# Elasticsearch Keystore not being created

**URL:** <https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [August 18, 2023, 5:55pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120 "2023-08-18T17:55:48Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 18, 2023, 5:55pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/1 "2023-08-18T17:55:48Z")

</div>

Hi there,  
So, I am trying to run a simple ES single-node cluster.  
Here is the Dockerfile:-

> FROM elasticsearch:8.7.0  
> COPY . . #this copies the start\_es.sh  
> ENTRYPOINT ["./start\_es.sh"]

The **start\_es.sh** contains nothing but the entrypoint `"bin/elasticsearch"` only.

But when I am running the following command:-

```auto
sudo docker run -it --pull=always --privileged -p 9200:9200 -p 9300:9300 -e discovery.type=single-node -e xpack.ml.enabled=false -e ES_JAVA_OPTS="-Xms1g -Xmx1g" -e ELASTIC_PASSWORD=elastic es_image:latest

```

The issue is, there is **no Elasticsearch keystore** created to store the password that i am setting explicitly. Instead it is ignoring the password that I am providing and creating a randomized password similar to what it creates when we run with just `xpack.security.enabled=true`.

But when i am running with the official ES images it does create the Elasticsearch keystore as expected like this:-

> Created elasticsearch keystore in /usr/share/elasticsearch/config/elasticsearch.keystore

I am doing nothing but just running the ES entrypoint from within a shell script and that's it.  
All other env variables are working fine but the elasticsearch keystore is not working.

Could someone please help me here to understand the problem or What I am doing wrong?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 18, 2023, 7:52pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/2 "2023-08-18T19:52:10Z")

</div>

Why do you want to provide your own startup script instead of using the default behavior?

If you really want to do it, have a look at this:

> <https://github.com/elastic/elasticsearch/blob/001fcfb931454d760dbccff9f4d1b8d113f8708c/distribution/docker/src/docker/bin/docker-entrypoint.sh#L4>

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 19, 2023, 4:14am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/3 "2023-08-19T04:14:52Z")

</div>

thanks for the response @dadoonet .  
Actually I want to set `vm.max_map_count=262144` and `max file descriptors` during the startup.  
Because I have some unavoidable limitation where I cannot set this value from the host VM itself.  
therefore I am trying to run a script like this in as an ENTRYPOINT in Dockerfile:-

For your reference here is the script.

> #!/bin/bash  
> new\_value=262144  
> #Check if running as root  
> if [[$(id -u) -ne 0]]; then  
> echo "This script must be run as root or with sudo."  
> exit 1  
> else  
> echo "vm.max\_map\_count = $new\_value" \>\> /etc/sysctl.conf  
> echo "elasticsearch - nofile 65535" \>\> /etc/security/limits.conf  
> sysctl -p  
> su -c "bin/elasticsearch" elasticsearch #running with elasticsearch user  
> fi

Kindly suggest if am doing something wrong here.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 19, 2023, 5:30am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/4 "2023-08-19T05:30:44Z")

</div>

I believe that this is covered in the documentation. See [Install Elasticsearch with Docker | Elasticsearch Guide [8.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-prod-prerequisites)

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 19, 2023, 6:25am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/5 "2023-08-19T06:25:51Z")

</div>

I don't think that covers it @dadoonet, the docs say how to set this up on the host but the OP can't do that for some reason and wants to set it in the Dockerfile instead.

The ENTRYPOINT script doesn't pass any arguments to `bin/elasticsearch`. If you want to pass command line arguments to Elasticsearch, you need to add them there.

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 19, 2023, 6:42am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/6 "2023-08-19T06:42:39Z")

</div>

thanks for the reply @DavidTurner !  
As suggested by @dadoonet , I am using the docker-entrypoint.sh script.  
As below where, I running 2 script from a 3rd script passed in entrypoint. like below:-

> #!/bin/bash  
> **#Run the script to set the kernel parameters with root priviledge**  
> ./set\_kernel\_parameters.sh  
> **#Run the docker-entrypoint.sh with elasticsearch user**  
> su -c "./docker-entrypoint.sh" elasticsearch

But here I am getting the following error:-

```auto
vm.max_map_count = 262144
./entrypoint.sh: line 44: elasticsearch-keystore: command not found

```

From above output it says, the kernel parameters are set successfully from _./set\_kernel\_parameters.sh_ but _docker-entrypoint.sh_ is having some issue.

I think we are very close to get this solved.  
Any help is appreciated!

thanks

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 19, 2023, 7:23am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/7 "2023-08-19T07:23:46Z")

</div>

Try using an absolute path instead, maybe `/usr/share/elasticsearch/bin/elasticsearch-keystore`?

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 19, 2023, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/8 "2023-08-19T09:00:08Z")

</div>

I substituted `elasticsearch-keystore` with `/usr/share/elasticsearch/bin/elasticsearch-keystore` in the docker-entrypoint.sh and it worked.

Thanks a lot @DavidTurner !

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 19, 2023, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/9 "2023-08-19T10:36:22Z")

</div>

Great. I opened [docker-entrypoint.sh uses a mix of absolute and relative/implied paths · Issue #98643 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/98643) to ask whether we consider that a bug or not.

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 19, 2023, 12:36pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/10 "2023-08-19T12:36:21Z")

</div>

hey @DavidTurner, Now I am getting this error:-

```auto
Created elasticsearch keystore in /usr/share/elasticsearch/config/elasticsearch.keystore

ERROR: Missing logging config file at /usr/share/elasticsearch/config/log4j2.properties

```

Path also matches from the _docker-entrypoint.sh_

What could be the issue here?

This is occurring when I am mounting my self signed certificates into `usr/share/elasticsearch/config`  
and but working fine when I am mounting them to `usr/share/elasticsearch/config/certificates`.

thanks in advance!

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 19, 2023, 7:35pm UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/11 "2023-08-19T19:35:57Z")

</div>

It says that the file it needs is missing, but unfortunately I don't know any more about this. I think you must not be creating your container image correctly.

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [August 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/12 "2023-08-20T04:30:08Z")

</div>

I have created a `"certificates"` directory in `/usr/sahre/elasticsearch/config/`. It is working fine now.  
Is this what you are referring to?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2023, 4:31am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120/13 "2023-09-17T04:31:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
