Работа напрямую с разнообразными API Elasticsearch может быть сложной и неэффективной. CSS упрощает это, предоставляя High Level REST Client, предлагая более эффективный способ выполнения запросов и управления вашими данными. High Level REST Client инкапсулирует API Elasticsearch. Вам нужно лишь сформировать необходимые структуры запросов для доступа к кластеру Elasticsearch. Это упрощает процесс работы с кластерами Elasticsearch, а также процесс разработки. Для получения подробной информации о том, как использовать REST Client, см. Java High Level REST Client.
Если версия High Level REST Client новее версии кластера Elasticsearch и возникают проблемы совместимости с некоторыми запросами, вы можете использовать RestHighLevelClient.getLowLevelClient() для получения Low Level REST Client и настройки запросов Elasticsearch. Для получения подробной информации см. Connecting to a Cluster Using the Low Level REST Client.
Импортируйте зависимости Java на сервере, где выполняется код Java, используя один из следующих способов:
Замените 7.10.2 на фактическую версию Java‑клиента.
<dependency><groupId>org.elasticsearch.client</groupId><artifactId>elasticsearch-rest-high-level-client</artifactId><version>7.10.2</version></dependency><dependency><groupId>org.elasticsearch</groupId><artifactId>elasticsearch</artifactId><version>7.10.2</version></dependency>
Замените 7.10.2 на фактическую версию Java‑клиента.
compile group: 'org.elasticsearch.client', name: 'elasticsearch-rest-high-level-client', version: '7.10.2'
Пример кода зависит от настроек режима безопасности целевого кластера Elasticsearch. Выберите соответствующий справочный документ в зависимости от вашего сценария обслуживания.
Настройки режима безопасности кластера Elasticsearch | Нужно ли загружать сертификат безопасности | Details |
|---|---|---|
Режим без безопасности | - | Подключение к кластеру в режиме без безопасности с использованием High Level REST Client |
Security mode + HTTP Security mode + HTTPS | No | |
Security mode + HTTPS | Yes |
Используйте High Level REST Client для подключения к кластеру Elasticsearch, у которого отключён режим безопасности, и выполните запрос, существует ли индекс test. Пример кода приведён ниже:
1234567891011121314151617181920212223242526272829303132import org.apache.http.HttpHost;import org.elasticsearch.client.RequestOptions;import org.elasticsearch.client.RestClient;import org.elasticsearch.client.RestClientBuilder;import org.elasticsearch.client.RestHighLevelClient;import org.elasticsearch.client.indices.GetIndexRequest;import java.io.IOException;import java.util.Arrays;import java.util.List;/*** Use the High Level REST Client to connect to a non-security mode cluster.*/public class Main {public static void main(String[] args) throws IOException {List<String> host = Arrays.asList("{Cluster access address}");RestClientBuilder builder = RestClient.builder(constructHttpHosts(host, 9200, "http"));final RestHighLevelClient client = new RestHighLevelClient(builder);GetIndexRequest indexRequest = new GetIndexRequest("test");boolean exists = client.indices().exists(indexRequest, RequestOptions.DEFAULT);System.out.println(exists);client.close();}/*** Use the constructHttpHosts function to convert the node IP address list of the host cluster.*/public static HttpHost[] constructHttpHosts(List<String> host, int port, String protocol) {return host.stream().map(p -> new HttpHost(p, port, protocol)).toArray(HttpHost[]::new);}}
Этот фрагмент кода проверяет, существует ли индекс test в кластере. Если возвращается true (индекс существует) или false (индекс не существует), это указывает на то, что кластер подключён.
