# Basic security without xpack

**URL:** <https://discuss.elastic.co/t/basic-security-without-xpack/198349>\
**Category:** Elasticsearch\
**Created:** [September 6, 2019, 5:52am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349 "2019-09-06T05:52:06Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [September 6, 2019, 5:52am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/1 "2019-09-06T05:52:06Z")

</div>

Is there an option to have login/password connectivity(tls is optional) to elasticsearch and authentication enabled on kibana without xpack installation?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 6, 2019, 6:05am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/2 "2019-09-06T06:05:13Z")

</div>

Do you have any concern using the default distribution of elasticsearch which contains the basic license with this security feature you are looking for?

---

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [September 6, 2019, 6:51am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/3 "2019-09-06T06:51:09Z")

</div>

I use the following chart [https://hub.helm.sh/charts/elastic/elasticsearch](https://hub.helm.sh/charts/elastic/elasticsearch) and tried to use the image:  
`docker.elastic.co/elasticsearch/elasticsearch:7.3.0` but xpack isn't enabled by default there and if I enable xpack, I have an issue described [Elasticsearch with xpack.security.enabled throws Cluster is not yet ready](https://discuss.elastic.co/t/elasticsearch-with-xpack-security-enabled-throws-cluster-is-not-yet-ready/198260/5)  
Can you please suggest which elasticsearch versions include xpack for basic license?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 6, 2019, 7:04am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/4 "2019-09-06T07:04:26Z")

</div>

Here is how I'm setting that with docker compose ( `docker-compose.yml`):

```auto
---
version: '3'
services:

  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:$ELASTIC_VERSION
    environment:
      - bootstrap.memory_lock=true
      - discovery.type=single-node
      - cluster.name=elasticsearch
      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"
      - cluster.routing.allocation.disk.threshold_enabled=false
      - ELASTIC_PASSWORD=$ELASTIC_PASSWORD
      - xpack.security.enabled=$ELASTIC_SECURITY
    ulimits:
      memlock:
        soft: -1
        hard: -1
    ports:
      - 9200:9200
      - 9300:9300
    networks: ['stack']

  kibana:
    image: docker.elastic.co/kibana/kibana:$ELASTIC_VERSION
    environment:
      - ELASTICSEARCH_USERNAME=elastic
      - ELASTICSEARCH_PASSWORD=$ELASTIC_PASSWORD
    ports: ['5601:5601']
    networks: ['stack']
    links: ['elasticsearch']
    depends_on: ['elasticsearch']

networks:
  stack: {}

```

`.env` file is:

```auto
ELASTIC_VERSION=7.2.0
ELASTIC_SECURITY=true
ELASTIC_PASSWORD=changeme

```

It has security enabled.

---

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [September 6, 2019, 10:56am UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/5 "2019-09-06T10:56:43Z")

</div>

I used only these parameters in different section of helm chart with version 7.2.0:

> ```
> - name: ELASTIC_PASSWORD
> value: changeme
> - name: xpack.security.enabled
> value: "true"
> 
> ```

Now I have an error:

```
 Readiness probe failed: Waiting for elasticsearch cluster to become cluster to be ready (request params: "wait_for_status=green&timeout=5s" )
Cluster is not yet ready (request params: "wait_for_status=green&timeout=5s" )

```

Even with this setting:  
`replicas: 1`  
`minimumMasterNodes: 1`  
and  
`antiAffinity: "soft"`

The fun thin is that I the problem is only with pods starting, when I do curl I receive response.

Do you have any idea how to get a cluster ready?

`curl -u "elastic:changeme" -k "http://localhost:9200"`

---

<div class="post-metadata">

**Author:** ![O\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/o_k/32/52424_2.png) [@O\_K](https://discuss.elastic.co/u/O_K)\
**Post date:** [September 6, 2019, 12:40pm UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/6 "2019-09-06T12:40:55Z")

</div>

It seems adding `- ELASTICSEARCH_USERNAME=elastic` into elasticsearch env var helped 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2019, 12:40pm UTC](https://discuss.elastic.co/t/basic-security-without-xpack/198349/7 "2019-10-04T12:40:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
