# Elastic Agent on ECK with Fleet - How to provide an enrollment token within the CRD, so that Agents use the correct policy on startup?

**URL:** <https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** fleet\
**Created:** [October 21, 2021, 11:42pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372 "2021-10-21T23:42:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [October 21, 2021, 11:42pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372/1 "2021-10-21T23:42:46Z")

</div>

Hi all,

I was wondering if it's possible/how to set the policy that an Elastic Agent on ECK uses when managed by fleet? I wasn't able to find anything in the [ECK Elastic Agent Fleet](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet.html) docs that mentioned how to set the `enrollment token` of the policy I want the agent to use.

---

<div class="post-metadata">

**Author:** ![dkow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkow/32/47340_2.png) [@dkow](https://discuss.elastic.co/u/dkow)\
**Post date:** [October 26, 2021, 5:59am UTC](https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372/2 "2021-10-26T05:59:29Z")

</div>

Hi @BenB196, thanks for your question.

For this we defer to Elastic Agent [docs](https://www.elastic.co/guide/en/fleet/current/agent-environment-variables.html), but it is definitely possible. Just set `FLEET_ENROLLMENT_TOKEN` env variable to your token in the `agent` container of Elastic Agent, similar to below.

```auto
apiVersion: agent.k8s.elastic.co/v1alpha1
kind: Agent
metadata: 
  name: elastic-agent
spec:
  version: 7.14.0
  kibanaRef:
    name: kibana
  fleetServerRef: 
    name: fleet-server
  mode: fleet
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: elastic-agent
        hostNetwork: true
        dnsPolicy: ClusterFirstWithHostNet
        automountServiceAccountToken: true
        securityContext:
          runAsUser: 0
        containers:
        - name: agent
          env:
          - name: FLEET_ENROLLMENT_TOKEN
            value: MDdVcHUzd0JqR2pzREhXRGRMT3U6VlRXQlNmZHJRXy0wR1BWZ05JeFdGUQ==

```

This assumes you have other resources set as in the [System and Kubernetes integrations configuration example](https://raw.githubusercontent.com/elastic/cloud-on-k8s/1.8/config/recipes/elastic-agent/fleet-kubernetes-integration.yaml).

Let me know if you have any other questions on this.

Thanks,  
David

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [October 26, 2021, 11:42am UTC](https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372/3 "2021-10-26T11:42:52Z")

</div>

Ahh, thanks @dkow I didn't even think about looking there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2021, 11:43am UTC](https://discuss.elastic.co/t/elastic-agent-on-eck-with-fleet-how-to-provide-an-enrollment-token-within-the-crd-so-that-agents-use-the-correct-policy-on-startup/287372/4 "2021-11-23T11:43:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
