# ECK Beat via Helm doesn't create a service

**URL:** <https://discuss.elastic.co/t/eck-beat-via-helm-doesnt-create-a-service/371418>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [December 3, 2024, 8:18pm UTC](https://discuss.elastic.co/t/eck-beat-via-helm-doesnt-create-a-service/371418 "2024-12-03T20:18:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![natharran](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@natharran](https://discuss.elastic.co/u/natharran)\
**Post date:** [December 3, 2024, 8:18pm UTC](https://discuss.elastic.co/t/eck-beat-via-helm-doesnt-create-a-service/371418/1 "2024-12-03T20:18:52Z")

</div>

Hello. I have Elastic stack deployed on Kubernetes via up-to-date elastic Helm charts from [here](https://github.com/elastic/cloud-on-k8s/tree/main/deploy/eck-stack/charts). Everything is running smoothly. Among other things, Metricbeat is sending data to Elasticsearch. I have trial license activated. Now I'd like to make Metricbeat authenticate to ES via mTLS as I have done with Logstash where it works fine.

However, ECK doesn't seem to create a key and certificate for this beat, but it created CA for it. I understand that this is due to MB not listening for any incoming connections, so I'm trying to set up a service to make ECK create a key and certificate.

I understand that the [http directive](https://github.com/elastic/cloud-on-k8s/blob/main/deploy/eck-stack/charts/eck-beats/values.yaml#L108) is supposed to handle this, but I used it to no avail. I have it set to

```auto
http: 
  service:
    metadata:
      name: mb
    spec:
      ports:
        - name: mb
          port: 5066
          protocol: TCP
          targetPort: 5066
  tls:
    certificate: {}

```

with no extra indentation but no service gets created. When I see the settings as the beat got deployed in k8s (kubectl get beat my-beat -o yaml), this section isn't even there.

This is surely some minor mistake on my part but I just can't find it. Could someone please help?

Thank you.

---

<div class="post-metadata">

**Author:** ![natharran](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@natharran](https://discuss.elastic.co/u/natharran)\
**Post date:** [December 17, 2024, 2:56pm UTC](https://discuss.elastic.co/t/eck-beat-via-helm-doesnt-create-a-service/371418/2 "2024-12-17T14:56:22Z")

</div>

OK so the situation is slightly different than I thought. ECK didn't create any PKI stuff for Beats. This "ca secret" that got created only contains CA of the ES cluster referenced by the elasticsearchRef directive. Nothing new has been created.

So I guess that ECK creates CA, CRT and KEY for ES, KBN and LS but no other components.