Используйте High Level REST Client для подключения к кластеру Elasticsearch в режиме безопасности (HTTP или HTTPS) без загрузки сертификата безопасности и выполните запрос, существует ли индекс test. Пример кода приведён ниже:
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115import org.apache.http.HttpHost;import org.apache.http.auth.AuthScope;import org.apache.http.auth.UsernamePasswordCredentials;import org.apache.http.client.CredentialsProvider;import org.apache.http.conn.ssl.NoopHostnameVerifier;import org.apache.http.impl.client.BasicCredentialsProvider;import org.apache.http.nio.conn.ssl.SSLIOSessionStrategy;import org.apache.logging.log4j.LogManager;import org.apache.logging.log4j.Logger;import org.elasticsearch.action.admin.cluster.health.ClusterHealthRequest;import org.elasticsearch.action.admin.cluster.health.ClusterHealthResponse;import org.elasticsearch.client.RequestOptions;import org.elasticsearch.client.RestClient;import org.elasticsearch.client.RestClientBuilder;import org.elasticsearch.client.RestHighLevelClient;import org.elasticsearch.client.indices.GetIndexRequest;import java.io.IOException;import java.security.KeyManagementException;import java.security.NoSuchAlgorithmException;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import java.util.Arrays;import java.util.List;import java.util.concurrent.TimeUnit;import javax.net.ssl.SSLContext;import javax.net.ssl.TrustManager;import javax.net.ssl.X509TrustManager;/*** Use the High Level REST Client to connect to a security-mode cluster (without a certificate).*/public class Main {private static final Logger logger = LogManager.getLogger(Main.class);/*** Create a class for the client. Define the create function.*/public static RestHighLevelClient create(List<String> host, int port, String protocol, int connectTimeout,int connectionRequestTimeout, int socketTimeout, String username, String password) throws IOException {RestClientBuilder builder = RestClient.builder(constructHttpHosts(host, port, protocol)).setRequestConfigCallback(requestConfig -> requestConfig.setConnectTimeout(connectTimeout).setConnectionRequestTimeout(connectionRequestTimeout).setSocketTimeout(socketTimeout)).setHttpClientConfigCallback(httpClientBuilder -> {// enable user authenticationfinal CredentialsProvider credentialsProvider = new BasicCredentialsProvider();credentialsProvider.setCredentials(AuthScope.ANY, new UsernamePasswordCredentials(username, password));httpClientBuilder.setDefaultCredentialsProvider(credentialsProvider);// set keepalivehttpClientBuilder.setKeepAliveStrategy(((httpResponse, httpContext) -> TimeUnit.MINUTES.toMinutes(10)));// enable SSL / TLSSSLContext sc = null;try {sc = SSLContext.getInstance("SSL");sc.init(null, trustAllCerts, new SecureRandom());} catch (KeyManagementException | NoSuchAlgorithmException e) {e.printStackTrace();}SSLIOSessionStrategy sslStrategy = new SSLIOSessionStrategy(sc, new NoopHostnameVerifier());httpClientBuilder.setSSLStrategy(sslStrategy);return httpClientBuilder;});final RestHighLevelClient client = new RestHighLevelClient(builder);logger.info("es rest client build success {} ", client);ClusterHealthRequest request = new ClusterHealthRequest();ClusterHealthResponse response = client.cluster().health(request, RequestOptions.DEFAULT);System.out.println("es rest client health response {} " + response);return client;}/*** Use the constructHttpHosts function to convert the node IP address list of the host cluster.*/public static HttpHost[] constructHttpHosts(List<String> host, int port, String protocol) {return host.stream().map(p -> new HttpHost(p, port, protocol)).toArray(HttpHost[]::new);}/*** Configure trustAllCerts to ignore the certificate configuration.*/public static TrustManager[] trustAllCerts = new TrustManager[] {new X509TrustManager() {@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return null;}}};/*** The following is an example of the main function. Call the create function to create a client and check whether the test index exists.*/public static void main(String[] args) throws IOException {RestHighLevelClient client = create(Arrays.asList("{host}"), 9200, "https", 1000, 1000, 1000, "username", "password");GetIndexRequest indexRequest = new GetIndexRequest("test");boolean exists = client.indices().exists(indexRequest, RequestOptions.DEFAULT);System.out.println(exists);client.close();}}
Параметр | Описание |
|---|---|
host | IP-адрес для доступа к кластеру. Если указано несколько IP-адресов, разделите их запятой (,) . |
port | Порт доступа к кластеру. Значение по умолчанию — 9200. |
protocol | Протокол соединения, который может быть http или https. |
connectTimeout | Тайм-аут сокет‑соединения (в мс). |
connectionRequestTimeout | Тайм-аут запроса сокет‑соединения (в мс). |
socketTimeout | Тайм-аут запроса сокета (в мс). |
username | Имя пользователя для доступа к кластеру. |
password | Пароль пользователя. |
Этот фрагмент кода проверяет, существует ли индекс test в кластере. Если возвращается true (индекс существует) или false (индекс не существует), это указывает на то, что кластер подключён.
