# Exiting: error loading config file: config file ("/etc/apm-server/apm-server.yml") must be owned by the user identifier (uid=0) or root

**URL:** <https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824>\
**Category:** APM\
**Created:** [May 6, 2019, 5:32pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824 "2019-05-06T17:32:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![meiyuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meiyuan/32/44468_2.png) [@meiyuan](https://discuss.elastic.co/u/meiyuan)\
**Post date:** [May 6, 2019, 5:32pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/1 "2019-05-06T17:32:47Z")

</div>

**APM Server version** : 7.0.0.

**APM Agent language and version** : Node.js

**Original install method (e.g. download page, yum, deb, from source, etc.) and version**:  
[https://artifacts.elastic.co/downloads/apm-server/apm-server-7.0.0-x86\_64.rpm](https://artifacts.elastic.co/downloads/apm-server/apm-server-7.0.0-x86_64.rpm)

**Is there anything special in your setup?**  
We use ansible playbook to install and config APM;

```auto
// this would copy the apm-server.yml ot the right plalce
- name: Deploy /etc/apm-server/apm-server.yml config
  template: 
    src: apm-server.yml.j2
    dest: /etc/apm-server/apm-server.yml
  become: true
  
// We want to start the service, `become: true` means become `root` user
- name: Start APM-Server Service
  systemd:
    state: started
    name: apm-server.service
  become: true

```

**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:

```auto
[deploy@ip-192-168-0-141 ~]$ systemctl status apm-server
● apm-server.service - Elastic APM Server
   Loaded: loaded (/usr/lib/systemd/system/apm-server.service; disabled; vendor preset: disabled)
   Active: failed (Result: start-limit) since Thu 2019-05-02 21:23:57 UTC; 3 days ago
     Docs: https://www.elastic.co/solutions/apm
  Process: 5707 ExecStart=/usr/share/apm-server/bin/apm-server $BEAT_LOG_OPTS $BEAT_CONFIG_OPTS $BEAT_PATH_OPTS (code=exited, status=1/FAILURE)
 Main PID: 5707 (code=exited, status=1/FAILURE)

May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: apm-server.service: main process exited, code=exited, status=1/FAILURE
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: Unit apm-server.service entered failed state.
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: apm-server.service failed.
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: apm-server.service holdoff time over, scheduling restart.
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: start request repeated too quickly for apm-server.service
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: Failed to start Elastic APM Server.
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: Unit apm-server.service entered failed state.
May 02 21:23:57 ip-192-168-0-141.ec2.internal systemd[1]: apm-server.service failed.

```

**Provide logs and/or server output (if relevant)**:  
`Exiting: error loading config file: config file ("/etc/apm-server/apm-server.yml") must be owned by the user identifier (uid=0) or root`

**Other comments** :

1. The `/etc/apm-server/apm-server.yml` is owned by the `apm-server` user.
2. [https://github.com/elastic/apm-server/blob/6.3/\_beats/dev-tools/packer/platforms/debian/systemd.j2](https://github.com/elastic/apm-server/blob/6.3/_beats/dev-tools/packer/platforms/debian/systemd.j2)  
This is an old systemd file. I couldn't find the v7.0.0.  
How can I run this service with user `apm-server` without changing the file permission to `root`?

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [May 6, 2019, 6:58pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/2 "2019-05-06T18:58:31Z")

</div>

Hello @meiyuan, sorry to see you've run into [this issue](https://github.com/elastic/apm-server/issues/2096). This has been fixed in 7.0.1, please upgrade if possible.

If you are unable to upgrade, in 7.0.0 you can patch the service file adding `User` and `Group` to work around the problem.

---

<div class="post-metadata">

**Author:** ![meiyuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meiyuan/32/44468_2.png) [@meiyuan](https://discuss.elastic.co/u/meiyuan)\
**Post date:** [May 6, 2019, 9:30pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/3 "2019-05-06T21:30:35Z")

</div>

Hi Gil.  
Yeah, I updated it to 7.0.1 and I was able to pass that error.  
Just out of curiosity, how would I patch the service file? Because when the service fails to load, there is no file in `/etc/systemd/system`. Should I just create my own service file from scratch? Is there a template for us to use?

---

<div class="post-metadata">

**Author:** ![meiyuan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/meiyuan/32/44468_2.png) [@meiyuan](https://discuss.elastic.co/u/meiyuan)\
**Post date:** [May 6, 2019, 9:36pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/4 "2019-05-06T21:36:28Z")

</div>

I read your comment in that git issue. Still not very clear on how we would patch it since there is no such file.  
Thank you very much.

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [May 7, 2019, 3:38pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/5 "2019-05-07T15:38:25Z")

</div>

The file to patch is `/usr/lib/systemd/system/apm-server.service`, that should be created when installing the rpm. This should do the job:

```auto
sudo patch /usr/lib/systemd/system/apm-server.service << EOF
--- apm-server.service.orig 0000-00-00 00:00:00.000000000 +0000
+++ apm-server.service0000-00-00 00:00:00.000000000 +0000
@@ -5,6 +5,8 @@
 After=network-online.target
 
 [Service]
+User=apm-server
+Group=apm-server
 Environment="BEAT_LOG_OPTS=-e"
 Environment="BEAT_CONFIG_OPTS=-c /etc/apm-server/apm-server.yml"
 Environment="BEAT_PATH_OPTS=-path.home /usr/share/apm-server -path.config /etc/apm-server -path.data /var/lib/apm-server -path.logs /var/log/apm-server"
EOF

# reload
sudo systemctl daemon-reload

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2019, 11:38am UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-config-file-etc-apm-server-apm-server-yml-must-be-owned-by-the-user-identifier-uid-0-or-root/179824/6 "2019-05-28T11:38:27Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
