# Fleet server agent with ECK operator in OpenShift deploying error

**URL:** <https://discuss.elastic.co/t/fleet-server-agent-with-eck-operator-in-openshift-deploying-error/362694>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [July 8, 2024, 10:06am UTC](https://discuss.elastic.co/t/fleet-server-agent-with-eck-operator-in-openshift-deploying-error/362694 "2024-07-08T10:06:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohamedmahrous](https://avatars.discourse-cdn.com/v4/letter/m/b5ac83/32.png) [@mohamedmahrous](https://discuss.elastic.co/u/mohamedmahrous)\
**Post date:** [July 8, 2024, 10:06am UTC](https://discuss.elastic.co/t/fleet-server-agent-with-eck-operator-in-openshift-deploying-error/362694/1 "2024-07-08T10:06:35Z")

</div>

Error: preparing STATE\_PATH(/usr/share/elastic-agent/state) failed: mkdir /usr/share/elastic-agent/state/data: permission denied

I got this error while the deploying of fleet server using this configuration in manifest file:

```auto
deployment:
  podTemplate:
    metadata:
      creationTimestamp: null
    spec:
      automountServiceAccountToken: true
      containers:
          name: agent
          resources: {}
      securityContext:
        privileged: true
        runAsUser: 0

```

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [July 9, 2024, 8:41am UTC](https://discuss.elastic.co/t/fleet-server-agent-with-eck-operator-in-openshift-deploying-error/362694/2 "2024-07-09T08:41:05Z")

</div>

Hi,

Here is a response I got from a colleague:

> The `securityContext` looks good with `runAsUser: 0` and `privileged: true` . Maybe he missed the step to correctly configure the ServiceAccount used to deploy the Agent resource: [Grant host access permission to Elastic Agent | Elastic Cloud on Kubernetes [2.13] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-openshift-agent.html).

> About the second thing: this involves preparing the directory (in particular executing `chcon -Rt svirt_sandbox_file_t "${dir}"` ). It seems to me that this is only necessary if you want to deploy the agent as non-root, not the case here.  
> We tried to do something in the operator, see [Automatically adjust Elastic Agent hostPath permissions by naemono · Pull Request #6599 · elastic/cloud-on-k8s · GitHub](https://github.com/elastic/cloud-on-k8s/pull/6599#issuecomment-1513366543)  
> The PR showing the daemonSet: [https://github.com/elastic/cloud-on-k8s/pull/6700](https://github.com/elastic/cloud-on-k8s/pull/6700).

There could be something odd with your storage setup. Could you give more details of their cluster (version; storage; etc)?
