# Docker - app\_search - how to find default password

**URL:** <https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235>\
**Category:** Elastic Search\
**Tags:** docker, elastic-app-search\
**Created:** [December 27, 2019, 10:44pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235 "2019-12-27T22:44:14Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![byteandbit](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@byteandbit](https://discuss.elastic.co/u/byteandbit)\
**Post date:** [December 27, 2019, 10:44pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/1 "2019-12-27T22:44:14Z")

</div>

How to find out or set password for user: app\_search in App Search Docker?

Can not login via: [http://localhost:3002/login](http://localhost:3002/login) and keep getting: "Authentication has failed  
Invalid credentials"

From logs I can see that AppSearch successfully connects to Elasticsearch.

Thanks

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [December 30, 2019, 8:35am UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/2 "2019-12-30T08:35:23Z")

</div>

Hi @byteandbit 👋

As mentioned [here](https://swiftype.com/documentation/app-search/self-managed/security#within-app-search) you can set a fixed default password by setting the `APP_SEARCH_DEFAULT_PASSWORD` environment variable.

Setting the default password only works on the initial boot so if you want to reset it afterwards you should run `bin/app-search --reset-auth` or in the case with Docker Compose you would do `docker-compose run app-search --reset-auth`.

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [December 30, 2019, 8:37am UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/3 "2019-12-30T08:37:13Z")

</div>

Oh and to answer "how to find default password", the default password will be logged to the console but only on the initial boot, so if you didn't notice it, it might be hard to retrieve it now.

---

<div class="post-metadata">

**Author:** ![byteandbit](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@byteandbit](https://discuss.elastic.co/u/byteandbit)\
**Post date:** [December 30, 2019, 10:25am UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/4 "2019-12-30T10:25:59Z")

</div>

hi @orhantoy thank you for the response.

I am running ElasticSearch and Kibana in Docker containers on Kubernetes, and AppSearch is running in Docker on Kubernetes too. Unfortunately I have missed the initial boot.... I have tried  
`bin/app-search --reset-auth` but it does not work. It shows new password however when I go to `http://localhost:3002/login` and try to login I am getting exactly the same massage: `"Authentication has failed Invalid credentials"`. I have also tried to set env variable `APP_SEARCH_DEFAULT_PASSWORD` but exactly the same effect: `"Authentication has failed Invalid credentials"`.

Do you know if the password for app\_search user is saved in AppSearch container or it saved in some index on ElasticSearch? If it is in AppSearch how can I reset in Docker on Kubernetes?

Thanks

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [December 30, 2019, 10:29am UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/5 "2019-12-30T10:29:27Z")

</div>

The `app_search` user is managed in Elasticsearch so you could also use the [Change password API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-change-password.html) directly.

---

<div class="post-metadata">

**Author:** ![byteandbit](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@byteandbit](https://discuss.elastic.co/u/byteandbit)\
**Post date:** [January 1, 2020, 3:17am UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/6 "2020-01-01T03:17:42Z")

</div>

Thanks.

But I use `app_search.auth.source: standard`. Does Elasticsearch manage `app_search` in such case too?

Anyway I have run `GET /_security/user` and got following output:

> ```
> {
> "app_search" : {
> "username" : "app_search",
> "roles" : [],
> "full_name" : "app_search",
> "email" : "app-search@example.com",
> "metadata" : { },
> "enabled" : true
> }
> }
> 
> ```

I have also successfully run:

> POST /\_security/user/app\_search/\_password  
> {  
> "password" : "test"  
> }

But still the same front end error `Authentication has failed invalid credentials` and in the `appserach` logs I can see always (with unsuccessful login) following:  
`action_controller][INFO]: [1c44b989-67f1-4996-8ce5-93eb0f005550] Completed 403 Forbidden in 105ms (Views: 18.2ms)`

Any Idea?

---

<div class="post-metadata">

**Author:** ![orhantoy](https://avatars.discourse-cdn.com/v4/letter/o/c5a1d2/32.png) [@orhantoy](https://discuss.elastic.co/u/orhantoy)\
**Post date:** [January 6, 2020, 12:18pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/7 "2020-01-06T12:18:01Z")

</div>

Can you try to change the password _after_ App Search has booted up (via the ES Security API)? And then try to log in again.

