# Elastic-agent install -f

**URL:** <https://discuss.elastic.co/t/elastic-agent-install-f/286753>\
**Category:** Beats\
**Tags:** docker, fleet\
**Created:** [October 14, 2021, 4:11pm UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753 "2021-10-14T16:11:59Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 14, 2021, 4:11pm UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/1 "2021-10-14T16:11:59Z")

</div>

Greetings  
I'm trying to set up fleet. All along the doc I see:

```auto
elastic-agent install -f 

```

but the -f flag is not documented anywhere (and make the elastic-agent choke in the docker version). What is it for? My goal is to use the Docker version, but I don't know what to specify in the compose file to have the agent set up itself...

Thanks in advance

Regards

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 14, 2021, 4:47pm UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/2 "2021-10-14T16:47:56Z")

</div>

Removes the interactive prompts i believe

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 8:06am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/3 "2021-10-15T08:06:29Z")

</div>

Makes sense! Thanks!  
Do you know which parameters to pass to the elastic-agent to have it set up inside a container?

Regards

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 8:11am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/4 "2021-10-15T08:11:58Z")

</div>

@Greg_R

Have you looked at the container command.

> **[Run Elastic Agent in a container | Fleet and Elastic Agent Guide \[7.15\] |...](https://www.elastic.co/guide/en/fleet/current/elastic-agent-container.html)**

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 8:24am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/5 "2021-10-15T08:24:25Z")

</div>

Yes but I keep having error messages:

```auto
2021-10-15T08:23:46.021Z ERROR status/reporter.go:236 Elastic Agent status changed to: 'error'
2021-10-15T08:23:46.022Z ERROR log/reporter.go:36 2021-10-15T08:23:46Z - message: Application: fleet-server--7.15.0[]: State changed to FAILED: Error - EOF - type: 'ERROR' - sub_type: 'FAILED'
2021-10-15T08:23:46.278Z INFO cmd/enroll_cmd.go:724 Fleet Server - Error - EOF
2021-10-15T08:23:52.286Z INFO cmd/enroll_cmd.go:729 Fleet Server - Error - EOF

```

It says EOF but does'nt say which file ☹

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 8:36am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/6 "2021-10-15T08:36:21Z")

</div>

Can you share the steps and commands you are using ? is this for the Fleet Server or Agent ?

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 8:40am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/7 "2021-10-15T08:40:31Z")

</div>

I'm trying to start the first element, which I think is the "server"?

```auto
  fleet-root:
    image: docker.elastic.co/beats/elastic-agent:7.15.0
    container_name: fleet-root
    user: root
    environment:
      - FLEET_SERVER_SERVICE_TOKEN=AAE....
      - FLEET_SERVER_POLICY_ID=5d...
      - FLEET_SERVER_ELASTICSEARCH_HOST=https://172.20.0.2:9200
      - FLEET_SERVER_ENABLE=true
      - FLEET_SERVER_INSECURE_HTTP=true
      - FLEET_INSECURE=true
      - FLEET_ENROLL=1
      - FLEET_URL=https://10.10.11.42:8220
    expose:
      - 8220
    ports:
      - 0.0.0.0:8220:8220

```

I guess it has something to do with the server being accessible on https by IP. I don't know how to disable cert check (communications are already encrypted):

```auto
2021-10-15T08:53:54.133Z ERROR log/reporter.go:36 2021-10-15T08:53:54Z - message: Application: fleet-server--7.15.0[]: State changed to FAILED: Error - x509: cannot validate certificate for 172.20.0.2 because it doesn't contain any IP SANs - type: 'ERROR' - sub_type: 'FAILED'
2021-10-15T08:53:54.785Z INFO cmd/enroll_cmd.go:724 Fleet Server - Error - x509: cannot validate certificate for 172.20.0.2 because it doesn't contain any IP SANs
2021-10-15T08:54:00.792Z INFO cmd/enroll_cmd.go:729 Fleet Server - Error - x509: cannot validate certificate for 172.20.0.2 because it doesn't contain any IP SANs

```

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 9:00am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/8 "2021-10-15T09:00:09Z")

</div>

If I try with the container name, I get:

```auto
2021-10-15T08:59:23.817Z ERROR log/reporter.go:36 2021-10-15T08:59:23Z - message: Application: fleet-server--7.15.0[]: State changed to FAILED: Error - x509: certificate is not valid for any names, but wanted to match elasticsearch03 - type: 'ERROR' - sub_type: 'FAILED'
2021-10-15T08:59:23.932Z INFO cmd/enroll_cmd.go:724 Fleet Server - Error - x509: certificate is not valid for any names, but wanted to match elasticsearch03

```

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 9:07am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/9 "2021-10-15T09:07:47Z")

</div>

> [@Greg\_R](#):
>
> ```auto
> - FLEET_SERVER_INSECURE_HTTP=true
> 
> ```

Why not leave the server as https and connect the agent using the insecure flag.

Anyway, the ip addresses you are using dont match what are in your certificate.

What certificates are you using ?

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 9:20am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/10 "2021-10-15T09:20:16Z")

</div>

> Why not leave the server as https and connect the agent using the insecure flag.

how can I do that?

> What certificates are you using ?

None, I didn't understand how to do that, furthermore I don't want encryption since the connection is encrypted already 🙂 (and in this case it's local)

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 9:26am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/11 "2021-10-15T09:26:29Z")

</div>

> [@zx8086](#):
>
> > [@Greg\_R](#):
> >
> > ````auto
> > > - FLEET_SERVER_INSECURE_HTTP=true
> > > ```
> > 
> > ````

set it to false or remove it so it is set to the default vale.

If you don't specify your own certificates, fleet will generates it owns which is why it runs over the https protocol. Either it uses its own or you provide them.

> **[Troubleshoot common problems | Fleet and Elastic Agent Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-troubleshooting.html#agent-enrollment-certs)**

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 15, 2021, 9:39am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/12 "2021-10-15T09:39:18Z")

</div>

Yes I tried to add it because I couldn't make it work, but it's not working. Without this line, the error is:

```auto
x509: cannot validate certificate for 172.20.0.2 because it doesn't contain any IP SANs 

```

I wanted a way to prevent the agent from validating the certificate of ES (which I know nothing about).

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 10:10am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/13 "2021-10-15T10:10:04Z")

</div>

It will work with the default setup, using the self-signed certificates, so you don't have to know anything about the certificates.

> To ensure that communication with Fleet Server is encrypted, Fleet Server requires Elastic Agents to present a signed certificate. In a self-managed cluster, if you don’t specify certificates when you set up Fleet Server, self-signed certificates are generated automatically.

---

<div class="post-metadata">

**Author:** ![Greg\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/greg_r/32/92845_2.png) [@Greg\_R](https://discuss.elastic.co/u/Greg_R)\
**Post date:** [October 19, 2021, 9:03am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/14 "2021-10-19T09:03:08Z")

</div>

Great, so how can I make the magic happen? 😄 -D

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2021, 11:03am UTC](https://discuss.elastic.co/t/elastic-agent-install-f/286753/15 "2021-11-16T11:03:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
