# Elastic-agent as non-root - possible?

**URL:** <https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321>\
**Category:** Elastic Agent\
**Created:** [November 18, 2022, 4:12pm UTC](https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321 "2022-11-18T16:12:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![el\_gg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@el\_gg](https://discuss.elastic.co/u/el_gg)\
**Post date:** [November 18, 2022, 4:12pm UTC](https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321/1 "2022-11-18T16:12:00Z")

</div>

Hi,

We're doing a POC on the ELK stack and are now looking into the elastic-agent and fleet. Our install is on RHEL8 VMs. We now ran into this:

> Error: unable to perform install command, not executed with root permissions

I also found on [Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide [8.11] | Elastic](https://www.elastic.co/guide/en/fleet/current/beats-agent-comparison.html) that

> Fleet-managed Elastic Agents require root permission, in particular for Elastic Defend. Standalone Elastic Agents and Beats do not

Is it possible at all the install a fleet managed elastic-agent as non-root? Asking root permissions, letting something run as root or even installing something as root is a no-go in our environment.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 18, 2022, 5:36pm UTC](https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321/2 "2022-11-18T17:36:15Z")

</div>

> [@el\_gg](#):
>
> Is it possible at all the install a fleet managed elastic-agent as non-root?

I don't think so, the managed elastic-agent needs to be installed and run as root to be able to install and update the integrations and itself.

If you cannot use it as root then you will need to self-manage the agents or use one of the beats.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2022, 1:14am UTC](https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321/3 "2022-11-21T01:14:10Z")

</div>

Plus there is specific logs and other system level things the Beats need root access to be able to read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2022, 2:26pm UTC](https://discuss.elastic.co/t/elastic-agent-as-non-root-possible/319321/5 "2022-12-23T14:26:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
