# After creating Elasticsearch, and then changing the yaml file, apply fails

**URL:** <https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 25, 2021, 4:55am UTC](https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433 "2021-02-25T04:55:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![haipeng.zhao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/haipeng.zhao/32/84582_2.png) [@haipeng.zhao](https://discuss.elastic.co/u/haipeng.zhao)\
**Post date:** [February 25, 2021, 4:55am UTC](https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433/1 "2021-02-25T04:55:37Z")

</div>

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1

kind: Elasticsearch

metadata:

  name: aimee  

spec:

  version: 7.10.1  

  securityContext:

    fsGroup: 1000

    runAsUser: 1000

  http:

      service:

        spec:

          type: NodePort

          ports:

            - name: http

              nodePort: 30655

              port: 9200

              protocol: TCP

              targetPort: 9200

  nodeSets:

  - name: master-node    

    count: 3   

    config:

      node.master: true   

      node.data: false

      xpack.security.transport.ssl.certificate_authorities:

      - /usr/share/elasticsearch/config/other/two.ca.crt

      path.repo: "/data/index/buckup"     

    podTemplate:

      spec:

        initContainers:

        - name: sysctl   

          securityContext:

            privileged: true

          command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144']   

        containers:

        - name: elasticsearch

          volumeMounts:

          - mountPath: "/data/index/backup"

            name: backup

          - mountPath: /usr/share/elasticsearch/config/other

            name: remote-certs

        volumes:

        - name: backup

          persistentVolumeClaim:

            claimName: backup    

        - name: elasticsearch-data

          emptyDir: {}

        - name: remote-certs

          secret:

            secretName: remote-certs

          env:

          - name: ES_JAVA_OPTS    

            value: -Xms3g -Xmx3g  

          - name: READINESS_PROBE_TIMEOUT

            value: "30"

          resources:

            requests:

              cpu: 3

              memory: 3Gi

            limits:

              cpu: 4

              memory: 6Gi

  - name: data-node-hot

    count: 3

    config:

      node.master: false  

      node.data: true  

      node.attr.date: hot   

    podTemplate:

      spec:

        initContainers:

        - name: sysctl

          securityContext:

            privileged: true

          command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144']

        containers:

        - name: elasticsearch

          env:

          - name: ES_JAVA_OPTS

            value: -Xms10g -Xmx10g

          - name: READINESS_PROBE_TIMEOUT

            value: "30"

          resources:

            requests:

              cpu: 2

              memory: 16Gi

            limits:

              cpu: 5

              memory: 20Gi

        volumes:

