# Elasticsearch cloud ignoring bucket permissions

**URL:** <https://discuss.elastic.co/t/elasticsearch-cloud-ignoring-bucket-permissions/293406>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** snapshot-and-restore\
**Created:** [January 4, 2022, 6:16am UTC](https://discuss.elastic.co/t/elasticsearch-cloud-ignoring-bucket-permissions/293406 "2022-01-04T06:16:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![epfcgs](https://avatars.discourse-cdn.com/v4/letter/e/edb3f5/32.png) [@epfcgs](https://discuss.elastic.co/u/epfcgs)\
**Post date:** [January 4, 2022, 6:16am UTC](https://discuss.elastic.co/t/elasticsearch-cloud-ignoring-bucket-permissions/293406/1 "2022-01-04T06:16:06Z")

</div>

I have created an elasticsearch cluster according to:

> **[Migrate workloads to GKE  |  Google Kubernetes Engine (GKE)...](https://cloud.google.com/kubernetes-engine/docs/concepts/migrate-workloads)**
>
> Learn how to migrate workloads to GKE.

using the following yaml

```auto
cat << 'EOF' > ~/eck.yaml
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
 name: quickstart
spec:
 version: 7.6.1
 secureSettings:
 - secretName: gcs-credentials
 nodeSets:
 - name: default
   count: 3
   config:
     node.master: true
     node.data: true
     node.ingest: true
     node.store.allow_mmap: false
   podTemplate:
     spec:
       initContainers:
       - name: install-plugins
         env:
           - name: ES_PATH_CONF
             value: /etc/elasticsearch
         command:
         - sh
         - -c
         - |
           bin/elasticsearch-plugin install --batch repository-gcs ingest-attachment
---
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
 name: kibana-sample
spec:
 version: 7.6.1
 count: 1
 elasticsearchRef:
   name: quickstart
---
apiVersion: apm.k8s.elastic.co/v1
kind: ApmServer
metadata:
 name: apm-server-sample
spec:
 version: 7.6.1
 count: 1
 elasticsearchRef:
   name: quickstart
EOF

kubectl apply -f eck.yaml

```

the service account has storage admin access on the bucket to read and write but i get the following error when creating a snapshot using google cloud storage, client: default, bucket :ecksnapshotraindrop, cannot verify

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "blob_store_exception",
        "reason": "Unable to check if bucket [ecksnapshotraindrop] exists"
      }
    ],
    "type": "repository_exception",
    "reason": "[examplerepo] cannot create blob store",
    "caused_by": {
      "type": "blob_store_exception",
      "reason": "Unable to check if bucket [ecksnapshotraindrop] exists",
      "caused_by": {
        "type": "access_control_exception",
        "reason": "access denied (\"java.lang.RuntimePermission\" \"accessDeclaredMembers\")"
      }
    }
  },
  "status": 500
}

```

according to:

> [@Elastic snapshot for GCS seem to be ignoring my client credentials](https://discuss.elastic.co/t/elastic-snapshot-for-gcs-seem-to-be-ignoring-my-client-credentials/217526):
>
> Hi, I've exhausted my google-fu and have trawled the documentation and similar issues discussed in these support and am completely stuck. I'm attempting to snapshot my cluster to GCS, and the system seems to be ignoring my credentials. elastic version: "version" : { "number" : "7.5.2", "build\_flavor" : "default", "build\_type" : "deb", "build\_hash" : "8bec50e1e0ad29dad5653712cf3bb580cd1afcdf", "build\_date" : "2020-01-15T12:11:52.313576Z", "build\_snapshot" : false, …

I must set ES\_PATH\_CONF to /etc/elasticsearch  
I attempted to set this in the container spec above, but it did not work. How do I set ES\_PATH\_CONF in gcloud?

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [January 6, 2022, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-ignoring-bucket-permissions/293406/2 "2022-01-06T13:54:15Z")

</div>

> [@epfcgs](#):
>
> I must set ES\_PATH\_CONF to /etc/Elasticsearch

This is not required. The steps described [here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-snapshots.html#k8s-secure-settings) should help you to use GCS for you snapshots.  
I would double check that the GCP service account has the relevant permissions to access the bucket and also check the content of `gcs.client.default.credentials_file` in the `gcs-credentials` `Secret` .

See also my answer [here](https://github.com/elastic/cloud-on-k8s/issues/5230#issuecomment-1005712536) if you want to try to rely on Workload Identity.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2022, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-ignoring-bucket-permissions/293406/3 "2022-02-03T13:54:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
