# AWS S3 repo configuration

**URL:** <https://discuss.elastic.co/t/aws-s3-repo-configuration/332868>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** snapshot-and-restore\
**Created:** [May 9, 2023, 6:14am UTC](https://discuss.elastic.co/t/aws-s3-repo-configuration/332868 "2023-05-09T06:14:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dj\_kill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dj_kill/32/114743_2.png) [@dj\_kill](https://discuss.elastic.co/u/dj_kill)\
**Post date:** [May 9, 2023, 6:14am UTC](https://discuss.elastic.co/t/aws-s3-repo-configuration/332868/1 "2023-05-09T06:14:48Z")

</div>

Hello.

I'm using Elasticsearch (ECK) Operator 2.7 in OpenShift environment.  
All components are on 8.6.2 version.

Configuration for the S3 is pretty simple:

```auto
spec:
  version: 8.6.2
  secureSettings:
    - secretName: credentials
      entries:
        - key: AWS_SECRET_ACCESS_KEY
          path: s3.client.default.access_key
        - key: AWS_ACCESS_KEY_ID
          path: s3.client.default.secret_key

```

and

```auto
  nodeSets:
      config:
        s3.client.default.endpoint: "https://s3.eu-west-1.amazonaws.com"
        s3.client.default.region: "eu-west-1"

```

I tried with region and endpoint and without.  
IAM user with provided key has policy attached as it is described [here.](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-snapshots.html#k8s-iam-service-accounts).

But if I try to verify repository I've got `AuthorizationHeaderMalformed` error.

```auto
{
  "name": "ResponseError",
  "meta": {
    "body": {
      "error": {
        "root_cause": [
          {
            "type": "repository_verification_exception",
            "reason": "[platform-backups] path is not accessible on master node"
          }
        ],
        "type": "repository_verification_exception",
        "reason": "[platform-backups] path is not accessible on master node",
        "caused_by": {
          "type": "i_o_exception",
          "reason": "Unable to upload object [tests-Sbnv9P08StSsQ9EaD59_uQ/master.dat] using a single upload",
          "caused_by": {
            "type": "amazon_s3_exception",
            "reason": "amazon_s3_exception: /YYYYMMDD/REGION/SERVICE/aws4_request\". (Service: Amazon S3; Status Code: 400; Error Code: AuthorizationHeaderMalformed; Request ID: ....; S3 Extended Request ID: ....; Proxy: null)"
          }
        }
      },
      "status": 500
    },
    "statusCode": 500,
    "headers": {
      "x-opaque-id": "998ea841-e17e-46fe-b9bc-2b6839485374;kibana:application:management:",
      "x-elastic-product": "Elasticsearch",
      "content-type": "application/json;charset=utf-8",
      "content-length": "743"
    },
    "meta": {
      "context": null,
      "request": {
        "params": {
          "method": "POST",
          "path": "/_snapshot/platform-backups/_verify",
          "querystring": "",
          "headers": {
            "user-agent": "Kibana/8.6.2",
            "x-elastic-product-origin": "kibana",
            "authorization": "Basic ....",
            "x-opaque-id": "998ea841-e17e-46fe-b9bc-2b6839485374;kibana:application:management:",
            "x-elastic-client-meta": "es=8.4.0p,js=16.18.1,t=8.2.0,hc=16.18.1",
            "accept": "application/vnd.elasticsearch+json; compatible-with=8,text/plain"
          }
        },
        "options": {
          "opaqueId": "998ea841-e17e-46fe-b9bc-2b6839485374;kibana:application:management:",
          "headers": {
            "x-elastic-product-origin": "kibana",
            "user-agent": "Kibana/8.6.2",
            "authorization": "Basic ....",
            "x-opaque-id": "998ea841-e17e-46fe-b9bc-2b6839485374",
            "x-elastic-client-meta": "es=8.4.0p,js=16.18.1,t=8.2.0,hc=16.18.1"
          }
        },
        "id": 1
      },
      "name": "elasticsearch-js",
      "connection": {
        "url": "https://elasticsearch-es-http.services.svc:9200/",
        "id": "https://elasticsearch-es-http.services.svc:9200/",
        "headers": {},
        "status": "alive"
      },
      "attempts": 0,
      "aborted": false
    },
    "warnings": null
  }
}

```

Any advice how I can debug this or what can be wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2023, 6:15am UTC](https://discuss.elastic.co/t/aws-s3-repo-configuration/332868/2 "2023-06-06T06:15:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
