type: application/json' -d' +# { +# "settings": { +# "index": { +# "number_of_shards": 3, +# "number_of_replicas": 1, +# "max_ngram_diff": 2 +# }, +# "analysis": { +# "analyzer": { +# "ngram_analyzer": { +# "type": "custom", +# "tokenizer": "ngram_tokenizer", +# "filter": [ +# "lowercase" +# ] +# }, +# "standard_search_analyzer_lowercase": { +# "type": "custom", +# "tokenizer": "standard", +# "filter": [ +# "lowercase" +# ] +# } +# }, +# "tokenizer": { +# "ngram_tokenizer": { +# "type": "ngram", +# "min_gram": 3, +# "max_gram": 5, +# "token_chars": [] +# } +# }, +# "normalizer": { +# "lowercase_normalizer": { +# "type": "custom", +# "filter": [ +# "lowercase" +# ] +# } +# } +# } +# }, +# "mappings": { +# "properties": { +# "id": { +# "type": "long" +# }, +# "name": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "name_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "description": { +# "type": "text", +# "analyzer": "standard", +# "search_analyzer": "standard_search_analyzer_lowercase", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "_class": { +# "type": "text", +# "fields": { +# "keyword": { +# "ignore_above": 256.0, +# "type": "keyword" +# } +# } +# } +# } +# } +# } +# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/message_v1_idx?pretty" -H 'Content-Type: application/json' -d' +# { +# "settings": { +# "index": { +# "number_of_shards": "3", +# "number_of_replicas": "1" +# }, +# "analysis": { +# "analyzer": { +# "edge_ngram_index_analyzer": { +# "tokenizer": "edge_ngram_index_tokenizer", +# "filter": [ +# "lowercase", +# "apostrophe", +# "classic" +# ] +# }, +# "message_search_analyzer": { +# "tokenizer": "standard" +# } +# }, +# "tokenizer": { +# "edge_ngram_index_tokenizer": { +# "type": "edge_ngram", +# "min_gram": 1, +# "max_gram": 20, +# "token_chars": [ +# "letter", +# "digit" +# ] +# } +# } +# } +# }, +# "mappings": { +# "properties": { +# "chatId": { +# "type": "long" +# }, +# "messageId": { +# "type": "long" +# }, +# "serverTime": { +# "type": "long" +# }, +# "_class": { +# "type": "text", +# "fields": { +# "keyword": { +# "ignore_above": 256.0, +# "type": "keyword" +# } +# } +# }, +# "id": { +# "type": "keyword" +# }, +# "text": { +# "type": "text", +# "analyzer": "edge_ngram_index_analyzer", +# "search_analyzer": "message_search_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# } +# } +# } +# } +# curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/user_v1_idx?pretty" -H 'Content-Type: application/json' -d' +# { +# "settings": { +# "index": { +# "number_of_shards": 3, +# "number_of_replicas": 1, +# "max_ngram_diff": 2 +# }, +# "analysis": { +# "analyzer": { +# "ngram_analyzer": { +# "type": "custom", +# "tokenizer": "ngram_tokenizer", +# "filter": [ +# "lowercase" +# ] +# }, +# "standard_search_analyzer_lowercase": { +# "type": "custom", +# "tokenizer": "standard", +# "filter": [ +# "lowercase" +# ] +# } +# }, +# "tokenizer": { +# "ngram_tokenizer": { +# "type": "ngram", +# "min_gram": 3, +# "max_gram": 5, +# "token_chars": [] +# } +# }, +# "normalizer": { +# "lowercase_normalizer": { +# "type": "custom", +# "filter": [ +# "lowercase" +# ] +# } +# } +# } +# }, +# "mappings": { +# "properties": { +# "id": { +# "type": "long" +# }, +# "username": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "username_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "nickname": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "nickname_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "phone": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "phone_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "email": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "email_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "job_title": { +# "type": "keyword", +# "normalizer": "lowercase_normalizer" +# }, +# "job_title_ngram": { +# "type": "text", +# "analyzer": "ngram_analyzer", +# "search_analyzer": "ngram_analyzer", +# "index_options": "offsets", +# "term_vector": "with_positions_offsets" +# }, +# "_class": { +# "type": "text", +# "fields": { +# "keyword": { +# "ignore_above": 256.0, +# "type": "keyword" +# } +# } +# } +# } +# } +# } +# volumeMounts: +# - name: elasticsearch-password +# mountPath: /etc/elasticsearch-password +# readOnly: true extraVolumes: # Mount the JSON template - name: index-template configMap: name: index-template-1 -# - name: http-cert -# secret: -# secretName: elasticsearch-master-certs + - name: http-cert + secret: + secretName: elasticsearch-master-certs # (Secret volume is optional; we’ll inject via