# Add a node to elastic running on docker from another server

**URL:** <https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [September 26, 2021, 6:49am UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156 "2021-09-26T06:49:46Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![kakigadol](https://avatars.discourse-cdn.com/v4/letter/k/94ad74/32.png) [@kakigadol](https://discuss.elastic.co/u/kakigadol)\
**Post date:** [September 26, 2021, 6:49am UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/1 "2021-09-26T06:49:46Z")

</div>

I have an Elasticsearch 6.6 cluster with two nodes running on the first server using `docker-compose`  
I want to add another node running on a separate server to get more physical resources.

I configured everything the same as the first two nodes using `discovery.zen.ping.unicast.hosts` settings  
But when I started the node I got timeout error after initial discovery.  
The reason for the timeout is that the first two nodes bound IP addresses are the docker's addresses, which the new node obviously can't route to them (although the hosts set for discovery is the outer address of the host)

What is the solution for setting up docker Elasticsearch nodes on separated server then?  
The only quick and dirty solution I found is using preroute iptables rule to masquerade the inner subnets between the servers..

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 27, 2021, 12:24am UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/2 "2021-09-27T00:24:58Z")

</div>

Welcome to our community! 😃  
6.6 has been [EOL](https://www.elastic.co/support/eol) for over a year now, please upgrade ASAP.

You will need to expose the HTTP port outside the container, and then use the host IPs to connect the other nodes.

---

<div class="post-metadata">

**Author:** ![kakigadol](https://avatars.discourse-cdn.com/v4/letter/k/94ad74/32.png) [@kakigadol](https://discuss.elastic.co/u/kakigadol)\
**Post date:** [October 4, 2021, 12:40pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/3 "2021-10-04T12:40:29Z")

</div>

I upgraded my Elasticsearch to 6.8.18, and the issue consists

I exposed the port used for `transport.tcp.port`, and when I use the iptables hack it works but without it it still tries to connect to the container internal IP which is obviously unreachable for a container on another server

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 4, 2021, 12:59pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/4 "2021-10-04T12:59:15Z")

</div>

This is not an Elasticsearch issue and the version you are using has no influence, it is a connectivity issue related on how you are trying to start your cluster.

You need to make sure that your nodes can communicate with each other, that your nodes running on docker can resolve and connect to your other node outside docker and that this node can also resolve and connect to the docker nodes.

Maybe someone had a similar problem and can help, but this is an infrastructure issue, not an Elasticsearch one.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [October 4, 2021, 1:13pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/5 "2021-10-04T13:13:24Z")

</div>

I dunno, it sort of is an Elasticsearch issue, at least it's a discrepancy between Elasticsearch's network requirements and how the network is actually set up at present. I don't think the 6.8 reference manual makes it very clear, but the relevant section in the 7.15 docs also largely applies to 6.8:

> **[Networking | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-network.html#modules-network-binding-publishing)**

In particular (emphasis mine):

> Each Elasticsearch node has an address at which clients and other nodes can contact it, known as its _publish address_ . Each node has one publish address for its [...] transport interface [...] **Each node must be accessible at its transport publish address by all other nodes in its cluster.**

---

<div class="post-metadata">

**Author:** ![kakigadol](https://avatars.discourse-cdn.com/v4/letter/k/94ad74/32.png) [@kakigadol](https://discuss.elastic.co/u/kakigadol)\
**Post date:** [October 4, 2021, 2:23pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/6 "2021-10-04T14:23:18Z")

</div>

lets say for the following comment that the ip addresses of the two servers are 1.2.3.4 and 1.2.3.5.

My nodes _are_ accessible, using the host server's IP and published port (curling 1.2.3.4:9300 from 1.2.3.5 will return `this is not an HTTP port` as expected)

The problem is that the zen hosts set for one of 1.2.3.4's nodes is `discovery.zen.ping.unicast.hosts: "1.2.3.5:9300,1.2.3.5:9300"` (the ports are published through docker and the port is set with `transport.tcp.port=9300`)  
and the initial connection is made just fine, but then the connection to a node on the other server is failed due to timeout  
and when looking at the logs is says the other node ip is 172...3 (docker internal ip) and not 1.2.3.4  
I believe the node tells its address to the new node after the initial negotiation and then it gives the address set as **publish\_address**

I tried to change the publish address to 1.2.3.4, but obviously it didn't work because the container doesn't recognize this address  
and I also tried 0.0.0.0, but because the node listened on it it just used the container address again

And finally, as I said in the first post - if i masquerade the address using iptables (making the host thing 172... is 1.2.3.4 and the other way around on the other server) it works fine

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [October 4, 2021, 2:31pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/7 "2021-10-04T14:31:54Z")

</div>

Right, this is addressed by the docs quoted in my previous message though:

> [@DavidTurner](#):
>
> Each node must be accessible at its transport publish address by all other nodes in its cluster.

You've got to set your network up so that this is the case.

---

<div class="post-metadata">

**Author:** ![kakigadol](https://avatars.discourse-cdn.com/v4/letter/k/94ad74/32.png) [@kakigadol](https://discuss.elastic.co/u/kakigadol)\
**Post date:** [October 4, 2021, 2:43pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/8 "2021-10-04T14:43:06Z")

</div>

First of all thank you all for your replies!

Secondly I get the problem now, I assume my setup (few docker nodes and two separate servers) isn't really supported by elastic  
And I guess the solution is to set up a single node, running natively, on each server. Or running docker nodes on some kind of cluster such as k8s. Am I right?

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [October 4, 2021, 2:51pm UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/9 "2021-10-04T14:51:28Z")

</div>

The simplest approach is just to use a `host` network rather than a `bridge` one, but you can get fancy with k8s if you want. Note that the [docs on `bridge` networking](https://docs.docker.com/network/bridge/) say this:

> Bridge networks apply to containers running on the **same** Docker daemon host. For communication among containers running on different Docker daemon hosts, you can either manage routing at the OS level, or you can use an [overlay network](https://docs.docker.com/network/overlay/).

---

<div class="post-metadata">

**Author:** ![kakigadol](https://avatars.discourse-cdn.com/v4/letter/k/94ad74/32.png) [@kakigadol](https://discuss.elastic.co/u/kakigadol)\
**Post date:** [October 10, 2021, 11:38am UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/10 "2021-10-10T11:38:48Z")

</div>

I will try this option and report here, thanks a lot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2021, 11:38am UTC](https://discuss.elastic.co/t/add-a-node-to-elastic-running-on-docker-from-another-server/285156/11 "2021-11-07T11:38:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
