# Configure GCP bucket for snapshot

**URL:** <https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150>\
**Category:** Elasticsearch\
**Created:** [November 10, 2018, 4:30pm UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150 "2018-11-10T16:30:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhilpawar1985](https://avatars.discourse-cdn.com/v4/letter/n/e68b1a/32.png) [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Post date:** [November 10, 2018, 4:30pm UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150/1 "2018-11-10T16:30:25Z")

</div>

Hi ,  
I have ES cluster running on GCP instances. I am trying to configure GCP bucket for snapshots but unable to add gcp service-account.json (credential file to ES keystore ) can someone advise on this , how to add it setting and a credential file to keystore and configure this .

`/usr/share/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.es-snap-agent.elasticsearch_gserviceaccount`

my gcp service act - elasticsearch\_gserviceaccount

```
[root@es-node-1-us-east4-a-96182b elasticsearch]# /usr/share/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.default.elasticsearch_gserviceaccount
A tool for managing settings stored in the elasticsearch keystore

Commands
--------
create - Creates a new elasticsearch keystore
list - List entries in the keystore
add - Add a string setting to the keystore
add-file - Add a file setting to the keystore
remove - Remove a setting from the keystore

Non-option arguments:
command

Option Description
------ -----------
-h, --help show help
-s, --silent show minimal output
-v, --verbose show verbose output
ERROR: Missing file name
```

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 10, 2018, 10:43pm UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150/2 "2018-11-10T22:43:48Z")

</div>

> [@Nikhilpawar1985](#):
>
> ```auto
> ERROR: Missing file name
> 
> ```

This is the clue, but the docs are unclear so I opened [#35433](https://github.com/elastic/elasticsearch/issues/35433). The command should be:

```auto
elasticsearch-keystore add-file gcs.client.default.credentials_file FILENAME

```

where `FILENAME` is the name of your credentials file. Note that the setting name is `gcs.client.NAME.credentials_file` where `NAME` is normally `default`, which is not what you're using.

---

<div class="post-metadata">

**Author:** ![Nikhilpawar1985](https://avatars.discourse-cdn.com/v4/letter/n/e68b1a/32.png) [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Post date:** [November 10, 2018, 11:16pm UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150/3 "2018-11-10T23:16:29Z")

</div>

Hi David .

I tried to change the default name . But in cmd line if you check i did used default earlier .

But as per your advise

```
[root@elasticsearch-node-1-us-east4-a-96182b elasticsearch]# /usr/share/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.default.elasticsearch_gserviceaccount elasticsearch_gserviceaccount
Setting gcs.client.default.elasticsearch_gserviceaccount already exists. Overwrite? [y/N]y
[root@elasticsearch-node-1-us-east4-a-96182b elasticsearch]# /usr/share/elasticsearch/bin/elasticsearch-keystore list
gcs.client.default.elasticsearch_gserviceaccount
keystore.seed

```

I do face problem in next step now

```
curl --cacert /etc/elasticsearch/certs/digicertca-chain.cert -X PUT -u elastic "https://elasticsearch-node-2.jabodo.com:9200/_snapshot/iacapps_gcs_repository" -H 'Content-Type: application/json' -d'
> {
> "type": "gcs",
> "settings": {
> "bucket": "iacapps-es-snapshots",
> "client": "default"
> }
> }
> '
Enter host password for user 'elastic':
{"error":{"root_cause":[{"type":"blob_store_exception","reason":"Unable to check if bucket [iacapps-es-snapshots] exists"}],"type":"repository_exception","reason":"[iacapps_gcs_repository] cannot create blob store","caused_by":{"type":"blob_store_exception","reason":"Unable to check if bucket [iacapps-es-snapshots] exists","caused_by":{"type":"security_exception","reason":"access denied (\"java.lang.RuntimePermission\" \"accessDeclaredMembers\")"}}},"status":500}

```

looks like permission issue. But service act has storage admin permissions . How do i troubleshoot this

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 11, 2018, 8:31am UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150/4 "2018-11-11T08:31:13Z")

</div>

Could you share the stack trace from this exception, which you will find in the node logs?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2018, 8:31am UTC](https://discuss.elastic.co/t/configure-gcp-bucket-for-snapshot/156150/5 "2018-12-09T08:31:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
