# ElasticSearch on Kubernetes, one master nod not discovered when xpack.security.transport.ssl.enabled=true

**URL:** <https://discuss.elastic.co/t/elasticsearch-on-kubernetes-one-master-nod-not-discovered-when-xpack-security-transport-ssl-enabled-true/244717>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 12, 2020, 1:05pm UTC](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-one-master-nod-not-discovered-when-xpack-security-transport-ssl-enabled-true/244717 "2020-08-12T13:05:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Uvais\_Ibrahim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/uvais_ibrahim/32/72968_2.png) [@Uvais\_Ibrahim](https://discuss.elastic.co/u/Uvais_Ibrahim)\
**Post date:** [August 12, 2020, 1:05pm UTC](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-one-master-nod-not-discovered-when-xpack-security-transport-ssl-enabled-true/244717/1 "2020-08-12T13:05:36Z")

</div>

I have deployed an elasticsearch in Kubernetes with 3 masters and 3 data nodes. All the pods are running.

```auto
NAME READY STATUS RESTARTS AGE
elasticsearch-master-v1-0 1/1 Running 0 29m
elasticsearch-master-v1-1 1/1 Running 0 29m
elasticsearch-master-v1-2 1/1 Running 0 29m

```

_Note: Now the replicaset for data-node deployment is set to 0._

Elasticsearch Version: 6.4.0

But when I had checked the node status through elasticsearch API, only two nodes are showing up.

API CALL: /\_cat/nodes?v

```auto
ip heap.percent ram.percent cpu load_1m load_5m load_15m node.role master name
192.188.158.230 2 38 27 0.35 0.21 0.15 m * elasticsearch-master-v1-1
192.188.119.232 2 38 19 0.55 0.26 0.17 m - elasticsearch-master-v1-0

```

It should show all the three master nodes above

Why the third node is not showing up here? The following are the relevant configuration in elasticsearch.yml file.

```auto
discovery:
      zen:
        ping.unicast.hosts: elasticsearch-discovery  
//This is the service I created for internode communication.
        minimum_master_nodes: 2

    xpack.ml.enabled: false
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: certificate
    xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12

```

**I noticed that, when in the above configuration `xpack.security.transport.ssl.enabled: false` on the same API call it showed all the three master nodes**

K8s Service yaml for inter node communication.

```auto
apiVersion: v1
kind: Service
metadata:
  labels:
    app: elasticsearch-master
  name: elasticsearch-discovery-master
spec:
  ports:
  - name: transport
    port: 9300
    protocol: TCP
    targetPort: 9300
  selector:
    app: elasticsearch-master
  type: ClusterIP

```

This is what the logs says from the third master node which is not discovered,

```auto
[2020-08-12T12:38:41,342][WARN][o.e.d.z.ZenDiscovery] [elasticsearch-master-v1-2] not enough master nodes discovered during pinging (found [[Candidate{node={elasticsearch-master-v1-2}{F8L_VgGuRKWxxjKcQzhfzg}{ZPk-SAFESX2UFsEcH6Q7Hw}{192.188.193.101}{192.188.193.101:9300}{xpack.installed=true}, clusterStateVersion=-1}]], but needed [2]), pinging again
[2020-08-12T12:38:50,616][WARN][o.e.d.z.ZenDiscovery] [elasticsearch-master-v1-2] not enough master nodes discovered during pinging (found [[Candidate{node={elasticsearch-master-v1-2}{F8L_VgGuRKWxxjKcQzhfzg}{ZPk-SAFESX2UFsEcH6Q7Hw}{192.188.193.101}{192.188.193.101:9300}{xpack.installed=true}, clusterStateVersion=-1}]], but needed [2]), pinging again
[2020-08-12T12:39:15,424][WARN][o.e.d.z.ZenDiscovery] [elasticsearch-master-v1-2] not enough master nodes discovered during pinging (found [[Candidate{node={elasticsearch-master-v1-2}{F8L_VgGuRKWxxjKcQzhfzg}{ZPk-SAFESX2UFsEcH6Q7Hw}{192.188.193.101}{192.188.193.101:9300}{xpack.installed=true}, clusterStateVersion=-1}]], but needed [2]), pinging again
[2020-08-12T12:39:18,425][WARN][o.e.d.z.ZenDiscovery] [elasticsearch-master-v1-2] not enough master nodes discovered during pinging (found [[Candidate{node={elasticsearch-master-v1-2}{F8L_VgGuRKWxxjKcQzhfzg}{ZPk-SAFESX2UFsEcH6Q7Hw}{192.188.193.101}{192.188.193.101:9300}{xpack.installed=true}, clusterStateVersion=-1}]], but needed [2]), pinging again

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2020, 1:05pm UTC](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-one-master-nod-not-discovered-when-xpack-security-transport-ssl-enabled-true/244717/2 "2020-09-09T13:05:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
