首先,在ElasticSearch的访问策略中找到明确拒绝访问的规则,并将其修改为允许访问或删除该规则。例如,以下访问策略明确拒绝所有IP地址访问ElasticSearch:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Principal": "*",
"Action": "*",
"Resource": "arn:aws:es:us-west-2:123456789012:domain/my-domain/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "192.0.2.0/24"
}
}
}
]
}
可以将其改为允许该IP地址访问,如下所示:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "*",
"Resource": "arn:aws:es:us-west-2:123456789012:domain/my-domain/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "192.0.2.0/24"
}
}
}
]
}
或者也可以删除该规则,如下所示:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "*",
"Resource": "arn:aws:es:us-west-2:123456789012:domain/my-domain/*"
}
]
}
注意:在执行任何更改之前,请确保您了解本次更改的风险,并验证访问策略的正确性。