# Apikeys and elastic cloud

**URL:** <https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856>\
**Category:** Beats\
**Tags:** elastic-stack-security, metricbeat, filebeat\
**Created:** [April 12, 2021, 9:13am UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856 "2021-04-12T09:13:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![alfredo.deluca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfredo.deluca/32/95381_2.png) [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Post date:** [April 12, 2021, 9:13am UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/1 "2021-04-12T09:13:35Z")

</div>

Hi all.  
We use elastic cloud 7.12. We have also metricbeat and filebeat running on node and k8s cluster and for their configurations I use cloud.id and cloud.auth has ta user (beats\_setup) with those privileges.  
Now I'd like to change the cloud.auth with the apikeys.  
How can I do that?  
Should I create an apikey for the beats\_setup user then simply replace cloud.auth the the apikeys entry?  
Is that correct?  
Cheers

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [April 13, 2021, 11:16pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/2 "2021-04-13T23:16:16Z")

</div>

There should be some steps here that should be straight forward to follow, let me know if its working out 🙂

> **[Grant access using API keys | Filebeat Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/beats-api-keys.html)**

There is an example API call you can run from the kibana dev tools console to create the API key, instead of creating the key for the user, you are creating it for the role.

After that, as in the documentation, you can use the `api_key` instead of your `cloud.id` and `cloud.auth`:

```
    output.elasticsearch:
      api_key: TiNAGG4BaaMdaH1tRfuU:KnR6yE41RrSowb0kQ0HWoA

```

though you would still need to specify the hostname, in the cloud UI you can click on the specific cluster you want to connect to, and choose "Copy Endpoint" for Elasticsearch to get the endpoint if you want to.

---

<div class="post-metadata">

**Author:** ![alfredo.deluca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfredo.deluca/32/95381_2.png) [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Post date:** [April 14, 2021, 10:57am UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/3 "2021-04-14T10:57:23Z")

</div>

Thanks heaps Marius.  
I will give it a try but do you think I can still use [cloud.id](http://cloud.id) and then under output.elasticsearch the apikeys?  
I find [cloud.id](http://cloud.id) a bit more secure then the hosts, which is the endpoint for elastic!

Cheers

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [April 14, 2021, 11:16am UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/4 "2021-04-14T11:16:37Z")

</div>

I don't remember that out of my head unfortunately, in the documentation it states that:

cloud.id overwrites output.elasticsearch.hosts  
cloud.auth overwrites output.elasticsearch.username and password

It does not say that you have to use both at the same time, but I honestly did not test that, as I usually use one or the other, so give it a try.

If using cloud.id + api key does not work, and you do not feel its secure to hardcode the ES endpoint, you could always store the elasticsearch endpoint in a environment variable, and use the environment variable in the config, similar to how its often done with passwords and api\_keys as well.

Hope this helps! 🙂

---

<div class="post-metadata">

**Author:** ![alfredo.deluca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfredo.deluca/32/95381_2.png) [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Post date:** [April 14, 2021, 12:13pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/5 "2021-04-14T12:13:26Z")

</div>

Ok thanks. I ve been using [clou.id](http://clou.id) and cloud.auth for a while now but I was wondering if I can user [cloud.id](http://cloud.id) and then elasticsearch.host with apikey.

Do you think I can use only apikeys without [cloud.id](http://cloud.id) and cloud.auth?

Cheers

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [April 14, 2021, 12:18pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/6 "2021-04-14T12:18:23Z")

</div>

That won't be possible unfortunately, but you could try to use cloud.id and apikey, or you will have to use apikey and hosts.  
The API key does not include the destination in any way, so it will have to get the host from either cloud.id or elasticsearch.host, though I have yet to try to use cloud.id without cloud.auth, so you would have to just give it a try 🙂

For example:

```
cloud.id: CLOUDID
output.elasticsearch.api_key: APIKEY
```

---

<div class="post-metadata">

**Author:** ![alfredo.deluca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfredo.deluca/32/95381_2.png) [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Post date:** [April 14, 2021, 12:30pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/7 "2021-04-14T12:30:42Z")

</div>

perfect. Thanks  
I will give it a try soon and let you know

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2021, 2:31pm UTC](https://discuss.elastic.co/t/apikeys-and-elastic-cloud/269856/8 "2021-05-12T14:31:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
