--- clusterName: "elasticsearch" nodeGroup: "master" # The service that non master groups will try to connect to when joining the cluster # This should be set to clusterName + "-" + nodeGroup for your master group masterService: "" # Elasticsearch roles that will be applied to this nodeGroup # These will be set as environment variables. E.g. node.roles=master # https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#node-roles roles: - master - data - data_content - data_hot - data_warm - data_cold - ingest - ml - remote_cluster_client - transform replicas: 3 minimumMasterNodes: 2 esMajorVersion: "" # Allows you to add any config files in /usr/share/elasticsearch/config/ # such as elasticsearch.yml and log4j2.properties esConfig: elasticsearch.yml: | xpack.security.enabled: false xpack.security.http.ssl.enabled: false xpack.security.transport.ssl.enabled: false createCert: false esJvmOptions: {} # processors.options: | # -XX:ActiveProcessorCount=3 # Extra environment variables to append to this nodeGroup # This will be appended to the current 'env:' key. You can use any of the kubernetes env # syntax here extraEnvs: - name: ES_USERNAME valueFrom: secretKeyRef: name: elasticsearch-master-credentials key: username - name: ES_PASSWORD valueFrom: secretKeyRef: name: elasticsearch-master-credentials key: password # - name: CA_CERT # value: "/usr/share/elasticsearch/config/http-certs/ca.crt" - name: ES_URL value: "http://elasticsearch-master:9200" - name: TEMPLATE_PATH_1 value: "/usr/share/elasticsearch/templates/chat_v1_idx.json" - name: TEMPLATE_PATH_2 value: "/usr/share/elasticsearch/templates/message_v1_idx.json" - name: TEMPLATE_PATH_3 value: "/usr/share/elasticsearch/templates/user_v1_idx.json" - name: MAX_RETRIES value: "30" # Allows you to load environment variables from kubernetes secret or config map envFrom: [] # - secretRef: # name: env-secret # - configMapRef: # name: config-map # Disable it to use your own elastic-credential Secret. secret: enabled: true password: "" # generated randomly if not defined # A list of secrets and their paths to mount inside the pod # This is useful for mounting certificates for security and for mounting # the X-Pack license secretMounts: [] # - name: elastic-certificates # secretName: elastic-certificates # path: /usr/share/elasticsearch/config/certs # defaultMode: 0755 hostAliases: [] #- ip: "127.0.0.1" # hostnames: # - "foo.local" # - "bar.local" image: "docker.io/library/elasticsearch" imageTag: "8.5.1" imagePullPolicy: "IfNotPresent" podAnnotations: {} # iam.amazonaws.com/role: es-cluster # additionals labels labels: {} esJavaOpts: "" # example: "-Xmx1g -Xms1g" resources: requests: cpu: "1000m" memory: "2Gi" limits: cpu: "1000m" memory: "2Gi" initResources: {} # limits: # cpu: "25m" # # memory: "128Mi" # requests: # cpu: "25m" # memory: "128Mi" networkHost: "0.0.0.0" volumeClaimTemplate: storageClassName: "client2" accessModes: ["ReadWriteOnce"] resources: requests: storage: 30Gi rbac: create: false serviceAccountAnnotations: {} serviceAccountName: "" automountToken: true podSecurityPolicy: create: false name: "" spec: privileged: true fsGroup: rule: RunAsAny runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny volumes: - secret - configMap - persistentVolumeClaim - emptyDir persistence: enabled: true labels: enabled: false annotations: {} extraVolumeMounts: - name: index-template mountPath: /usr/share/elasticsearch/templates readOnly: true # - name: poststart-logs # mountPath: /poststart # - name: http-cert # mountPath: /usr/share/elasticsearch/config/http-certs # readOnly: true extraContainers: [] - name: elasticsearch-template-loader image: docker.io/library/elasticsearch:8.5.1 command: - /bin/bash - -c - | set -ex echo "[initContainer] Waiting for Elasticsearch at $ES_URL..." for