Cluster read-only block

A cluster-wide read-only block is enabled. Indexing and other write operations are rejected until the block is cleared.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity High
Scope Cluster
Domains cluster-health

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

cluster.blocks.read_only is true. The cluster accepts only read operations, but indexing and updates are blocked.

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

When cluster.blocks.read_only is true, Elasticsearch rejects write traffic cluster-wide. Searches and other reads can continue, but new and updated documents cannot be stored.

Operators often enable this block during maintenance so the cluster stays searchable without accepting writes. If the block is left on after maintenance, ingest pipelines fail and applications cannot index.

Clear the block when the work that required it is finished, and only after you confirm the cluster has enough disk and capacity to accept writes again.