Работа напрямую с базовыми API Elasticsearch может увеличить сложность разработки, например, дополнительные задачи по обслуживанию кода. Кластеры CSS Elasticsearch поддерживают запросы данных и управление через Spring Data Elasticsearch (интегрированный компонент Elasticsearch в экосистеме Spring Boot). Этот компонент инкапсулирует официальные Elasticsearch Java API. Разработчики могут использовать Spring repository API или native query DSL для эффективного доступа к кластерам без работы с базовыми API. Для получения подробной информации о том, как использовать Spring Boot, см. Spring Boot.
В этом документе в качестве примера используется Spring Boot 2.5.5. Соответствующая версия Spring Data Elasticsearch — 4.2.x, а версия целевого кластера Elasticsearch — 7.10.2.
В этом документе в качестве примера используется Spring Boot 2.5.5. Соответствующая версия Spring Data Elasticsearch — 4.2.x, а версия целевого кластера Elasticsearch — 7.10.2.
<parent><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-parent</artifactId><version>2.5.5</version></parent><dependencies><dependency><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-web</artifactId></dependency><dependency><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-data-elasticsearch</artifactId></dependency><dependency><groupId>org.elasticsearch.client</groupId><artifactId>elasticsearch-rest-high-level-client</artifactId><version>7.10.2</version></dependency></dependencies>
Пример кода зависит от настроек режима безопасности целевого кластера Elasticsearch. Выберите соответствующий справочный документ в зависимости от сценария вашего сервиса.
Elasticsearch Cluster Security-Mode Settings | Whether to Load a Security Certificate | Details |
|---|---|---|
Non-security mode Security mode + HTTP | - | |
Security mode + HTTPS | No | Connecting to a Cluster That Uses HTTPS via Spring Boot (Without a Certificate) |
Security mode + HTTPS | Yes | Connecting to a Cluster That Uses HTTPS via Spring Boot (With a Certificate) |
Ниже приведены шаги по использованию Spring Boot для подключения к кластеру Elasticsearch в режиме без безопасности; либо к кластеру в режиме безопасности, использующему HTTP вместо HTTPS.
1234elasticsearch.url=host1:9200,host2:9200// You do not need to configure the following two lines for a non-security cluster.elasticsearch.username=usernameelasticsearch.password=password
Параметр | Описание |
|---|---|
host | Адрес для доступа к кластеру. |
username | Имя пользователя для доступа к кластеру. |
password | Пароль пользователя. |
123456789101112131415161718192021222324252627282930313233343536373839404142434445package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;// There is no need to set the following two parameters for a non-security cluster.@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl))// For a non-security cluster, there is no need to configure withBasicAuth..withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}}
Ниже приведены шаги по использованию Spring Boot для подключения к кластеру Elasticsearch в режиме безопасности + HTTPS без загрузки сертификата безопасности.
123elasticsearch.url=host1:9200,host2:9200elasticsearch.username=usernameelasticsearch.password=password
Параметр | Описание |
|---|---|
host | Адрес для доступа к кластеру. |
username | Имя пользователя для доступа к кластеру. |
password | Пароль пользователя. |
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;import java.security.KeyManagementException;import java.security.NoSuchAlgorithmException;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import javax.net.ssl.HostnameVerifier;import javax.net.ssl.SSLContext;import javax.net.ssl.SSLSession;import javax.net.ssl.TrustManager;import javax.net.ssl.X509TrustManager;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {SSLContext sc = null;try {sc = SSLContext.getInstance("SSL");sc.init(null, trustAllCerts, new SecureRandom());} catch (KeyManagementException | NoSuchAlgorithmException e) {e.printStackTrace();}final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl)).usingSsl(sc, new NullHostNameVerifier()).withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}public static TrustManager[] trustAllCerts = new TrustManager[] {new X509TrustManager() {@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return null;}}};public static class NullHostNameVerifier implements HostnameVerifier {@Overridepublic boolean verify(String arg0, SSLSession arg1) {return true;}}}
Ниже приведены шаги по использованию Spring Boot для подключения к кластеру Elasticsearch в режиме безопасности + HTTPS с загрузкой сертификата безопасности.
123elasticsearch.url=host1:9200,host2:9200elasticsearch.username=usernameelasticsearch.password=password
Параметр | Описание |
|---|---|
host | Адрес для доступа к кластеру. |
username | Имя пользователя для доступа к кластеру. |
password | Пароль пользователя. |
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;import java.io.File;import java.io.FileInputStream;import java.io.InputStream;import java.security.KeyStore;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import javax.net.ssl.HostnameVerifier;import javax.net.ssl.SSLContext;import javax.net.ssl.SSLSession;import javax.net.ssl.TrustManager;import javax.net.ssl.TrustManagerFactory;import javax.net.ssl.X509TrustManager;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {SSLContext sc = null;try {// certFilePath and certPassword are the path and password of the security certificate.TrustManager[] tm = {new MyX509TrustManager(certFilePath, certPassword)};sc = SSLContext.getInstance("SSL", "SunJSSE");sc.init(null, tm, new SecureRandom());} catch (Exception e) {e.printStackTrace();}final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl)).usingSsl(sc, new NullHostNameVerifier()).withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}public static class MyX509TrustManager implements X509TrustManager {X509TrustManager sunJSSEX509TrustManager;MyX509TrustManager(String certFilePath, String certPassword) throws Exception {File file = new File(certFilePath);if (!file.isFile()) {throw new Exception("Wrong Certification Path");}System.out.println("Loading KeyStore " + file + "...");InputStream in = new FileInputStream(file);KeyStore ks = KeyStore.getInstance("JKS");ks.load(in, certPassword.toCharArray());TrustManagerFactory tmf = TrustManagerFactory.getInstance("SunX509", "SunJSSE");tmf.init(ks);TrustManager[] tms = tmf.getTrustManagers();for (TrustManager tm : tms) {if (tm instanceof X509TrustManager) {sunJSSEX509TrustManager = (X509TrustManager) tm;return;}}throw new Exception("Couldn't initialize");}@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return new X509Certificate[0];}}public static class NullHostNameVerifier implements HostnameVerifier {@Overridepublic boolean verify(String arg0, SSLSession arg1) {return true;}}}
Чтобы получить доступ к кластеру Elasticsearch в режиме безопасности, использующему HTTPS, выполните следующие действия для получения сертификата безопасности, если он требуется, и загрузите его в клиент.
keytool -import -alias newname -keystore ./truststore.jks -file ./CloudSearchService.cer
keytool -import -alias newname -keystore .\truststore.jks -file .\CloudSearchService.cer
В приведённой выше команде newname указывает пользовательское имя сертификата.
После выполнения этой команды вам будет предложено задать пароль сертификата и подтвердить его. Надёжно сохраните пароль. Он будет использоваться для доступа к кластеру.