# Filebeat fails to start with add\_kubernetes\_metadata

**URL:** <https://discuss.elastic.co/t/filebeat-fails-to-start-with-add-kubernetes-metadata/188825>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 4, 2019, 3:09am UTC](https://discuss.elastic.co/t/filebeat-fails-to-start-with-add-kubernetes-metadata/188825 "2019-07-04T03:09:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adam\_Wong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adam_wong/32/49400_2.png) [@Adam\_Wong](https://discuss.elastic.co/u/Adam_Wong)\
**Post date:** [July 4, 2019, 3:09am UTC](https://discuss.elastic.co/t/filebeat-fails-to-start-with-add-kubernetes-metadata/188825/1 "2019-07-04T03:09:56Z")

</div>

When starting filebeat using add\_kubernetes\_metadata, the beat will report an error like this and stop:

```
2019-07-02T19:32:29.785+0800	INFO	instance/beat.go:279	Setup Beat: filebeat; Version: 7.0.0-alpha1
2019-07-02T19:32:29.785+0800	INFO	kubernetes/util.go:86	kubernetes: Using pod name filebeat-zzvs8 and namespace kube-system to discover kubernetes node
2019-07-02T19:32:31.253+0800	ERROR	kubernetes/util.go:90	kubernetes: Querying for pod failed with error: %!(EXTRA string=performing request: Get https://1.1.1.1:443/api/v1/namespaces/kube-system/pods/filebeat-zzvs8: x509: certificate signed by unknown authority)
2019-07-02T19:32:31.254+0800	INFO	kubernetes/watcher.go:180	kubernetes: Performing a resource sync for *v1.PodList
2019-07-02T19:32:31.711+0800	ERROR	kubernetes/watcher.go:183	kubernetes: Performing a resource sync err performing request: Get https://1.1.1.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0: x509: certificate signed by unknown authority for *v1.PodList
2019-07-02T19:32:31.711+0800	INFO	instance/beat.go:340	filebeat stopped.
2019-07-02T19:32:31.711+0800	ERROR	instance/beat.go:758	Exiting: error initializing publisher: error initializing processors: performing request: Get https://1.1.1.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0: x509: certificate signed by unknown authority
Exiting: error initializing publisher: error initializing processors: performing request: Get https://1.1.1.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0: x509: certificate signed by unknown authority

```

and add\_kubernetes\_metadata config is:

```
  - add_kubernetes_metadata:
    enabled: true
    in_cluster: true

```

this is the version I am using.But it works in another cluster.

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [July 8, 2019, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-fails-to-start-with-add-kubernetes-metadata/188825/2 "2019-07-08T13:11:20Z")

</div>

It looks like the problem isn't your filebeat config but rather your system's SSL config -- it doesn't recognize your kubernetes server as coming from a trusted source. Does your kubernetes setup perhaps use a self-signed certificate? [Here is a link](https://blog.confirm.ch/adding-a-new-trusted-certificate-authority/) on adding certificate authorities that shows a way to update it from kubernetes, you may want to compare your certificates with the cluster that works and import the root certificate from there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2019, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-fails-to-start-with-add-kubernetes-metadata/188825/3 "2019-08-05T13:11:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
