--- clusterName: "elasticsearch" nodeGroup: "master" # The service that non master groups will try to connect to when joining the cluster # This should be set to clusterName + "-" + nodeGroup for your master group masterService: "" # Elasticsearch roles that will be applied to this nodeGroup # These will be set as environment variables. E.g. node.roles=master # https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#node-roles roles: - master - data - data_content - data_hot - data_warm - data_cold - ingest - ml - remote_cluster_client - transform replicas: 3 minimumMasterNodes: 2 esMajorVersion: "" # Allows you to add any config files in /usr/share/elasticsearch/config/ # such as elasticsearch.yml and log4j2.properties esConfig: elasticsearch.yml: | xpack.security.enabled: false # Disable Elasticsearch security xpack.security.http.ssl.enabled: false # Disable HTTP SSL xpack.security.transport.ssl.enabled: false # Disable transport SSL createCert: false esJvmOptions: {} # processors.options: | # -XX:ActiveProcessorCount=3 # Extra environment variables to append to this nodeGroup # This will be appended to the current 'env:' key. You can use any of the kubernetes env # syntax here extraEnvs: - name: ES_USERNAME valueFrom: secretKeyRef: name: elasticsearch-master-credentials key: username - name: ES_PASSWORD valueFrom: secretKeyRef: name: elasticsearch-master-credentials key: password - name: CA_CERT value: "/usr/share/elasticsearch/config/http-certs/ca.crt" - name: ES_URL value: "http://elasticsearch-master:9200" - name: TEMPLATE_PATH_1 value: "/usr/share/elasticsearch/templates/chat_v1_idx.json" - name: TEMPLATE_PATH_2 value: "/usr/share/elasticsearch/templates/message_v1_idx.json" - name: TEMPLATE_PATH_3 value: "/usr/share/elasticsearch/templates/user_v1_idx.json" - name: MAX_RETRIES value: "30" # Allows you to load environment variables from kubernetes secret or config map envFrom: [] # - secretRef: # name: env-secret # - configMapRef: # name: config-map # Disable it to use your own elastic-credential Secret. secret: enabled: false password: "" # generated randomly if not defined # A list of secrets and their paths to mount inside the pod # This is useful for mounting certificates for security and for mounting # the X-Pack license secretMounts: [] # - name: elastic-certificates # secretName: elastic-certificates # path: /usr/share/elasticsearch/config/certs # defaultMode: 0755 hostAliases: [] #- ip: "127.0.0.1" # hostnames: # - "foo.local" # - "bar.local" image: "docker.io/library/elasticsearch" imageTag: "8.5.1" imagePullPolicy: "IfNotPresent" podAnnotations: {} # iam.amazonaws.com/role: es-cluster # additionals labels labels: {} esJavaOpts: "" # example: "-Xmx1g -Xms1g" resources: requests: cpu: "1000m" memory: "2Gi" limits: cpu: "1000m" memory: "2Gi" initResources: {} # limits: # cpu: "25m" # # memory: "128Mi" # requests: # cpu: "25m" # memory: "128Mi" networkHost: "0.0.0.0" volumeClaimTemplate: accessModes: ["ReadWriteOnce"] resources: requests: storage: 30Gi rbac: create: false serviceAccountAnnotations: {} serviceAccountName: "" automountToken: true podSecurityPolicy: create: false name: "" spec: privileged: true fsGroup: rule: RunAsAny runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny volumes: - secret - configMap - persistentVolumeClaim - emptyDir persistence: enabled: true labels: # Add default labels for the volumeClaimTemplate of the StatefulSet enabled: false annotations: {} extraVolumeMounts: - name: index-template mountPath: /usr/share/elasticsearch/templates readOnly: true - name: http-cert mountPath: /usr/share/elasticsearch/config/http-certs readOnly: true extraContainers: [] # - name: do-something # image: busybox # command: ['do', 'something'] extraInitContainers: [] # - name: es-index-init # image: alpine/curl:latest # command: ['/bin/sh', '-c'] # args: # - | # ES_HOST="elasticsearch-master" # Match your ES service name # ES_PORT="9200" # ELASTIC_PASSWORD=$(cat /etc/elasticsearch-password/password) # curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/chat_v1_idx?pretty" -H 'Content-Type: application/json' -d' # { # "settings": { # "index": { # "number_of_shards": 3, # "number_of_replicas": 1, # "max_ngram_diff": 2 # }, # "analysis": { # "analyzer": { # "ngram_analyzer": { # "type": "custom", # "tokenizer": "ngram_tokenizer", # "filter": [ # "lowercase" # ] # }, # "standard_search_analyzer_lowercase": { # "type": "custom", # "tokenizer": "standard", # "filter": [ # "lowercase" # ] # } # }, # "tokenizer": { # "ngram_tokenizer": { # "type": "ngram", # "min_gram": 3, # "max_gram": 5, # "token_chars": [] # } # }, # "normalizer": { # "lowercase_normalizer": { # "type": "custom", # "filter": [ # "lowercase" # ] # } # } # } # }, # "mappings": { # "properties": { # "id": { # "type": "long" # }, # "name": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "name_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "description": { # "type": "text", # "analyzer": "standard", # "search_analyzer": "standard_search_analyzer_lowercase", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "_class": { # "type": "text", # "fields": { # "keyword": { # "ignore_above": 256.0, # "type": "keyword" # } # } # } # } # } # } # curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/message_v1_idx?pretty" -H 'Content-Type: application/json' -d' # { # "settings": { # "index": { # "number_of_shards": "3", # "number_of_replicas": "1" # }, # "analysis": { # "analyzer": { # "edge_ngram_index_analyzer": { # "tokenizer": "edge_ngram_index_tokenizer", # "filter": [ # "lowercase", # "apostrophe", # "classic" # ] # }, # "message_search_analyzer": { # "tokenizer": "standard" # } # }, # "tokenizer": { # "edge_ngram_index_tokenizer": { # "type": "edge_ngram", # "min_gram": 1, # "max_gram": 20, # "token_chars": [ # "letter", # "digit" # ] # } # } # } # }, # "mappings": { # "properties": { # "chatId": { # "type": "long" # }, # "messageId": { # "type": "long" # }, # "serverTime": { # "type": "long" # }, # "_class": { # "type": "text", # "fields": { # "keyword": { # "ignore_above": 256.0, # "type": "keyword" # } # } # }, # "id": { # "type": "keyword" # }, # "text": { # "type": "text", # "analyzer": "edge_ngram_index_analyzer", # "search_analyzer": "message_search_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # } # } # } # } # curl -u "elastic:${ELASTIC_PASSWORD}" -X PUT "http://${ES_HOST}:${ES_PORT}/user_v1_idx?pretty" -H 'Content-Type: application/json' -d' # { # "settings": { # "index": { # "number_of_shards": 3, # "number_of_replicas": 1, # "max_ngram_diff": 2 # }, # "analysis": { # "analyzer": { # "ngram_analyzer": { # "type": "custom", # "tokenizer": "ngram_tokenizer", # "filter": [ # "lowercase" # ] # }, # "standard_search_analyzer_lowercase": { # "type": "custom", # "tokenizer": "standard", # "filter": [ # "lowercase" # ] # } # }, # "tokenizer": { # "ngram_tokenizer": { # "type": "ngram", # "min_gram": 3, # "max_gram": 5, # "token_chars": [] # } # }, # "normalizer": { # "lowercase_normalizer": { # "type": "custom", # "filter": [ # "lowercase" # ] # } # } # } # }, # "mappings": { # "properties": { # "id": { # "type": "long" # }, # "username": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "username_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "nickname": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "nickname_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "phone": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "phone_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "email": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "email_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "job_title": { # "type": "keyword", # "normalizer": "lowercase_normalizer" # }, # "job_title_ngram": { # "type": "text", # "analyzer": "ngram_analyzer", # "search_analyzer": "ngram_analyzer", # "index_options": "offsets", # "term_vector": "with_positions_offsets" # }, # "_class": { # "type": "text", # "fields": { # "keyword": { # "ignore_above": 256.0, # "type": "keyword" # } # } # } # } # } # } # volumeMounts: # - name: elasticsearch-password # mountPath: /etc/elasticsearch-password # readOnly: true extraVolumes: # Mount the JSON template - name: index-template configMap: name: index-template-1 # - name: http-cert # secret: # secretName: elasticsearch-master-certs # (Secret volume is optional; we’ll inject via envFrom) # This is the PriorityClass settings as defined in # https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass priorityClassName: "" # By default this will make sure two pods don't end up on the same node # Changing this to a region would allow you to spread pods across regions antiAffinityTopologyKey: "kubernetes.io/hostname" # Hard means that by default pods will only be scheduled if there are enough nodes for them # and that they will never end up on the same node. Setting this to soft will do this "best effort" antiAffinity: "hard" # This is the node affinity settings as defined in # https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#node-affinity-beta-feature nodeAffinity: {} # The default is to deploy all pods serially. By setting this to parallel all pods are started at # the same time when bootstrapping the cluster podManagementPolicy: "Parallel" # The environment variables injected by service links are not used, but can lead to slow Elasticsearch boot times when # there are many services in the current namespace. # If you experience slow pod startups you probably want to set this to `false`. enableServiceLinks: true protocol: http httpPort: 9200 transportPort: 9300 service: enabled: true labels: {} labelsHeadless: {} type: ClusterIP # Consider that all endpoints are considered "ready" even if the Pods themselves are not # https://kubernetes.io/docs/reference/kubernetes-api/service-resources/service-v1/#ServiceSpec publishNotReadyAddresses: false nodePort: "" annotations: {} httpPortName: http transportPortName: transport loadBalancerIP: "" loadBalancerSourceRanges: [] externalTrafficPolicy: "" updateStrategy: RollingUpdate # This is the max unavailable setting for the pod disruption budget # The default value of 1 will make sure that kubernetes won't allow more than 1 # of your pods to be unavailable during maintenance maxUnavailable: 1 podSecurityContext: fsGroup: 1000 runAsUser: 1000 securityContext: capabilities: drop: - ALL # readOnlyRootFilesystem: true runAsNonRoot: true runAsUser: 1000 # How long to wait for elasticsearch to stop gracefully terminationGracePeriod: 120 sysctlVmMaxMapCount: 262144 readinessProbe: failureThreshold: 3 initialDelaySeconds: 10 periodSeconds: 10 successThreshold: 3 timeoutSeconds: 5 # https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-health.html#request-params wait_for_status clusterHealthCheckParams: "wait_for_status=green&timeout=1s" ## Use an alternate scheduler. ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ ## schedulerName: "" imagePullSecrets: [] nodeSelector: {} tolerations: [] # Enabling this will publicly expose your Elasticsearch instance. # Only enable this if you have security enabled on your cluster ingress: enabled: false annotations: {} # kubernetes.io/ingress.class: nginx # kubernetes.io/tls-acme: "true" className: "nginx" pathtype: ImplementationSpecific hosts: - host: chart-example.local paths: - path: / tls: [] # - secretName: chart-example-tls # hosts: # - chart-example.local nameOverride: "" fullnameOverride: "" healthNameOverride: "" lifecycle: {} postStart: exec: command: - /bin/bash - -c - | set -euo pipefail echo "[postStart] Waiting for Elasticsearch to be ready..." >&2 for ((i=1; i<=MAX_RETRIES; i++)); do if /usr/bin/curl --cacert "$CA_CERT" -s -u "$ES_USERNAME:$ELASTIC_PASSWORD" "$ES_URL" >/dev/null; then echo "[postStart] Elasticsearch is up after $i attempts!" >&2 break fi if [ "$i" -eq "$MAX_RETRIES" ]; then echo "[postStart] ERROR: Elasticsearch did not become ready after $MAX_RETRIES attempts." >&2 exit 1 fi sleep 5 done echo "[postStart] Loading index template from $TEMPLATE_PATH" >&2 if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/chat" \ -u "$ES_USERNAME:$ES_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_1"; then echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/message" \ -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_2"; then echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi if ! /usr/bin/curl --cacert "$CA_CERT" -X PUT "$ES_URL/user" \ -u "$ES_USERNAME:$ELASTIC_PASSWORD" \ -H 'Content-Type: application/json' \ --data-binary @"$TEMPLATE_PATH_3"; then echo "[postStart] ERROR: Failed to apply index template!" >&2 exit 1 fi echo "[postStart] Index template 'chat_v1_idx' applied." >&2 echo "Debug message" >> /poststart.log 2>&1 sysctlInitContainer: enabled: true keystore: [] networkPolicy: ## Enable creation of NetworkPolicy resources. Only Ingress traffic is filtered for now. ## In order for a Pod to access Elasticsearch, it needs to have the following label: ## {{ template "uname" . }}-client: "true" ## Example for default configuration to access HTTP port: ## elasticsearch-master-http-client: "true" ## Example for default configuration to access transport port: ## elasticsearch-master-transport-client: "true" http: enabled: true ## if explicitNamespacesSelector is not set or set to {}, only client Pods being in the networkPolicy's namespace ## and matching all criteria can reach the DB. ## But sometimes, we want the Pods to be accessible to clients from other namespaces, in this case, we can use this ## parameter to select these namespaces ## # explicitNamespacesSelector: # # Accept from namespaces with all those different rules (only from whitelisted Pods) # matchLabels: # role: frontend # matchExpressions: # - {key: role, operator: In, values: [frontend]} ## Additional NetworkPolicy Ingress "from" rules to set. Note that all rules are OR-ed. ## # additionalRules: # - podSelector: # matchLabels: # role: frontend # - podSelector: # matchExpressions: # - key: role # operator: In # values: # - frontend transport: ## Note that all Elasticsearch Pods can talk to themselves using transport port even if enabled. enabled: false # explicitNamespacesSelector: # matchLabels: # role: frontend # matchExpressions: # - {key: role, operator: In, values: [frontend]} # additionalRules: # - podSelector: # matchLabels: # role: frontend # - podSelector: # matchExpressions: # - key: role # operator: In # values: # - frontend tests: enabled: true