# Bootstrap checks failed,

**URL:** <https://discuss.elastic.co/t/bootstrap-checks-failed/287674>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [October 26, 2021, 10:09am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674 "2021-10-26T10:09:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![manu\_john](https://avatars.discourse-cdn.com/v4/letter/m/f6c823/32.png) [@manu\_john](https://discuss.elastic.co/u/manu_john)\
**Post date:** [October 26, 2021, 10:09am UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/1 "2021-10-26T10:09:09Z")

</div>

Using this repository

> **[GitHub - elastic/helm-charts: You know, for Kubernetes](https://github.com/elastic/helm-charts)**
>
> You know, for Kubernetes. Contribute to elastic/helm-charts development by creating an account on GitHub.

Getting below error, as per the error checked the configuration and its all same as expected  
ERROR: [1] bootstrap checks failed. You must address the points described in the following [1] lines before starting Elasticsearch.

bootstrap check failure [1] of [1]: Transport SSL must be enabled if security is enabled. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]

ERROR: Elasticsearch did not exit normally - check the logs at /usr/share/Elasticsearch/logs/multi.log

---

<div class="post-metadata">

**Author:** ![Michael\_Montgomery](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_montgomery/32/82242_2.png) [@Michael\_Montgomery](https://discuss.elastic.co/u/Michael_Montgomery)\
**Post date:** [November 8, 2021, 3:27pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/2 "2021-11-08T15:27:34Z")

</div>

Mind posting your full Elasticsearch custom resource so we can better help debug your error?

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch

```

Thanks

---

<div class="post-metadata">

**Author:** ![bikeman](https://avatars.discourse-cdn.com/v4/letter/b/d6d6ee/32.png) [@bikeman](https://discuss.elastic.co/u/bikeman)\
**Post date:** [November 21, 2021, 9:26pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/3 "2021-11-21T21:26:00Z")

</div>

Same error here!  
Installed a cluster och four nodes (on separate centos 7 virtual machines)  
Node-1: master  
Node-2: data, master  
Node-3: data  
Node-4: ingest

All 4 nodes joined a cluster and kibana kicked in as expected.  
BUT! when i proceeded with setup with a "[minimu security for Elasicsearch](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-minimal-setup.html)"  
Then in the first step Elasticsearch fails to start up.

`ERROR][o.e.b.Bootstrap] [elk1] node validation exception  
[1] bootstrap checks failed. You must address the points described in the following [1] lines before starting Elasticsearch.  
bootstrap check failure [1] of [1]: Transport SSL must be enabled if security is enabled on a [basic] license. Please set [xpack.security.transport.ssl.enabled] to [true] or disable security by setting [xpack.security.enabled] to [false]'

And now I'm in a loop.  
If I enable xpack.security.transport.ssl then ES cluster wont start because I newer set up passwords and I can't set up passwords because ES refuse to start.

Please point me in the right direction here, what i'm i missing?

BTW, this is my Elasticsearch.yml settings (in short)  
'cluster.name: virt-cluster  
node.roles: [master]  
node.name: Node-1  
path.data: /var/lib/Elasticsearch  
path.logs: /var/log/Elasticsearch  
network.host: 192.168.1.21  
discovery.seed\_hosts: ["192.168.1.21", "192.168.1.22"]  
#cluster.initial\_master\_nodes: ["Node-1", "Node-22"]  
xpack.security.enabled: true'

The other nodes files are with the equal settings.

---

<div class="post-metadata">

**Author:** ![Michael\_Montgomery](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_montgomery/32/82242_2.png) [@Michael\_Montgomery](https://discuss.elastic.co/u/Michael_Montgomery)\
**Post date:** [November 23, 2021, 7:04pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/4 "2021-11-23T19:04:52Z")

</div>

Unfortunately, I cannot reproduce this.

```auto
❯ curl -u elastic:--redact-- -sk https://localhost:9200/_cluster/health\?pretty
{
  "cluster_name" : "testing-xpack",
  "status" : "green",
  "timed_out" : false,
  "number_of_nodes" : 3,
  "number_of_data_nodes" : 3,
  "active_primary_shards" : 1,
  "active_shards" : 2,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 0,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 100.0
}

```

Resource

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: testing-xpack
spec:
  version: 7.15.1
  nodeSets:
  - name: masters
    count: 3
    config:
      node.roles: ["master", "data"]
      node.store.allow_mmap: false
      xpack.security.enabled: true

```

With Eck 1.8.0. Could you please give a full reproducible steps to generate the error, that would greatly assist in debugging these types of errors. Thanks.

---

<div class="post-metadata">

**Author:** ![bikeman](https://avatars.discourse-cdn.com/v4/letter/b/d6d6ee/32.png) [@bikeman](https://discuss.elastic.co/u/bikeman)\
**Post date:** [November 24, 2021, 4:59pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/5 "2021-11-24T16:59:17Z")

</div>

Hello,

I kind a found my way out of the loop!  
I jumped directly to "[basic security](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-basic-setup.html)" and created certificates. After that the servers ware able to talk to each other and Elasticsearch started.  
With ES up and running I runned ./bin/Elasticsearch-setup-password auto (jumped back to minimum security).

Maybe it was my fault to setup SSL/TLS on a formed cluster before putting sec on everything and that's why I was stuck in a loop. I should maybe do another way around?

However this worked for me.

1. Install 3-5 machines
2. Install ES, Kibana, Logstash, etc och your machines
3. Form a cluster
4. [Set up basic security for the Elastic Stack](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-basic-setup.html)
5. [Set up minimal security for Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-minimal-setup.html)
6. [Set up basic security for the Elastic Stack plus secured HTTPS traffic](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/security-basic-setup-https.html)

BTW  
I hope my explanation help's someone, sorry for hijacking/borrowing a thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2021, 4:59pm UTC](https://discuss.elastic.co/t/bootstrap-checks-failed/287674/6 "2021-12-22T16:59:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