Используйте High Level REST Client для подключения к кластеру Elasticsearch в режиме безопасности, использующему HTTPS с загруженным сертификатом безопасности, и проверьте, существует ли индекс test. Пример кода приведён ниже:
Чтобы узнать, как получить и загрузить сертификат безопасности, см. Obtaining and Uploading a Security Certificate.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137import org.apache.http.HttpHost;import org.apache.http.auth.AuthScope;import org.apache.http.auth.UsernamePasswordCredentials;import org.apache.http.client.CredentialsProvider;import org.apache.http.conn.ssl.NoopHostnameVerifier;import org.apache.http.impl.client.BasicCredentialsProvider;import org.apache.http.nio.conn.ssl.SSLIOSessionStrategy;import org.apache.logging.log4j.LogManager;import org.apache.logging.log4j.Logger;import org.elasticsearch.action.admin.cluster.health.ClusterHealthRequest;import org.elasticsearch.action.admin.cluster.health.ClusterHealthResponse;import org.elasticsearch.client.RequestOptions;import org.elasticsearch.client.RestClient;import org.elasticsearch.client.RestClientBuilder;import org.elasticsearch.client.RestHighLevelClient;import org.elasticsearch.client.indices.GetIndexRequest;import java.io.File;import java.io.FileInputStream;import java.io.IOException;import java.io.InputStream;import java.security.KeyStore;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import java.util.Arrays;import java.util.List;import java.util.concurrent.TimeUnit;import javax.net.ssl.SSLContext;import javax.net.ssl.TrustManager;import javax.net.ssl.TrustManagerFactory;import javax.net.ssl.X509TrustManager;/*** Use the Hive Level REST Client to connect to a security-mode cluster (with an HTTPS certificate).*/public class Main {public static RestHighLevelClient create(List<String> host, int port, String protocol, int connectTimeout,int connectionRequestTimeout, int socketTimeout, String username, String password, String certFilePath,String certPassword) throws IOException {RestClientBuilder builder = RestClient.builder(constructHttpHosts(host, port, protocol)).setRequestConfigCallback(requestConfig -> requestConfig.setConnectTimeout(connectTimeout).setConnectionRequestTimeout(connectionRequestTimeout).setSocketTimeout(socketTimeout)).setHttpClientConfigCallback(httpClientBuilder -> {// enable user authenticationfinal CredentialsProvider credentialsProvider = new BasicCredentialsProvider();credentialsProvider.setCredentials(AuthScope.ANY, new UsernamePasswordCredentials(username, password));httpClientBuilder.setDefaultCredentialsProvider(credentialsProvider);// set keepalivehttpClientBuilder.setKeepAliveStrategy(((httpResponse, httpContext) -> TimeUnit.MINUTES.toMinutes(10)));// enable SSL / TLSSSLContext sc = null;try {TrustManager[] tm = {new MyX509TrustManager(certFilePath, certPassword)};sc = SSLContext.getInstance("SSL", "SunJSSE");//You can also use SSLContext sslContext = SSLContext.getInstance("TLSv1.2");sc.init(null, tm, new SecureRandom());} catch (Exception e) {e.printStackTrace();}SSLIOSessionStrategy sslStrategy = new SSLIOSessionStrategy(sc, new NoopHostnameVerifier());httpClientBuilder.setSSLStrategy(sslStrategy);return httpClientBuilder;});final RestHighLevelClient client = new RestHighLevelClient(builder);logger.info("es rest client build success {} ", client);ClusterHealthRequest request = new ClusterHealthRequest();ClusterHealthResponse response = client.cluster().health(request, RequestOptions.DEFAULT);logger.info("es rest client health response {} ", response);return client;}/*** Use the constructHttpHosts function to convert the node IP address list of the host cluster.