# Bootstrap checks failed due to memory is not locked

**URL:** <https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178>\
**Category:** Elasticsearch\
**Created:** [June 13, 2017, 11:34am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178 "2017-06-13T11:34:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chenmu](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@chenmu](https://discuss.elastic.co/u/chenmu)\
**Post date:** [June 13, 2017, 11:34am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/1 "2017-06-13T11:34:15Z")

</div>

I’m running elasticsearch image (buiding on centOS 7) on k8s and have the "bootstrap.memory\_lock: true" in elasticsearch.yml file. I added the following lines in /etc/security/limits.conf file  
`esuser soft memlock unlimited esuser hard memlock unlimited`  
and `session required pam_limits.so` in /etc/pam.d/login file into es docker image which building on centOS 7.

When I try to run the image in k8s, it failed with the following messages:

> [2017-06-13T09:50:30,527][WARN][o.e.b.JNANatives] Unable to lock JVM Memory: error=12, reason=Cannot allocate memory  
> [2017-06-13T09:50:30,529][WARN][o.e.b.JNANatives] This can result in part of the JVM being swapped out.  
> [2017-06-13T09:50:30,529][WARN][o.e.b.JNANatives] Increase RLIMIT\_MEMLOCK, soft limit: 65536, hard limit: 65536  
> [2017-06-13T09:50:30,529][WARN][o.e.b.JNANatives] These can be adjusted by modifying /etc/security/limits.conf, for example:  
> # allow user 'esuser' mlockall  
> esuser soft memlock unlimited  
> esuser hard memlock unlimited  
> ......  
> [2017-06-13T09:50:36,938][INFO][o.e.b.BootstrapChecks] [es-master-1451757423-7hgdz] bound or publishing to a non-loopback or non-link-local address, enforcing bootstrap checks  
> ERROR: bootstrap checks failed  
> memory locking requested for elasticsearch process but memory is not locked  
> [2017-06-13T09:50:36,950][INFO][o.e.n.Node] [es-master-1451757423-7hgdz] stopping ...  
> [2017-06-13T09:50:37,005][INFO][o.e.n.Node] [es-master-1451757423-7hgdz] stopped  
> [2017-06-13T09:50:37,005][INFO][o.e.n.Node] [es-master-1451757423-7hgdz] closing ...  
> [2017-06-13T09:50:37,025][INFO][o.e.n.Node] [es-master-1451757423-7hgdz] closed  
> `

PS: I can run the image in docker with `docker run --limit memlock=-1:-1 ...` command.

I seems that no proper way to set memlock to unlimited in deployment yaml file on k8s.  
Any comment will be appreciated.

---

<div class="post-metadata">

**Author:** ![willJackson](https://avatars.discourse-cdn.com/v4/letter/w/958977/32.png) [@willJackson](https://discuss.elastic.co/u/willJackson)\
**Post date:** [June 23, 2017, 8:41am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/2 "2017-06-23T08:41:50Z")

</div>

Do you solve it?i get this problem too ,finding way to solve it .......

---

<div class="post-metadata">

**Author:** ![chenmu](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@chenmu](https://discuss.elastic.co/u/chenmu)\
**Post date:** [July 3, 2017, 3:13am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/3 "2017-07-03T03:13:32Z")

</div>

Not yet. I have to set "bootstrap.memory\_lock: false" and  
a. Set vm.swappiness to 1. ( This setting will impact all pods on k8s nodes)  
b. Set "resources" in yaml to restrict memory  
c. Set ES\_JAVA\_OPTS = -Xms\*\*\* -Xmx\*\*\* to be half of memory defined in "resources".

---

<div class="post-metadata">

**Author:** ![willJackson](https://avatars.discourse-cdn.com/v4/letter/w/958977/32.png) [@willJackson](https://discuss.elastic.co/u/willJackson)\
**Post date:** [July 6, 2017, 6:32am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/4 "2017-07-06T06:32:18Z")

</div>

my problem is solved ，i do like below :  
[a.in](http://a.in) the rc file i add privileged: true  
securityContext:  
privileged: true  
capabilities:  
add:  
- IPC\_LOCK  
[b.in](http://b.in) the nodes i change the KUBE\_ALLOW\_PRIV="--allow-privileged=true"

then es can run with memory lock

---

<div class="post-metadata">

**Author:** ![chenmu](https://avatars.discourse-cdn.com/v4/letter/c/839c29/32.png) [@chenmu](https://discuss.elastic.co/u/chenmu)\
**Post date:** [July 12, 2017, 8:52am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/5 "2017-07-12T08:52:41Z")

</div>

The settings are what I was using. Unfortunately, they don't work for me.  
Just see that the issue was discussed at [https://github.com/kubernetes/kubernetes/issues/3595](https://github.com/kubernetes/kubernetes/issues/3595)  
The PR was merged at [https://github.com/kubernetes-incubator/cri-o/pull/639](https://github.com/kubernetes-incubator/cri-o/pull/639)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2017, 9:07am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed-due-to-memory-is-not-locked/89178/6 "2017-08-09T09:07:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
