Closed dalamudx closed 1 month ago
从官方社区找到的,手动修改
/usr/share/opensearch/plugins/opensearch-security/tools/securityadmin.sh \
-icl \
-cacert /usr/share/opensearch/config/root-ca.pem \
-cert /usr/share/opensearch/config/kirk.pem \
-key /usr/share/opensearch/config/kirk-key.pem \
-r \
-cd current-config
./plugins/opensearch-security/tools/hash.sh -p $NEW_PASSWORD
修改current-config/internalusers$DATE.yml里面admin用户的hash,提交变更
/usr/share/opensearch/plugins/opensearch-security/tools/securityadmin.sh \
-icl \
-t internalusers \
-f current-config/internal_users_$DATE.yml \
-cacert /usr/share/opensearch/config/root-ca.pem \
-cert /usr/share/opensearch/config/kirk.pem \
-key /usr/share/opensearch/config/kirk-key.pem
另外定时任务看起来是正常获取到凭据的,所以密码与secret配置中密码保持一致,不然任务会报错
ks版本:kubesphere/ks-installer:v3.4.1-patch.0 kubernetes版本:
测试发现,虽然ks根据cluster-configuration.yaml设置创建了opensearch-credentials,但opensearch使用的还是默认用户名密码