# Challenge with Creating Secret elasticsearch-es-internal-users with Custom User Values Before ECK Deployment in ArgoCD

**URL:** <https://discuss.elastic.co/t/challenge-with-creating-secret-elasticsearch-es-internal-users-with-custom-user-values-before-eck-deployment-in-argocd/376955>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [April 9, 2025, 12:49pm UTC](https://discuss.elastic.co/t/challenge-with-creating-secret-elasticsearch-es-internal-users-with-custom-user-values-before-eck-deployment-in-argocd/376955 "2025-04-09T12:49:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![niveditakathal](https://avatars.discourse-cdn.com/v4/letter/n/e19b73/32.png) [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Post date:** [April 9, 2025, 12:49pm UTC](https://discuss.elastic.co/t/challenge-with-creating-secret-elasticsearch-es-internal-users-with-custom-user-values-before-eck-deployment-in-argocd/376955/1 "2025-04-09T12:49:23Z")

</div>

**Hi Experts,**

### **Current Situation:**

I have a working Elasticsearch setup (xpack: cps-v8.17.3-002) running in a Kubernetes production environment.

In the current deployment process, we are creating the `elasticsearch-es-internal-users` Secret to ensure that users like `elastic-internal`, `elastic-internal-probe`, etc., have their values securely stored in our external secret store.

However, we now want to transition the deployment process to use ArgoCD, and we are facing a challenge with ensuring that the `elasticsearch-es-internal-users` Secret is created before the Elastic Cloud on Kubernetes (ECK) operator deploys the Elasticsearch instance.

### **Question:**

How can we manage the creation of the `elasticsearch-es-internal-users` Secret before the ECK deployment starts, when transitioning to an ArgoCD-driven workflow?

### **Note:**

I tried using `secureSettings`, but ECK didn't use the `elastic-internal` and `elastic-internal-probe` values defined under the `es-internal-users` secret for the new `[il-elasticsearch-test-es-internal-users]` secret.

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: il-elasticsearch-test
spec:
  http:
    tls:
      selfSignedCertificate:
        disabled: true
  secureSettings:
    - secretName: es-internal-users
  nodeSets:...

```

Thanks,  
Nivedita
