# Can't create a cluster if node's domain points to the localhost in /etc/hosts

**URL:** <https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738>\
**Category:** Elasticsearch\
**Created:** [April 11, 2023, 11:20am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738 "2023-04-11T11:20:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![panrobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/panrobot/32/119680_2.png) [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Post date:** [April 11, 2023, 11:20am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/1 "2023-04-11T11:20:53Z")

</div>

Hi,

if `/etc/hosts/` is configured as follows:

```auto
127.0.0.1 node01.com
127.0.0.1 localhost

```

and if you set `elasticsearch.yml` to:

```auto
network.host: ["_enp1s0_", "_local_"]                                                                                                                                                                                                       
network.bind_host: ["_enp1s0_", "_local_"]                                                                                                                                                                                                  
network.publish_host: ["node01.com"] 

```

you won't be able to create a cluster because node will advertise itself as `node01.com/127.0.0.1` and every other node with similar config of `/etc/hosts/` and `elasticsearch.yml` will try to connect to other nodes with a correct domain but on own localhost. If I change `/etc/hosts` to `127.0.0.1 node01` it will work flawlessly.

Is there any way to set the domain with an address of a network interface? Something like `node01.com/_enp1s0_` ?

Best regards

### Steps to Reproduce

1. set your domain in `/etc/hosts` to resolve to 127.0.0.1
2. set `elasticsearch.yml` as presented in the problem description using only special values and a domain name
3. restart cluster

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 11, 2023, 12:23pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/2 "2023-04-11T12:23:29Z")

</div>

Do you want this? If not, can you expand on why it doesn't work for you?

`network.publish_host: ["_enp1s0_"] `

---

<div class="post-metadata">

**Author:** ![panrobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/panrobot/32/119680_2.png) [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Post date:** [April 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/3 "2023-04-11T12:59:39Z")

</div>

Hi David!

Thanks a lot for a quick response.

I have tried the config You propose. If I set `network.publish_host: ["_enp1s0_"] ` all nodes will try to connect each other using IP addresses instead of FQDN and as my certificate is wildcard I can not put IPs in it.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 11, 2023, 1:05pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/4 "2023-04-11T13:05:26Z")

</div>

You can use wildcard certificates from a well-known CA for your HTTP traffic, but it's a bad idea for transport traffic. See [these docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-basic-setup.html#generate-certificates) for more information:

> For the transport layer, we recommend using a separate, dedicated CA instead of an existing, possibly shared CA so that node membership is tightly controlled. Use the `elasticsearch-certutil` tool to generate a CA for your cluster.

---

<div class="post-metadata">

**Author:** ![panrobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/panrobot/32/119680_2.png) [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Post date:** [April 12, 2023, 8:21am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/5 "2023-04-12T08:21:22Z")

</div>

Thanks a lot for this good practice tip. I will consider it.

However it is still a bit misleading for me that setting only a domain in the `network.publish_host` will have a result depending on the content of `/etc/hosts` i.e. `domain/localhost` if domain points to localhost in `/etc/hosts` or `domain/global_ip` otherwise.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 12, 2023, 9:42am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/6 "2023-04-12T09:42:29Z")

</div>

In general we expect these things to yield the same results so it doesn't matter, but if you set up your DNS to give different answers depending on who is asking then this sort of problem will arise. I'll try and clarify this in the docs.

---

<div class="post-metadata">

**Author:** ![panrobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/panrobot/32/119680_2.png) [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Post date:** [April 12, 2023, 9:56am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/7 "2023-04-12T09:56:36Z")

</div>

Clarifying this in the docs would be great (and time saving for next time :D)! Thank you in advance 🙂

Do you think it could be possible to somehow take into account only DNS (without hosts file)?

![img](https://us1.discourse-cdn.com/elastic/original/3X/2/6/2652f25893bfec155782b30c4bb28f04dc244d57.jpeg)

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [April 12, 2023, 10:09am UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/8 "2023-04-12T10:09:57Z")

</div>

The JVM is just using something from `libc` like `gethostbyname()` under the hood, so you can control its behaviour via `nsswitch.conf` and friends (or whatever your system equivalent is). Or you could remove the bogus entry from `/etc/hosts` - that's what I'd do at least.

---

<div class="post-metadata">

**Author:** ![panrobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/panrobot/32/119680_2.png) [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Post date:** [April 12, 2023, 2:06pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/9 "2023-04-12T14:06:37Z")

</div>

TIL: there is something like `nsswitch.conf` 👍

I ended up editing `/etc/hosts`. Thanks a lot for all your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2023, 2:07pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738/10 "2023-05-10T14:07:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
