# Entitlements and tmpdir

**URL:** <https://discuss.elastic.co/t/entitlements-and-tmpdir/384627>\
**Category:** Elasticsearch\
**Created:** [January 19, 2026, 4:48pm UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627 "2026-01-19T16:48:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![frantz45](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@frantz45](https://discuss.elastic.co/u/frantz45)\
**Post date:** [January 19, 2026, 4:48pm UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627/1 "2026-01-19T16:48:18Z")

</div>

Hello,

I’ve just tried v8.19.10 and I get an issue with entitlements:

```auto
[2026-01-19T17:13:13,437][ERROR][o.e.b.Elasticsearch] [redacted] fatal exception while booting Elasticsearch
java.lang.IllegalArgumentException: policy for module [io.netty.common] in [repository-azure] has an invalid file entitlement. Any path under [/etc/elasticsearch] is forbidden for mode [READ_WRITE].
        at org.elasticsearch.entitlement.bootstrap.FilesEntitlementsValidation.buildValidationException(FilesEntitlementsValidation.java:63) ~[elasticsearch-entitlement-8.19.10.jar:?]
        at org.elasticsearch.entitlement.bootstrap.FilesEntitlementsValidation.validateWriteFilesEntitlements(FilesEntitlementsValidation.java:95) ~[elasticsearch-entitlement-8.19.10.jar:?]
        at org.elasticsearch.entitlement.bootstrap.FilesEntitlementsValidation.validate(FilesEntitlementsValidation.java:50) ~[elasticsearch-entitlement-8.19.10.jar:?]
        at org.elasticsearch.entitlement.bootstrap.EntitlementBootstrap.createPolicyManager(EntitlementBootstrap.java:169) ~[elasticsearch-entitlement-8.19.10.jar:?]
        at org.elasticsearch.entitlement.bootstrap.EntitlementBootstrap.bootstrap(EntitlementBootstrap.java:100) ~[elasticsearch-entitlement-8.19.10.jar:?]
        at org.elasticsearch.bootstrap.Elasticsearch.initPhase2(Elasticsearch.java:253) ~[elasticsearch-8.19.10.jar:?]
        at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:99) ~[elasticsearch-8.19.10.jar:?]

```

I’ve tried to apply the following patch:

```auto
versions:
  - 8.19.10
policy:
  io.netty.common:
    - files:
      - path: "/etc/elasticsearch"
        mode: read_write

```

(I then use “base64 -w0” to get the value to set in -Des.entitlements.policy.repository-azure=)

But I still get the error and the service doesn’t start.

I’ve understood why it tries to access /etc/elasticsearch, it’s because I use ES\_TMPDIR=/etc/elasticsearch and TMPDIR=/etc/elasticsearch. It’s because my /tmp partition is mounted with the noexec flag for security reasons.

Without these settings it works but I get the following error in logs:

```auto
systemd-entrypoint[34153]: Failed to load native library:jansi-2.4.0-63465bb7222bf8c0-libjansi.so. The native library file at /tmp/elasticsearch-17576746019114158548/jansi-2.4.0-63465bb7222bf8c0-libjansi.so is not executable, make sure that the directory is mounted on a partition without the noexec flag, or set the jansi.tmpdir system property to point to a proper location. osinfo: Linux/x86_64
systemd-entrypoint[34153]: java.lang.UnsatisfiedLinkError: /tmp/elasticsearch-17576746019114158548/jansi-2.4.0-63465bb7222bf8c0-libjansi.so: /tmp/elasticsearch-17576746019114158548/jansi-2.4.0-63465bb7222bf8c0-libjansi.so: échec d'adressage (mapping) du segment de l'objet partagé

```

So my question is how to use a tmpdir other than /tmp with entitlements ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 19, 2026, 6:27pm UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627/2 "2026-01-19T18:27:50Z")

</div>

> [@frantz45](#):
>
> So my question is how to use a tmpdir other than /tmp with entitlements ?

You need to create a directory with write permissions for the `elasticsearch` user and use it in the `ES_TMPDIR`, something like `/opt/tmp`, do not use `/etc/elasticsearch`.

---

<div class="post-metadata">

**Author:** ![frantz45](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@frantz45](https://discuss.elastic.co/u/frantz45)\
**Post date:** [January 20, 2026, 9:51am UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627/3 "2026-01-20T09:51:05Z")

</div>

/etc/elasticsearch was owned by elasticsearch and writable.

But anyway it works with /opt/tmp, thank you !

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 20, 2026, 11:39am UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627/4 "2026-01-20T11:39:23Z")

</div>

> [@frantz45](#):
>
> /etc/elasticsearch was owned by elasticsearch and writable.

Yeah, but you should not write any user data into `/etc`, not just for elasticsearch.

In Elasticsearch case there is a code validation for it.

---

<div class="post-metadata">

**Author:** ![frantz45](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@frantz45](https://discuss.elastic.co/u/frantz45)\
**Post date:** [January 20, 2026, 3:02pm UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627/5 "2026-01-20T15:02:29Z")

</div>

Ok thank you for the explanation
