# Dec 1st, 2023: \[EN\] Securing Elasticsearch with HashiCorp Vault

**URL:** <https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280>\
**Category:** Advent Calendar\
**Created:** [December 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280 "2023-12-01T08:00:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![framsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/framsouza/32/95958_2.png) [@framsouza](https://discuss.elastic.co/u/framsouza)\
**Post date:** [December 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280/1 "2023-12-01T08:00:52Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c0f6a21174fe4acdfaa8ca7e6994365e898f63e.png)

Are you utilizing both Elasticsearch and HashiCorp in your environment and seeking ways to connect the two? This concise article unveils the steps to effectively employ HashiCorp Vault for automated credential generation and revocation on Elasticsearch.

> The [guide from HashiCorp provides instructions](https://developer.hashicorp.com/vault/docs/secrets/databases/elasticdb) for setting up an Elasticsearch secret engine, primarily focused on Elasticsearch version 7.1.1, which used an additional security feature called x-pack. This guide suggests installing a plugin using elasticsearch-cli for that version. However, it's important to note that in newer versions like 8\>, the need for installing this plugin has been eliminated because x-pack is no longer available separately. For instance, in Elasticsearch version 8.10, x-pack is integrated or replaced with native functionalities, eliminating the requirement for separate plugin installations. HashiCorp has recognized this change, and there's an ongoing [issue](https://github.com/hashicorp/vault/issues/18723) open with them to update the guide to reflect these changes for the latest versions of Elasticsearch. These instructions was performed on Elasticsearch version 8.10.0.

## Demo

Watch a quick demo by accessing this [link](https://github.com/framsouza/securing-es-with-vault/tree/main#demo).

## Requirements

1. Create an account on [Elastic Cloud](https://www.elastic.co/cloud/) (_\>8.+_)
2. Install and unseal vault in our Kubernetes/VMs ([see guide](https://developer.hashicorp.com/vault/docs/install))

## Implementation

1. Enable vault database secret engine

`vault secrets enable -path=elasticsearch database`

1. Configure a Vault role that will be used by the elasticsearch secret engine

```auto
vault write elasticsearch/roles/internally-defined-role \
      db_name=my-elasticsearch-database \
      creation_statements='{"elasticsearch_role_definition": {"indices": [{"names":["*"], "privileges":["read"]}]}}' \
      default_ttl="1h" \
      max_ttl="24h"

```

1. Configure the elasticsearch secret database to connect to your ES deployment

```auto
vault write elasticsearch/config/my-elasticsearch-database \
    plugin_name="elasticsearch-database-plugin" \
    allowed_roles="internally-defined-role" \
    username=vault \
    password=myPa55word \
    url=<ES-URL>

```

1. Generate a new credentials on Elasticsearch by running:

`vault read elasticsearch/creds/my-role`

This will generate user credentials on Elasticsearch using the role/permissions that was defined on step #2. The credentials will be automatically revoked once the ttl expires.

Easy, right? 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2023, 8:01am UTC](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280/2 "2023-12-29T08:01:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
