# ESrally with dedicated master

**URL:** <https://discuss.elastic.co/t/esrally-with-dedicated-master/225961>\
**Category:** Elasticsearch\
**Tags:** rally\
**Created:** [April 1, 2020, 12:35am UTC](https://discuss.elastic.co/t/esrally-with-dedicated-master/225961 "2020-04-01T00:35:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kinlee](https://avatars.discourse-cdn.com/v4/letter/k/838e76/32.png) [@kinlee](https://discuss.elastic.co/u/kinlee)\
**Post date:** [April 1, 2020, 12:35am UTC](https://discuss.elastic.co/t/esrally-with-dedicated-master/225961/1 "2020-04-01T00:35:45Z")

</div>

I have a cluster with three nodes and three dedicated masters. I want to run esrally

esrally --track=pmc --target-hosts=(node address 1):9200,(node address 2):9200,(node address3) --pipeline=benchmark-only --client options="use\_ssl:true,verify\_certs:false,basic\_auth\_user:'admin',basic\_auth\_password:'admin'

where do I put the IP address of the dedicated master???? is it in continuation with node IP address?

second is I have 3 nodes and 3 dedicated masters with security enabled

esrally --track=pmc --target-hosts=(node address 1):9200,(node address 2):9200,(node address3) --pipeline=benchmark-only --client  
options="use\_ssl:true,verify\_certs:true,basic\_auth\_user:'admin',basic\_auth\_password:'admin'

Do I have to provide a certificate instead of username and password.????

---

<div class="post-metadata">

**Author:** ![dliappis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dliappis/32/56174_2.png) [@dliappis](https://discuss.elastic.co/u/dliappis)\
**Post date:** [April 1, 2020, 7:13am UTC](https://discuss.elastic.co/t/esrally-with-dedicated-master/225961/2 "2020-04-01T07:13:03Z")

</div>

> [@kinlee](#):
>
> where do I put the IP address of the dedicated master???? is it in continuation with node IP address?

Rally should target the same nodes that the actual clients would target in a production scenario; we are benchmarking to simulate real-world scenarios and gather performance insights.

Are your master nodes, [dedicated master-eligible nodes](https://www.elastic.co/guide/en/elasticsearch/reference/master/modules-node.html#dedicated-master-node) (i.e. only have `node.master:true`)?

As mentioned in the [Elasticsearch documentation](https://www.elastic.co/guide/en/elasticsearch/reference/master/modules-node.html#dedicated-master-node) for dedicated master eligible nodes:

> Dedicated master-eligible nodes only have the `master` role, allowing them to focus on managing the cluster. While master nodes can also behave as [coordinating nodes](https://www.elastic.co/guide/en/elasticsearch/reference/master/modules-node.html#coordinating-node) and route search and indexing requests from clients to data nodes, it is better _not_ to use dedicated master nodes for this purpose.

So since you have three dedicated masters your target-hosts should target the other three nodes.

> [@kinlee](#):
>
> second is I have 3 nodes and 3 dedicated masters with security enabled
> 
> esrally --track=pmc --target-hosts=(node address 1):9200,(node address 2):9200,(node address3) --pipeline=benchmark-only --client  
> options="use\_ssl:true,verify\_certs:true,basic\_auth\_user:'admin',basic\_auth\_password:'admin'
> 
> Do I have to provide a certificate instead of username and password.????

You should first check how you've [configured security](https://www.elastic.co/guide/en/elasticsearch/reference/current/get-started-authentication.html) on Elasticearch. The [user authentication](https://www.elastic.co/guide/en/elasticsearch/reference/current/setting-up-authentication.html) Elasticsearch doc page is very helpful.

Depending on the realms you've configured (frequently it's just the `native` realm) you should attach your user credentials as per your example.

Regarding specifying the certificate itself, this depends on whether the Elasticsearch certificate was generated with a Public or Private CA. Frequently a private CA is used, in which case you'll need to present the ca certs by specifying `ca_certs:<path_to_pem_file>`, see the example under "Enable SSL, verify server certificates using private CA" in the [Rally docs](https://esrally.readthedocs.io/en/stable/command_line_reference.html#client-options) under TLS/SSL Examples.

I highly recommend reading the TLS/SSL section in the [Rally docs](https://esrally.readthedocs.io/en/stable/command_line_reference.html#client-options).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 7:13am UTC](https://discuss.elastic.co/t/esrally-with-dedicated-master/225961/3 "2020-04-29T07:13:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
