# Elasticsearch custom users with custom keys in existing Secret config

**URL:** <https://discuss.elastic.co/t/elasticsearch-custom-users-with-custom-keys-in-existing-secret-config/260950>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [January 13, 2021, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-custom-users-with-custom-keys-in-existing-secret-config/260950 "2021-01-13T08:15:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ismarslomic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismarslomic/32/63870_2.png) [@ismarslomic](https://discuss.elastic.co/u/ismarslomic)\
**Post date:** [January 13, 2021, 8:15am UTC](https://discuss.elastic.co/t/elasticsearch-custom-users-with-custom-keys-in-existing-secret-config/260950/1 "2021-01-13T08:15:27Z")

</div>

[File realm](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html#k8s_file_realm) doc provides example on how to define users and roles by **Secret** Kubernetes configuration with use of keys `users` and `users_roles` and referring to this with `spec.auth.fileRealm` from Elasticsearch configuration.

**Question** : we have centralized all our secrets in existing Kubernetes Secret (with standardized key naming) with automatic synchronization with AWS SSM. So I would like to avoid creating new Secret specifically for Elasticsearch. Does Elasticsearch configuration (`spec.auth.fileRealm`) support referring to secret _and_ keys?

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [January 13, 2021, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-custom-users-with-custom-keys-in-existing-secret-config/260950/2 "2021-01-13T08:50:58Z")

</div>

Hi,

Sorry, only `Secret` names are allowed in the `fileRealm` and `roles` fields.

In the case of the file realm it is not possible to use something else than the expected `users_roles` and `users` keys. I'm not sure what the spec would look like if we want to be more flexible tbh, do you have something specific in mind ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:21am UTC](https://discuss.elastic.co/t/elasticsearch-custom-users-with-custom-keys-in-existing-secret-config/260950/3 "2022-11-04T08:21:30Z")

</div>