i in $(seq 1 ${MAX_RETRIES:-30}); do if curl -s "$ES_URL" >/dev/null; then echo "[initContainer] Elasticsearch is up!" break fi echo "[initContainer] Attempt $i: ES not ready, sleeping..." sleep "${RETRY_INTERVAL:-5}" done echo "[initContainer] Applying templates..." for idx in "chat:$TEMPLATE_PATH_1" "message:$TEMPLATE_PATH_2" "user:$TEMPLATE_PATH_3"; do name="${idx%%:*}" path="${idx##*:}" echo "[initContainer] Applying $name from $path..." curl -X PUT "$ES_URL/$name" \ -H 'Content-Type: application/json' \ --data-binary @"$path" done echo "[initContainer] Done applying templates." env: - name: ES_URL value: "http://elasticsearch-master:9200" - name: TEMPLATE_PATH_1 value: "/templates/chat.json" - name: TEMPLATE_PATH_2 value: "/templates/message.json" - name: TEMPLATE_PATH_3 value: "/templates/user.json" volumeMounts: - name: index-template mountPath: /templates extraInitContainers: [] extraVolumes: # Mount the JSON template - name: index-template configMap: name: index-template-1 - name: http-cert secret: secretName: elasticsearch-master-certs # (Secret volume is optional; we’ll inject via envFrom) # This is the PriorityClass settings as defined in # https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass priorityClassName: "" # By default this will make sure two pods don't end up on the same node # Changing this to a region would allow you to spread pods across regions antiAffinityTopologyKey: "kubernetes.io/hostname" # Hard means that by default pods will only be scheduled if there are enough nodes for them # and that they will never end up on the same node. Setting this to soft will do this "best effort" antiAffinity: "hard" # This is the node affinity settings as defined in # https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#node-affinity-beta-feature nodeAffinity: {} # The default is to deploy all pods serially. By setting this to parallel all pods are started at # the same time when bootstrapping the cluster podManagementPolicy: "Parallel" # The environment variables injected by service links are not used, but can lead to slow Elasticsearch boot times when # there are many services in the current namespace. # If you experience slow pod startups you probably want to set this to `false`. enableServiceLinks: true protocol: http httpPort: 9200 transportPort: 9300 service: enabled: true labels: {} labelsHeadless: {} type: ClusterIP # Consider that all endpoints are considered "ready" even if the Pods themselves are not # https://kubernetes.io/docs/reference/kubernetes-api/service-resources/service-v1/#ServiceSpec publishNotReadyAddresses: false nodePort: "" annotations: {} httpPortName: http transportPortName: transport loadBalancerIP: "" loadBalancerSourceRanges: [] externalTrafficPolicy: "" updateStrategy: RollingUpdate # This is the max unavailable setting for the pod disruption budget # The default value of 1 will make sure that kubernetes won't allow more than 1 # of your pods to be unavailable during maintenance maxUnavailable: 1 podSecurityContext: fsGroup: 1000 runAsUser: 1000 securityContext: capabilities: drop: - ALL # readOnlyRootFilesystem: true runAsNonRoot: true runAsUser: 1000 # How long to wait for elasticsearch to stop gracefully terminationGracePeriod: 120 sysctlVmMaxMapCount: 262144 readinessProbe: failureThreshold: 3 initialDelaySeconds: 10 periodSeconds: 10 successThreshold: 3 timeoutSeconds: 5 # https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html#request-params wait_for_status clusterHealthCheckParams: "wait_for_status=green&timeout=1s" ## Use an alternate scheduler. ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ ## schedulerName: "" imagePullSecrets: [] nodeSelector: tenant: client2 tolerations: - key: "node-role.kubernetes.io/control-plane" operator: "Exists" effect: "NoSchedule" # Enabling this will publicly expose your Elasticsearch instance. # Only enable this if you have security enabled on your cluster ingress: enabled: false annotations: {} # kubernetes.io/ingress.class: nginx # kubernetes.io/tls-acme: "true" className: "nginx" pathtype: ImplementationSpecific hosts: - host: chart-example.local paths: - path: / tls: [] # - secretName: chart-example-tls # hosts: # - chart-example.local nameOverride: "" fullnameOverride: "" healthNameOverride: "" lifecycle: {} postStart: {} # exec: # command: # - /bin/bash # - -c # - | # echo "[postStart] Starting postStart hook..." >&2 # # Default values (override in env) # MAX_RETRIES="${MAX_RETRIES:-30}" # RETRY_INTERVAL="${RETRY_INTERVAL:-5}" # # Validate required env vars # REQUIRED_VARS=( "ES_URL" "TEMPLATE_PATH_1" "TEMPLATE_PATH_2" "TEMPLATE_PATH_3") # for var in "${REQUIRED_VARS[@]}"; do # if [ -z "${!var:-}" ]; then # echo "[postStart] ERROR: Required env var '$var' is not set!" >&2 # exit 1 # fi # done # echo "[postStart] Waiting for Elasticsearch at $ES_URL to be ready..." >&2 # for ((i=1; i<=MAX_RETRIES; i++)); do # if /usr/bin/curl -s "$ES_URL" >/dev/null; then # echo "[postStart] Elasticsearch is up after $i attempts!" >&2 # break # fi # if [ "$i" -eq "$MAX_RETRIES" ]; then # echo "[postStart] ERROR: Elasticsearch did not become ready after $MAX_RETRIES attempts." >&2 # exit 1 # fi # echo "[postStart] Attempt $i: Elasticsearch not ready, retrying in $RETRY_INTERVAL seconds..." >&2 # sleep "$RETRY_INTERVAL" # done # echo "[postStart] Applying index templates..." >&2 # for idx in "chat:$TEMPLATE_PATH_1" "message:$TEMPLATE_PATH_2" "user:$TEMPLATE_PATH_3"; do # name="${idx%%:*}" # path="${idx##*:}" # if ! /usr/bin/curl -X PUT "$ES_URL/$name" \ # -H 'Content-Type: application/json' \ # --data-binary @"$path"; then # echo "[postStart] ERROR: Failed to apply index template for '$name' from '$path'" >&2 # exit 1 # fi # echo "[postStart] Applied template: $name" >&2 # done # echo "[postStart] All index templates applied successfully." >&2 # sysctlInitContainer: enabled: true keystore: [] networkPolicy: ## Enable creation of NetworkPolicy resources. Only Ingress traffic is filtered for now. ## In order for a Pod to access Elasticsearch, it needs to have the following label: ## {{ template "uname" . }}-client: "true" ## Example for default configuration to access HTTP port: ## elasticsearch-master-http-client: "true" ## Example for default configuration to access transport port: ## elasticsearch-master-transport-client: "true" http: enabled: false ## if explicitNamespacesSelector is not set or set to {}, only client Pods being in the networkPolicy's namespace ## and matching all criteria can reach the DB. ## But sometimes, we want the Pods to be accessible to clients from other namespaces, in this case, we can use this ## parameter to select these namespaces ## # explicitNamespacesSelector: # # Accept from namespaces with all those different rules (only from whitelisted Pods) # matchLabels: # role: frontend # matchExpressions: # - {key: role, operator: In, values: [frontend]} ## Additional NetworkPolicy Ingress "from" rules to set. Note that all rules are OR-ed. ## # additionalRules: # - podSelector: # matchLabels: # role: frontend # - podSelector: # matchExpressions: # - key: role # operator: In # values: # - frontend transport: ## Note that all Elasticsearch Pods can talk to themselves using transport port even if enabled. enabled: false # explicitNamespacesSelector: # matchLabels: # role: frontend # matchExpressions: # - {key: role, operator: In, values: [frontend]} # additionalRules: # - podSelector: # matchLabels: # role: frontend # - podSelector: # matchExpressions: # - key: role # operator: In # values: # - frontend tests: enabled: true