June 22, 2012

Roaming ElasticSearch

I've been suffering from an unfortunate side effect of ElasticSearch's default configuration for months I finally got annoyed enough to diagnose and fix the problem.

By default, ElasticSearch binds to the first nonloopback interface. This is ordinarily what you want for a search server — you want to let other computers shove data into and rip data out of ElasticSearch. But if you're developing against a local ElasticSearch running on your laptop, that default works against you. The problem is that laptops are roaming mobile devices that connect to multiple different networks. Just in the past day I've connected to two home networks as well as my cellular hotspot. Each time I switched networks I basically broke ElasticSearch. The symptom is:

[Fri Jun 22 14:52:49 2012] Protocol: http, Server:
curl -XPOST '' -d ' ... data ... '

Error connecting to '' : Can't connect to (Operation timed out) (500)

The way I've been dealing with this is violently restarting ElasticSearch so it binds to a sensible interface again. But that's a pain in the ass in a few ways and totally snags whatever flow I'm in.

The way you actually fix this, I discovered, is by explicitly telling ElasticSearch that you want a loopback interface because you're not an ordinary production server. Edit your ElasticSearch config to include this line:


If you've installed ElasticSearch from homebrew, use brew info elasticsearch to find your config file. I'm sure if you're on a Debian-based system it'll be in /etc/elasticsearch/elasticsearch.yml.

Update: @karmiq suggested that I submit a pull request to add this default for network.host which is a great idea. So I did! And it landed!