And yes, Elasticsearch manages users in the `standard` auth source case as well.

---

<div class="post-metadata">

**Author:** ![byteandbit](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@byteandbit](https://discuss.elastic.co/u/byteandbit)\
**Post date:** [January 6, 2020, 11:01pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/8 "2020-01-06T23:01:15Z")

</div>

I have tried that already and same result.

See following log/trace from AppSearch.

I am always getting (see at the very bottom):

> Completed 403 Forbidden in...

2020-01-06T22:53:50.538+00:00][14][2352][action\_controller][INFO]: [9517012c-8a44-4115-8f59-d5f883fef0e0] Redirected to [http://localhost:3002/login](http://localhost:3002/login)  
[2020-01-06T22:53:50.553+00:00][14][2352][action\_controller][INFO]: [9517012c-8a44-4115-8f59-d5f883fef0e0] Completed 302 Found in 57ms  
[2020-01-06T22:53:50.606+00:00][14][2304][app-server][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Started GET "/login" for 127.0.0.1 at 2020-01-06 22:53:50 +0000  
[2020-01-06T22:53:50.616+00:00][14][2304][action\_controller][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Processing by LocoTogo::SessionsController#login as HTML  
[2020-01-06T22:53:50.617+00:00][14][2304][action\_controller][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Parameters: {"host"=\>"localhost:3002", "protocol"=\>"http"}  
[2020-01-06T22:53:50.700+00:00][14][2304][action\_view][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Rendered eui\_icons/\_close.html (0.4ms)  
[2020-01-06T22:53:50.713+00:00][14][2304][action\_view][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Rendered eui\_icons/\_lock.html (0.3ms)  
[2020-01-06T22:53:50.756+00:00][14][2304][action\_view][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Rendered loco\_togo/app/views/loco\_togo/sessions/login.html.rb (90.6ms)  
[2020-01-06T22:53:50.758+00:00][14][2304][action\_controller][INFO]: [8a622bd8-03d9-4bad-88a8-edd64f85ecaa] Completed 200 OK in 140ms (Views: 99.4ms)  
[2020-01-06T22:54:04.915+00:00][14][2304][app-server][INFO]: [718f2fe8-1536-4097-836b-a06b19a24df8] Started POST "/authenticate/sign\_in" for 127.0.0.1 at 2020-01-06 22:54:04 +0000  
[2020-01-06T22:54:04.930+00:00][14][2304][cache][DEBUG]: [718f2fe8-1536-4097-836b-a06b19a24df8] Cache read: rack::attack:438430:logins/email:app\_search ({:expires\_in=\>357})  
[2020-01-06T22:54:04.931+00:00][14][2304][cache][DEBUG]: [718f2fe8-1536-4097-836b-a06b19a24df8] Cache write: rack::attack:438430:logins/email:app\_search ({:expires\_in=\>357})  
[2020-01-06T22:54:04.939+00:00][14][2304][action\_controller][INFO]: [718f2fe8-1536-4097-836b-a06b19a24df8] Processing by AuthenticateController#login as _/_  
[2020-01-06T22:54:04.939+00:00][14][2304][action\_controller][INFO]: [718f2fe8-1536-4097-836b-a06b19a24df8] Parameters: {"auth\_strategy"=\>"password", "user"=\>{"email"=\>"app\_search", "password"=\>"[FILTERED]"}, "host"=\>"localhost:3002", "protocol"=\>"http"}  
[2020-01-06T22:54:04.963+00:00][14][2304][action\_view][INFO]: [718f2fe8-1536-4097-836b-a06b19a24df8] Rendered text template (0.1ms)  
[2020-01-06T22:54:04.964+00:00][14][2304][action\_controller][INFO]: [718f2fe8-1536-4097-836b-a06b19a24df8] Completed 403 Forbidden in 24ms (Views: 4.8ms)

---

<div class="post-metadata">

**Author:** ![byteandbit](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@byteandbit](https://discuss.elastic.co/u/byteandbit)\
**Post date:** [January 8, 2020, 10:42pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/9 "2020-01-08T22:42:49Z")

</div>

Where to find any more info? Is the source code available somewhere?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2020, 10:42pm UTC](https://discuss.elastic.co/t/docker-app-search-how-to-find-default-password/213235/10 "2020-02-05T22:42:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
