Working directly with Elasticsearch's underlying APIs can increase development complexity, such as additional code maintenance tasks. CSS Elasticsearch clusters support data query and management through Spring Data Elasticsearch (an integrated Elasticsearch component in the Spring Boot ecosystem). This component encapsulates official Elasticsearch Java APIs. Developers can use the Spring repository API or native query DSL to efficiently access clusters without working with underlying APIs. For details about how to use Spring Boot, see Spring Boot.
In this document, Spring Boot 2.5.5 is used as an example. The corresponding Spring Data Elasticsearch version is 4.2.x, and the target Elasticsearch cluster version is 7.10.2.
In this document, Spring Boot 2.5.5 is used as an example. The corresponding Spring Data Elasticsearch version is 4.2.x, and the target Elasticsearch cluster version is 7.10.2.
<parent><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-parent</artifactId><version>2.5.5</version></parent><dependencies><dependency><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-web</artifactId></dependency><dependency><groupId>org.springframework.boot</groupId><artifactId>spring-boot-starter-data-elasticsearch</artifactId></dependency><dependency><groupId>org.elasticsearch.client</groupId><artifactId>elasticsearch-rest-high-level-client</artifactId><version>7.10.2</version></dependency></dependencies>
The sample code varies depending on the security mode settings of the target Elasticsearch cluster. Select the right reference document based on your service scenario.
Elasticsearch Cluster Security-Mode Settings | Whether to Load a Security Certificate | Details |
|---|---|---|
Non-security mode Security mode + HTTP | - | |
Security mode + HTTPS | No | Connecting to a Cluster That Uses HTTPS via Spring Boot (Without a Certificate) |
Security mode + HTTPS | Yes | Connecting to a Cluster That Uses HTTPS via Spring Boot (With a Certificate) |
The following are steps for using Spring Boot to connect to a non-security mode Elasticsearch cluster; or a security-mode Elasticsearch cluster that uses HTTP instead of HTTPS.
1234elasticsearch.url=host1:9200,host2:9200// You do not need to configure the following two lines for a non-security cluster.elasticsearch.username=usernameelasticsearch.password=password
Parameter | Description |
|---|---|
host | Address for accessing the cluster. |
username | Username for accessing the cluster. |
password | Password of the user. |
123456789101112131415161718192021222324252627282930313233343536373839404142434445package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;// There is no need to set the following two parameters for a non-security cluster.@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl))// For a non-security cluster, there is no need to configure withBasicAuth..withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}}
The following are steps for using Spring Boot to connect to a security-mode + HTTPS Elasticsearch cluster without loading a security certificate.
123elasticsearch.url=host1:9200,host2:9200elasticsearch.username=usernameelasticsearch.password=password
Parameter | Description |
|---|---|
host | Address for accessing the cluster. |
username | Username for accessing the cluster. |
password | Password of the user. |
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;import java.security.KeyManagementException;import java.security.NoSuchAlgorithmException;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import javax.net.ssl.HostnameVerifier;import javax.net.ssl.SSLContext;import javax.net.ssl.SSLSession;import javax.net.ssl.TrustManager;import javax.net.ssl.X509TrustManager;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {SSLContext sc = null;try {sc = SSLContext.getInstance("SSL");sc.init(null, trustAllCerts, new SecureRandom());} catch (KeyManagementException | NoSuchAlgorithmException e) {e.printStackTrace();}final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl)).usingSsl(sc, new NullHostNameVerifier()).withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}public static TrustManager[] trustAllCerts = new TrustManager[] {new X509TrustManager() {@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return null;}}};public static class NullHostNameVerifier implements HostnameVerifier {@Overridepublic boolean verify(String arg0, SSLSession arg1) {return true;}}}
The following are steps for using Spring Boot to connect to a security-mode + HTTPS Elasticsearch cluster while loading a security certificate.
