# Cluster with separate roles docker/ansible

**URL:** https://discuss.elastic.co/t/cluster-with-separate-roles-docker-ansible/254977
**Category:** Elasticsearch
**Created:** [November 10, 2020, 9:43pm UTC](https://discuss.elastic.co/t/cluster-with-separate-roles-docker-ansible/254977 "2020-11-10T21:43:33Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![vinci](https://avatars.discourse-cdn.com/v4/letter/v/b5e925/32.png) [@vinci](https://discuss.elastic.co/u/vinci)
#### Post date: [November 10, 2020, 9:43pm UTC](https://discuss.elastic.co/t/cluster-with-separate-roles-docker-ansible/254977/1 "2020-11-10T21:43:33Z")

</div>

Hello,

I'm trying to set up an elasticsearch cluster with 3 nodes, one master, the other two data. I'm doing this all through ansible and in order to also set up the ssl connection between the nodes, I'm making use of a temporary container.  
These are the environmental variables that I'm using for this helper container:

```auto
    env:
      node.name: "{{ inventory_hostname }}"
      node.ml: "false"
      node.data: "false"
      cluster.name: "es-docker-cluster"
      cluster.initial_master_nodes: "{{ inventory_hostname }}"
      xpack.security.enabled: 'true'
      xpack.security.transport.ssl.enabled: 'true'
      ES_JAVA_OPTS: "-Xms1g -Xmx1g"

```

The problem with this is that when node.data set to false it simply won't work. The helper container doesn't seem to be able to form an independent entity, and when I reach the task where I generate the user passwords, I get:

```auto
{"type": "server", "timestamp": "2020-11-10T21:34:22,539Z", "level": "WARN", "component": "r.suppressed", "cluster.name": "es-docker-cluster", "node.name": "elk-test1", "message": "path: /_security/user/apm_system/_password, params: {pretty=, username=apm_system}", "cluster.uuid": "gEYqaOw3QH6uc5v4OV_MHg", "node.id": "hzjvMVv3RWu0h4g85tloRw" ,
"stacktrace": ["org.elasticsearch.action.UnavailableShardsException: [.security-7][0] [1] shardIt, [0] active : Timeout waiting for [1m], request: indices:data/write/update",
"at org.elasticsearch.action.support.single.instance.TransportInstanceSingleOperationAction$AsyncSingleAction.retry(TransportInstanceSingleOperationAction.java:224) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.action.support.single.instance.TransportInstanceSingleOperationAction$AsyncSingleAction.doStart(TransportInstanceSingleOperationAction.java:176) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.action.support.single.instance.TransportInstanceSingleOperationAction$AsyncSingleAction$2.onTimeout(TransportInstanceSingleOperationAction.java:245) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:325) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.cluster.ClusterStateObserver$ObserverClusterStateListener.onTimeout(ClusterStateObserver.java:252) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.cluster.service.ClusterApplierService$NotifyTimeout.run(ClusterApplierService.java:598) [elasticsearch-7.7.1.jar:7.7.1]",
"at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:633) [elasticsearch-7.7.1.jar:7.7.1]",
"at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1130) [?:?]",
"at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:630) [?:?]",
"at java.lang.Thread.run(Thread.java:832) [?:?]"] } 

```

I'm guessing it doesn't find a data role where it can store the shards?

So the question is, how could I go about creating a cluster with separate roles using containers in one go, as it were? I don't really understand the logic. The answer doesn't need to be necessarily applied to ansible, even though I should mention that ansible runs tasks only one after another, not in parallel 🙂

---

<div class="post-metadata">

### Author: ![vinci](https://avatars.discourse-cdn.com/v4/letter/v/b5e925/32.png) [@vinci](https://discuss.elastic.co/u/vinci)
#### Post date: [November 16, 2020, 11:25am UTC](https://discuss.elastic.co/t/cluster-with-separate-roles-docker-ansible/254977/2 "2020-11-16T11:25:41Z")

</div>

Maybe I should reword it:  
What is the minimum requirement for elasticsearch in order for `elasticsearch-setup-passwords` to work, while also being able to configure the nodes through TLS certificates?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 14, 2020, 11:25am UTC](https://discuss.elastic.co/t/cluster-with-separate-roles-docker-ansible/254977/3 "2020-12-14T11:25:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
