# ECK Deployment on Openshift using https://www.elastic.co/guide/en/cloud-on-k8s/1.9/k8s-openshift-deploy-elasticsearch.html

**URL:** https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644
**Category:** Elasticsearch
**Tags:** docker
**Created:** [February 8, 2022, 5:31pm UTC](https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644 "2022-02-08T17:31:00Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Ganesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesh_sharma/32/78930_2.png) [@Ganesh\_Sharma](https://discuss.elastic.co/u/Ganesh_Sharma)
#### Post date: [February 8, 2022, 5:31pm UTC](https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644/1 "2022-02-08T17:31:00Z")

</div>

Please can someone confirm if this is a valid Elasticsearch deployment for Openshift?  
Please advise as I am stuck since couple of days.

```auto
---
apiVersion: route.openshift.io/v1
kind: Route
metadata:
  name: elasticsearch
spec:
  #host: elasticsearch.example.com # override if you don't want to use the host that is automatically generated by OpenShift (<route-name>[-<namespace>].<suffix>)
  tls:
    termination: passthrough # Elasticsearch is the TLS endpoint
    insecureEdgeTerminationPolicy: Redirect
  to:
    kind: Service
    name: elasticsearch-es-http
---
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: elasticsearch  
spec:
  version: 7.17.0
  image: docker-eu.artifactory.swg-devops.com/sec-yoda-team-docker-local/pti/elasticsearch-gcs:7.17.0
  secureSettings:
  - secretName: jfrog
  nodeSets:
  - name: master   
    count: 1   
    config:
      node.master: true   
      node.data: false     
    podTemplate:
      spec:
        securityContext:
          runAsUser: 1234
          fsGroup: 1234
        initContainers:
        - name: sysctl
          securityContext:
            privileged: true   
          command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144']   
        containers:
        - name: elasticsearch
          env:
          - name: ES_JAVA_OPTS
            value: -Xms2g -Xmx2g
          resources:
            requests:
              cpu: 2
              memory: 8Gi
            limits:
              cpu: 3
              memory: 10Gi
  - name: data
    count: 3
    config:
      node.master: false  
      node.data: true  
      node.attr.date: hot   
    podTemplate:
      spec:
        securityContext:
          runAsUser: 1234
          fsGroup: 1234
        initContainers:
        - name: sysctl
          securityContext:
            privileged: true
          command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144']
        containers:
        - name: elasticsearch
          env:
          - name: ES_JAVA_OPTS
            value: -Xms2g -Xmx2g
          resources:
            requests:
              cpu: 2
              memory: 8Gi
            limits:
              cpu: 3
              memory: 10Gi
    volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 100Gi
        storageClassName: ibmc-file-silver

```

---

<div class="post-metadata">

### Author: ![Ganesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesh_sharma/32/78930_2.png) [@Ganesh\_Sharma](https://discuss.elastic.co/u/Ganesh_Sharma)
#### Post date: [February 8, 2022, 6:02pm UTC](https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644/2 "2022-02-08T18:02:02Z")

</div>

I am unable to pull image from the Repo 🙂  
I have added the Image Pull secret as 🙂

```auto
 secureSettings:
  - secretName:

```

---

<div class="post-metadata">

### Author: ![Ganesh\_Sharma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesh_sharma/32/78930_2.png) [@Ganesh\_Sharma](https://discuss.elastic.co/u/Ganesh_Sharma)
#### Post date: [February 8, 2022, 6:35pm UTC](https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644/3 "2022-02-08T18:35:37Z")

</div>

Do we need a Service Account to be created for this to work? I dont see any documentation for creating a SA for ImagePullSecret? Please can someone help me understand this?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2022, 6:36pm UTC](https://discuss.elastic.co/t/eck-deployment-on-openshift-using-https-www-elastic-co-guide-en-cloud-on-k8s-1-9-k8s-openshift-deploy-elasticsearch-html/296644/4 "2022-03-08T18:36:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