*/public static HttpHost[] constructHttpHosts(List<String> host, int port, String protocol) {return host.stream().map(p -> new HttpHost(p, port, protocol)).toArray(HttpHost[]::new);}private static final Logger logger = LogManager.getLogger(Main.class);public static class MyX509TrustManager implements X509TrustManager {X509TrustManager sunJSSEX509TrustManager;MyX509TrustManager(String certFilePath, String certPassword) throws Exception {File file = new File(certFilePath);if (!file.isFile()) {throw new Exception("Wrong Certification Path");}System.out.println("Loading KeyStore " + file + "...");InputStream in = new FileInputStream(file);KeyStore ks = KeyStore.getInstance("JKS");ks.load(in, certPassword.toCharArray());TrustManagerFactory tmf = TrustManagerFactory.getInstance("SunX509", "SunJSSE");tmf.init(ks);TrustManager[] tms = tmf.getTrustManagers();for (TrustManager tm : tms) {if (tm instanceof X509TrustManager) {sunJSSEX509TrustManager = (X509TrustManager) tm;return;}}throw new Exception("Couldn't initialize");}@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return new X509Certificate[0];}}/*** The following is an example of the main function. Call the create function to create a client and check whether the test index exists.*/public static void main(String[] args) throws IOException {RestHighLevelClient client = create(Arrays.asList({host}), 9200, "https", 1000, 1000, 1000, "username", "password", "certFilePath", "certPassword");GetIndexRequest indexRequest = new GetIndexRequest("test");boolean exists = client.indices().exists(indexRequest, RequestOptions.DEFAULT);System.out.println(exists);client.close();}}
Параметр | Description |
|---|---|
host | IP-адрес для доступа к кластеру. Если указано несколько IP-адресов, разделите их запятой (,). |
port | Порт доступа к кластеру. Значение по умолчанию 9200. |
protocol | Протокол соединения. Установите этот параметр в https. |
connectTimeout | Тайм‑аут Socket‑соединения (в мс). |
connectionRequestTimeout | Тайм‑аут запроса Socket‑соединения (в мс). |
socketTimeout | Тайм‑аут Socket‑запроса (в мс). |
username | Имя пользователя для доступа к кластеру. |
пароль | Пароль пользователя. |
certFilePath | Путь для хранения сертификата безопасности. |
certPassword | Пароль сертификата безопасности. |
Этот фрагмент кода проверяет, существует ли индекс test в кластере. Если возвращается true (индекс существует) или false (индекс не существует), это указывает на то, что кластер подключён.
Чтобы получить доступ к кластеру Elasticsearch в режиме безопасности, использующему HTTPS, выполните следующие шаги для получения сертификата безопасности, если он требуется, и загрузите его в клиент.
keytool -import -alias newname -keystore ./truststore.jks -file ./CloudSearchService.cer
keytool -import -alias newname -keystore .\truststore.jks -file .\CloudSearchService.cer
В предыдущей команде newname указывает пользовательское имя сертификата.
После выполнения этой команды вам будет предложено задать пароль сертификата и подтвердить пароль. Надёжно сохраните пароль. Он будет использоваться для доступа к кластеру.