envFrom) # This is the PriorityClass settings as defined in @@ -212,7 +486,7 @@ podManagementPolicy: "Parallel" # If you experience slow pod startups you probably want to set this to `false`. enableServiceLinks: true -protocol: http +protocol: https httpPort: 9200 transportPort: 9300 @@ -258,13 +532,13 @@ sysctlVmMaxMapCount: 262144 readinessProbe: failureThreshold: 3 - initialDelaySeconds: 30 - timeoutSeconds: 10 - failureThreshold: 5 + initialDelaySeconds: 10 periodSeconds: 10 + successThreshold: 3 + timeoutSeconds: 5 # https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html#request-params wait_for_status -clusterHealthCheckParams: "wait_for_status=green&timeout=15s" +clusterHealthCheckParams: "wait_for_status=green&timeout=1s" ## Use an alternate scheduler. ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ @@ -306,7 +580,7 @@ postStart: set -euo pipefail echo "[postStart] Waiting for Elasticsearch to be ready..." >&2 for ((i=1; i<=MAX_RETRIES; i++)); do - if /usr/bin/curl -s "$ES_URL" >/dev/null; then # Removed --cacert and -u flags + if /usr/bin/curl --cacert "$CA_CERT" -s -u "$ES_USERNAME:$ELASTIC_PASSWORD" "$ES_URL" >/dev/null; then echo "[postStart] Elasticsearch is up after $i attempts!" >&2 break fi @@ -316,69 +590,30 @@ postStart: fi sleep 5 done - echo "[postStart] Loading index templates..." >&2 - if ! /usr/bin/curl -X PUT "$ES_URL/chat" \ # Removed auth flags + echo "[postStart] Loading index template from $TEMPLATE_PATH" >&2 + if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/chat" \ + -u "$ES_USERNAME:$ES_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_1"; then - echo "[postStart] ERROR: Failed to apply chat template!" >&2 + echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi - if ! /usr/bin/curl -X PUT "$ES_URL/message" \ + if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/message" \ + -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_2"; then - echo "[postStart] ERROR: Failed to apply message template!" >&2 + echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi - if ! /usr/bin/curl -X PUT "$ES_URL/user" \ + if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/user" \ + -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_3"; then - echo "[postStart] ERROR: Failed to apply user template!" >&2 + echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi - echo "[postStart] All index templates applied successfully." >&2 -#postStart: -# exec: -# command: -# - /bin/bash -# - -c -# - | -# set -euo pipefail -# echo "[postStart] Waiting for Elasticsearch to be ready..." >&2 -# for ((i=1; i<=MAX_RETRIES; i++)); do -# if /usr/bin/curl --cacert "$CA_CERT" -s -u "$ES_USERNAME:$ELASTIC_PASSWORD" "$ES_URL" >/dev/null; then -# echo "[postStart] Elasticsearch is up after $i attempts!" >&2 -# break -# fi -# if [ "$i" -eq "$MAX_RETRIES" ]; then -# echo "[postStart] ERROR: Elasticsearch did not become ready after $MAX_RETRIES attempts." >&2 -# exit 1 -# fi -# sleep 5 -# done -# echo "[postStart] Loading index template from $TEMPLATE_PATH" >&2 -# if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/chat" \ -# -u "$ES_USERNAME:$ES_PASSWORD" \ -# -H 'Content-Type: application/json' \ -# --data-binary @"$TEMPLATE_PATH_1"; then -# echo "[postStart] ERROR: Failed to apply index template!" >&2 -# exit 1 -# fi -# if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/message" \ -# -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -# -H 'Content-Type: application/json' \ -# --data-binary @"$TEMPLATE_PATH_2"; then -# echo "[postStart] ERROR: Failed to apply index template!" >&2 -# exit 1 -# fi -# if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/user" \ -# -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -# -H 'Content-Type: application/json' \ -# --data-binary @"$TEMPLATE_PATH_3"; then -# echo "[postStart] ERROR: Failed to apply index template!" >&2 -# exit 1 -# fi -# echo "[postStart] Index template 'chat_v1_idx' applied." >&2 -# echo "Debug message" >> /poststart.log 2>&1 + echo "[postStart] Index template 'chat_v1_idx' applied." >&2 + echo "Debug message" >> /poststart.log 2>&1 sysctlInitContainer: enabled: true @@ -395,7 +630,7 @@ networkPolicy: ## elasticsearch-master-transport-client: "true" http: - enabled: true + enabled: false ## if explicitNamespacesSelector is not set or set to {}, only client Pods being in the networkPolicy's namespace ## and matching all criteria can reach the DB. ## But sometimes, we want the Pods to be accessible to clients from other namespaces, in this case, we can use this