# Elasticsearch.yml automatically reloaded?

**URL:** <https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313>\
**Category:** Elasticsearch\
**Created:** [August 16, 2017, 7:40pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313 "2017-08-16T19:40:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkoothrappahli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkoothrappahli/32/31959_2.png) [@nkoothrappahli](https://discuss.elastic.co/u/nkoothrappahli)\
**Post date:** [August 16, 2017, 7:40pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/1 "2017-08-16T19:40:58Z")

</div>

Are changes done in elasticsearch.yml automatically applied to the respective node (in other words: Is elasticsearch.yml watched by the elasticsearch process and reloaded upon change?)

Wondering if i can change network, transport and http related options at runtime without node restart. I try to renew SSL certificates for xpack-security and it looks like i need to take down a node to update ssl certificates. In the case of a root certificate change this means i need to do a full cluster restart, right?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 16, 2017, 9:48pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/2 "2017-08-16T21:48:21Z")

</div>

No they are not.

Yes you do.

This is done to improve security.

---

<div class="post-metadata">

**Author:** ![nkoothrappahli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkoothrappahli/32/31959_2.png) [@nkoothrappahli](https://discuss.elastic.co/u/nkoothrappahli)\
**Post date:** [August 17, 2017, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/3 "2017-08-17T08:50:40Z")

</div>

what about adding the new root ca additively to the trusted CA in rolling restart manner, then update the nodes with new certificates also in rolling restart manner and optionally remove the old ca again in rolling restart manner. Would this work in the case of a root certificate change? I need to to avoid a full cluster restart cause we cannot have any downtime.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 17, 2017, 9:13am UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/4 "2017-08-17T09:13:22Z")

</div>

Not sure on that, is this in relation to X-Pack Security?

---

<div class="post-metadata">

**Author:** ![nkoothrappahli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nkoothrappahli/32/31959_2.png) [@nkoothrappahli](https://discuss.elastic.co/u/nkoothrappahli)\
**Post date:** [August 17, 2017, 6:01pm UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/5 "2017-08-17T18:01:21Z")

</div>

yes (evaluating x-pack security and search guard)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2017, 12:25am UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/6 "2017-08-18T00:25:58Z")

</div>

You'd be better off making a new thread in #x-pack to ask about that 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2017, 12:26am UTC](https://discuss.elastic.co/t/elasticsearch-yml-automatically-reloaded/97313/7 "2017-09-15T00:26:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