        - name: elasticsearch-data

          emptyDir: {}

```

I defined the master node and mounted pvc and secret. When I used this yaml file to create a cluster for the first time, it was okay. Then I changed the yaml parameters, such as modifying the cpu, and then applied the yaml file, which prompted me to report an error.

The error report is as follows

Warning: kubectl apply should be used on resource created by either kubectl create --save-config or kubectl apply  
Error from server ([Elasticsearch.elasticsearch.k8s.elastic.co](http://Elasticsearch.elasticsearch.k8s.elastic.co) "aimee" is invalid: env: Invalid value: "env": env field found in the [kubectl.kubernetes.io/last-applied-configuration](http://kubectl.kubernetes.io/last-applied-configuration) annotation is unknown. This is often due to incorrect indentation in the manifest.): error when applying patch:  
{"metadata":{"annotations":{"[kubectl.kubernetes.io/last-applied-configuration":"{"apiVersion":"elasticsearch.k8s.elastic.co/v1","kind":"Elasticsearch","metadata":{"annotations":{},"name":"aimee","namespace":"default"},"spec":{"http":{"service":{"spec":{"ports":[{"name":"http","nodePort":30655,"port":9200,"protocol":"TCP","targetPort":9200}],"type":"NodePort"}}},"nodeSets":[{"config":{"node.data":false,"node.master":true,"path.repo":"/data/index/buckup","xpack.security.transport.ssl.certificate\_authorities":["/usr/share/elasticsearch/config/other/two.ca.crt"]},"count":3,"name":"master-node","podTemplate":{"spec":{"containers":[{"name":"elasticsearch","volumeMounts":[{"mountPath":"/data/index/backup","name":"backup"},{"mountPath":"/usr/share/elasticsearch/config/other","name":"remote-certs"}]}],"initContainers":[{"command":["sh","-c","sysctl](http://kubectl.kubernetes.io/last-applied-configuration%22:%22%7B%22apiVersion%22:%22elasticsearch.k8s.elastic.co/v1%22,%22kind%22:%22Elasticsearch%22,%22metadata%22:%7B%22annotations%22:%7B%7D,%22name%22:%22aimee%22,%22namespace%22:%22default%22%7D,%22spec%22:%7B%22http%22:%7B%22service%22:%7B%22spec%22:%7B%22ports%22:%5B%7B%22name%22:%22http%22,%22nodePort%22:30655,%22port%22:9200,%22protocol%22:%22TCP%22,%22targetPort%22:9200%7D%5D,%22type%22:%22NodePort%22%7D%7D%7D,%22nodeSets%22:%5B%7B%22config%22:%7B%22node.data%22:false,%22node.master%22:true,%22path.repo%22:%22/data/index/buckup%22,%22xpack.security.transport.ssl.certificate_authorities%22:%5B%22/usr/share/elasticsearch/config/other/two.ca.crt%22%5D%7D,%22count%22:3,%22name%22:%22master-node%22,%22podTemplate%22:%7B%22spec%22:%7B%22containers%22:%5B%7B%22name%22:%22elasticsearch%22,%22volumeMounts%22:%5B%7B%22mountPath%22:%22/data/index/backup%22,%22name%22:%22backup%22%7D,%7B%22mountPath%22:%22/usr/share/elasticsearch/config/other%22,%22name%22:%22remote-certs%22%7D%5D%7D%5D,%22initContainers%22:%5B%7B%22command%22:%5B%22sh%22,%22-c%22,%22sysctl) -w vm.max\_map\_count=262144"],"name":"sysctl","securityContext":{"privileged":true}}],"volumes":[{"name":"backup","persistentVolumeClaim":{"claimName":"backup"}},{"emptyDir":{},"name":"elasticsearch-data"},{"env":[{"name":"ES\_JAVA\_OPTS","value":"-Xms3g -Xmx3g"},{"name":"READINESS\_PROBE\_TIMEOUT","value":"30"}],"name":"remote-certs","resources":{"limits":{"cpu":4,"memory":"6Gi"},"requests":{"cpu":3,"memory":"3Gi"}},"secret":{"secretName":"remote-certs"}}]}}},{"config":{"node.attr.date":"hot","node.data":true,"node.master":false},"count":3,"name":"data-node-hot","podTemplate":{"spec":{"containers":[{"env":[{"name":"ES\_JAVA\_OPTS","value":"-Xms10g -Xmx10g"},{"name":"READINESS\_PROBE\_TIMEOUT","value":"30"}],"name":"elasticsearch","resources":{"limits":{"cpu":5,"memory":"20Gi"},"requests":{"cpu":2,"memory":"16Gi"}}}],"initContainers":[{"command":["sh","-c","sysctl -w vm.max\_map\_count=262144"],"name":"sysctl","securityContext":{"privileged":true}}],"volumes":[{"emptyDir":{},"name":"elasticsearch-data"}]}}}],"securityContext":{"fsGroup":1000,"runAsUser":1000},"version":"7.10.1"}}\n"}},"spec":{"nodeSets":[{"config":{"node.data":false,"node.master":true,"path.repo":"/data/index/buckup","xpack.security.transport.ssl.certificate\_authorities":["/usr/share/elasticsearch/config/other/two.ca.crt"]},"count":3,"name":"master-node","podTemplate":{"spec":{"containers":[{"name":"elasticsearch","volumeMounts":[{"mountPath":"/data/index/backup","name":"backup"},{"mountPath":"/usr/share/elasticsearch/config/other","name":"remote-certs"}]}],"initContainers":[{"command":["sh","-c","sysctl -w vm.max\_map\_count=262144"],"name":"sysctl","securityContext":{"privileged":true}}],"volumes":[{"name":"backup","persistentVolumeClaim":{"claimName":"backup"}},{"emptyDir":{},"name":"elasticsearch-data"},{"env":[{"name":"ES\_JAVA\_OPTS","value":"-Xms3g -Xmx3g"},{"name":"READINESS\_PROBE\_TIMEOUT","value":"30"}],"name":"remote-certs","resources":{"limits":{"cpu":4,"memory":"6Gi"},"requests":{"cpu":3,"memory":"3Gi"}},"secret":{"secretName":"remote-certs"}}]}}},{"config":{"node.attr.date":"hot","node.data":true,"node.master":false},"count":3,"name":"data-node-hot","podTemplate":{"spec":{"containers":[{"env":[{"name":"ES\_JAVA\_OPTS","value":"-Xms10g -Xmx10g"},{"name":"READINESS\_PROBE\_TIMEOUT","value":"30"}],"name":"elasticsearch","resources":{"limits":{"cpu":5,"memory":"20Gi"},"requests":{"cpu":2,"memory":"16Gi"}}}],"initContainers":[{"command":["sh","-c","sysctl -w vm.max\_map\_count=262144"],"name":"sysctl","securityContext":{"privileged":true}}],"volumes":[{"emptyDir":{},"name":"elasticsearch-data"}]}}}],"securityContext":{"fsGroup":1000,"runAsUser":1000}}}  
to:  
Resource: "[elasticsearch.k8s.elastic.co/v1](http://elasticsearch.k8s.elastic.co/v1), Resource=elasticsearches", GroupVersionKind: "[elasticsearch.k8s.elastic.co/v1](http://elasticsearch.k8s.elastic.co/v1), Kind=Elasticsearch"  
Name: "aimee", Namespace: "default"  
for: "elasticsearch.yaml": admission webhook "[elastic-es-validation-v1.k8s.elastic.co](http://elastic-es-validation-v1.k8s.elastic.co)" denied the request: [Elasticsearch.elasticsearch.k8s.elastic.co](http://Elasticsearch.elasticsearch.k8s.elastic.co) "aimee" is invalid: env: Invalid value: "env": env field found in the [kubectl.kubernetes.io/last-applied-configuration](http://kubectl.kubernetes.io/last-applied-configuration) annotation is unknown. This is often due to incorrect indentation in the manifest.

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [February 25, 2021, 6:50am UTC](https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433/2 "2021-02-25T06:50:58Z")

</div>

Hi,  
There are several issues with the manifest your provided:

- As suggested by the error message `env` should be in the container specification, not in the list of `volumes`.

- There is the same problem for the `resources` definition.

- The `securityContext` must be either at the Pod or Container level.

Hope it helps.

---

<div class="post-metadata">

**Author:** ![haipeng.zhao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/haipeng.zhao/32/84582_2.png) [@haipeng.zhao](https://discuss.elastic.co/u/haipeng.zhao)\
**Post date:** [February 25, 2021, 6:54am UTC](https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433/3 "2021-02-25T06:54:20Z")

</div>

Thank you for your answer, indeed this question has been revised~

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2021, 6:54am UTC](https://discuss.elastic.co/t/after-creating-elasticsearch-and-then-changing-the-yaml-file-apply-fails/265433/4 "2021-03-25T06:54:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
