# Best practis for agents enrollment with fleet on ECK

**URL:** https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986
**Category:** Elastic Cloud on Kubernetes (ECK)
**Created:** [November 26, 2023, 8:33am UTC](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986 "2023-11-26T08:33:58Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![khaled\_belgacem](https://avatars.discourse-cdn.com/v4/letter/k/45deac/32.png) [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)
#### Post date: [November 26, 2023, 8:33am UTC](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986/1 "2023-11-26T08:33:58Z")

</div>

Hello everyone,

i'm currently using ECK for my elastic stack, i installed agents on some laptops and they enrolled successfully with fleet ( they go by the public network, both elasticsearch and fleet are exposed ), but i'm not really sure if i'm doing it the right way, more precisely the secure way, and i cant find any doc about best practice for this point on ECK

At the moment i enroll elastic agents to my fleet servers only by token i just add --insecure to the commands and the enrollment is done

from my server side the stack uses self signed certs but the ingress uses a cert signed by a well known source, i tried both ssl.verification\_mode None and Certificate but the agents keeps enrolling with the token only

so is this the good aproach or is there a better way to do so

Best Regards

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 24, 2023, 8:34am UTC](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986/2 "2023-12-24T08:34:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
