Cluster read-only block
A cluster-wide read-only block is enabled. Indexing and other write operations are rejected until the block is cleared.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | High |
| Scope | Cluster |
| Domains | cluster-health |
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
cluster.blocks.read_only is true. The cluster accepts only read operations, but indexing and updates are blocked.
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Clear cluster read-only block
Condition: Shown when enough disk space.
Clear the cluster read-only block so indexing can resume. Use the action below, or set cluster.blocks.read_only to null in cluster settings.
PUT _cluster/settings
{
"transient": {
"cluster.blocks.read_only": null
},
"persistent": {
"cluster.blocks.read_only": null
}
}
Requires the manage cluster privilege. Requires Elasticsearch 8.0.0 or later. This action changes cluster or index configuration.
Free disk before clearing read-only block
Condition: Shown when not enough disk space.
Disk space is critically low. Increase disk space or delete old indices before you clear the read-only block. Deleting indices is permanent; confirm backups first.
When cluster.blocks.read_only is true, Elasticsearch rejects write traffic cluster-wide. Searches and other reads can continue, but new and updated documents cannot be stored.
Operators often enable this block during maintenance so the cluster stays searchable without accepting writes. If the block is left on after maintenance, ingest pipelines fail and applications cannot index.
Clear the block when the work that required it is finished, and only after you confirm the cluster has enough disk and capacity to accept writes again.