# Deploy ElasticSearch 6.5.4 on Kubernetes - AccessDeniedException

**URL:** <https://discuss.elastic.co/t/deploy-elasticsearch-6-5-4-on-kubernetes-accessdeniedexception/166207>\
**Category:** Elasticsearch\
**Created:** [January 29, 2019, 4:21pm UTC](https://discuss.elastic.co/t/deploy-elasticsearch-6-5-4-on-kubernetes-accessdeniedexception/166207 "2019-01-29T16:21:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![szern](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@szern](https://discuss.elastic.co/u/szern)\
**Post date:** [January 29, 2019, 4:21pm UTC](https://discuss.elastic.co/t/deploy-elasticsearch-6-5-4-on-kubernetes-accessdeniedexception/166207/1 "2019-01-29T16:21:50Z")

</div>

I'm attempting to deploy EFK on my Kubernetes cluster. The ElasticSearch version is 6.5.4. The pods get created and then immediately go to an error state with the exception:  
AccessDeniedException. The error in the logs:  
Caused by: java.nio.file.AccessDeniedException: /usr/share/elasticsearch/data/nodes  
at sun.nio.fs.UnixException.translateToIOException(UnixException.java:90) ~[?:?]  
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:111) ~[?:?]  
at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:116) ~[?:?]  
at sun.nio.fs.UnixFileSystemProvider.createDirectory(UnixFileSystemProvider.java:385) ~[?:?]  
at java.nio.file.Files.createDirectory(Files.java:689) ~[?:?]  
at java.nio.file.Files.createAndCheckIsDirectory(Files.java:796) ~[?:?]  
at java.nio.file.Files.createDirectories(Files.java:782) ~[?:?]  
In the YAML file I have the following:  
apiVersion: apps/v1  
kind: StatefulSet  
metadata:  
name: es-cluster  
namespace: "{{ .Values.efk.namespace }}"  
labels:  
k8s-app: es-cluster  
version: "{{ .Values.elasticsearch.version }}"  
[kubernetes.io/cluster-service:](http://kubernetes.io/cluster-service:) "true"  
[addonmanager.kubernetes.io/mode:](http://addonmanager.kubernetes.io/mode:) Reconcile  
app: elasticsearch  
spec:  
name: es-cluster  
replicas: {{ .Values.elasticsearch.replicacount }}  
selector:  
matchLabels:  
k8s-app: es-cluster  
version: "{{ .Values.elasticsearch.version }}"  
app: elasticsearch  
template:  
metadata:  
labels:  
k8s-app: es-cluster  
version: "{{ .Values.elasticsearch.version }}"  
[kubernetes.io/cluster-service:](http://kubernetes.io/cluster-service:) "true"  
app: elasticsearch  
spec:  
serviceAccountName: es-cluster  
containers:  
- image: "[docker.elastic.co/elasticsearch/elasticsearch-oss:](http://docker.elastic.co/elasticsearch/elasticsearch-oss:){{ .Values.elasticsearch.version }}"  
name: es-cluster  
resources:  
# need more cpu upon initialization, therefore burstable class  
limits:  
cpu: 1000m  
requests:  
cpu: 100m  
ports:  
- containerPort: 9200  
name: db  
protocol: TCP  
- containerPort: 9300  
name: transport  
protocol: TCP  
volumeMounts:  
- name: data  
mountPath: /usr/share/elasticsearch/data  
env:  
- name: node.name  
valueFrom:  
fieldRef:  
fieldPath: metadata.name  
- name: cluster.name  
value: k8s-logs  
- name: NAMESPACE  
valueFrom:  
fieldRef:  
fieldPath: metadata.namespace  
- name: discovery.zen.ping.unicast.hosts  
value: "es-cluster-0.elasticsearch,es-cluster-1.elasticsearch,es-cluster-2.elasticsearch"  
- name: discovery.zen.minimum\_master\_nodes  
value: "2"  
- name: ES\_JAVA\_OPTS  
value: "-Xms512m -Xmx512m"  
volumeClaimTemplates:

- metadata:  
name: elasticsearch-logging  
spec:  
accessModes: ["ReadWriteOnce"]  
resources:  
requests:  
storage: 50Gi  
initContainers:
  - image: busybox  
command: ["/sbin/sysctl", "-w", "vm.max\_map\_count=262144"]  
name: elasticsearch-logging-init  
securityContext:  
privileged: true
  - image: busybox  
command: ["sh", "-c", "chown -R 1000:1000 /usr/share/elasticsearch/data"]  
name: fix-permissions  
securityContext:  
privileged: true  
volumeMounts:
    - name: data  
mountPath: /usr/share/elasticsearch/data

  - image: busybox  
command: ["sh", "-c", "ulimit -n 65536"]  
name: fix-file-descriptors  
securityContext:  
privileged: true

I'm trying to identify how to rectify the AccessDeniedException. I've set the permissions on the location, but this doesn't work.

Any ideas on what I need to do to fix?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 4:21pm UTC](https://discuss.elastic.co/t/deploy-elasticsearch-6-5-4-on-kubernetes-accessdeniedexception/166207/2 "2019-02-26T16:21:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