123elasticsearch.url=host1:9200,host2:9200elasticsearch.username=usernameelasticsearch.password=password
Parameter | Description |
|---|---|
host | Address for accessing the cluster. |
username | Username for accessing the cluster. |
password | Password of the user. |
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899package com.xxx.configuration;import org.elasticsearch.client.RestHighLevelClient;import org.springframework.beans.factory.annotation.Value;import org.springframework.context.annotation.Bean;import org.springframework.context.annotation.ComponentScan;import org.springframework.context.annotation.Configuration;import org.springframework.data.elasticsearch.client.ClientConfiguration;import org.springframework.data.elasticsearch.client.RestClients;import org.springframework.data.elasticsearch.config.AbstractElasticsearchConfiguration;import org.springframework.data.elasticsearch.repository.config.EnableElasticsearchRepositories;import java.io.File;import java.io.FileInputStream;import java.io.InputStream;import java.security.KeyStore;import java.security.SecureRandom;import java.security.cert.CertificateException;import java.security.cert.X509Certificate;import javax.net.ssl.HostnameVerifier;import javax.net.ssl.SSLContext;import javax.net.ssl.SSLSession;import javax.net.ssl.TrustManager;import javax.net.ssl.TrustManagerFactory;import javax.net.ssl.X509TrustManager;@Configuration// com.xxx.repository is the repository directory, which is defined by extends org.springframework.data.elasticsearch.repository.ElasticsearchRepository.@EnableElasticsearchRepositories(basePackages = "com.xxx.repository")// com.xxx indicates the project directory, for example, com.company.project.@ComponentScan(basePackages = "com.xxx")public class Config extends AbstractElasticsearchConfiguration {@Value("${elasticsearch.url}")public String elasticsearchUrl;@Value("${elasticsearch.username}")public String elasticsearchUsername;@Value("${elasticsearch.password}")public String elasticsearchPassword;@Override@Beanpublic RestHighLevelClient elasticsearchClient() {SSLContext sc = null;try {// certFilePath and certPassword are the path and password of the security certificate.TrustManager[] tm = {new MyX509TrustManager(certFilePath, certPassword)};sc = SSLContext.getInstance("SSL", "SunJSSE");sc.init(null, tm, new SecureRandom());} catch (Exception e) {e.printStackTrace();}final ClientConfiguration clientConfiguration = ClientConfiguration.builder().connectedTo(StringHostParse(elasticsearchUrl)).usingSsl(sc, new NullHostNameVerifier()).withBasicAuth(elasticsearchUsername, elasticsearchPassword).build();return RestClients.create(clientConfiguration).rest();}private String[] StringHostParse(String hostAndPorts) {return hostAndPorts.split(",");}public static class MyX509TrustManager implements X509TrustManager {X509TrustManager sunJSSEX509TrustManager;MyX509TrustManager(String certFilePath, String certPassword) throws Exception {File file = new File(certFilePath);if (!file.isFile()) {throw new Exception("Wrong Certification Path");}System.out.println("Loading KeyStore " + file + "...");InputStream in = new FileInputStream(file);KeyStore ks = KeyStore.getInstance("JKS");ks.load(in, certPassword.toCharArray());TrustManagerFactory tmf = TrustManagerFactory.getInstance("SunX509", "SunJSSE");tmf.init(ks);TrustManager[] tms = tmf.getTrustManagers();for (TrustManager tm : tms) {if (tm instanceof X509TrustManager) {sunJSSEX509TrustManager = (X509TrustManager) tm;return;}}throw new Exception("Couldn't initialize");}@Overridepublic void checkClientTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic void checkServerTrusted(X509Certificate[] chain, String authType) throws CertificateException {}@Overridepublic X509Certificate[] getAcceptedIssuers() {return new X509Certificate[0];}}public static class NullHostNameVerifier implements HostnameVerifier {@Overridepublic boolean verify(String arg0, SSLSession arg1) {return true;}}}
To access a security-mode Elasticsearch cluster that uses HTTPS, perform the following steps to obtain the security certificate if it is required, and upload it to the client.
keytool -import -alias newname -keystore ./truststore.jks -file ./CloudSearchService.cer
keytool -import -alias newname -keystore .\truststore.jks -file .\CloudSearchService.cer
In the preceding command, newname indicates the user-defined certificate name.
After this command is executed, you will be prompted to set the certificate password and confirm the password. Securely store the password. It will be used for accessing the cluster.