# Fleet Server Deployment on kubernetes

**URL:** <https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [July 22, 2022, 1:48pm UTC](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408 "2022-07-22T13:48:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehran\_Hafizi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehran_hafizi/32/108711_2.png) [@Mehran\_Hafizi](https://discuss.elastic.co/u/Mehran_Hafizi)\
**Post date:** [July 22, 2022, 1:48pm UTC](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408/1 "2022-07-22T13:48:42Z")

</div>

Hello ,

I wanted to install Fleet server on the AKS cluster , but I got the following errror , would you please help me to solve this issue?

Error:  
`message: Application: fleet-server--7.17.0[]: State changed to FAILED: Error - x509: certificate is valid for elastic.dev.mydomain.com, not elasticsearch-es-http.default.svc - type: 'ERROR' - sub_type: 'FAILED'`

ELastic YAML :

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: elasticsearch
spec:
  secureSettings:
  - secretName: es-snapshot-secret #secret for repository
  version: 7.17.0
  nodeSets:
  - name: default
    count: 3
    config:
      # most Elasticsearch configuration parameters are possible to set, e.g: node.attr.attr_name: attr_value
      node.roles: ["master", "data", "ingest", "ml"]
      # this allows ES to run on nodes even if their vm.max_map_count has not been increased, at a performance cost
      node.store.allow_mmap: false
      path.repo: ["/"]
    podTemplate:
      metadata:
        labels:
          app: elasticsearch
      spec:
        initContainers:
        - name: sysctl
          securityContext:
            privileged: true
          command: ['sh', '-c', 'sysctl -w vm.max_map_count=262144']
        - name: install-plugin
          command:
          - sh
          - -c
          - |
            bin/elasticsearch-plugin install --batch repository-azure    
        - name: add-azure-keys
          env:
          - name: AZURE_ACCESS_ACCOUNT
            valueFrom:
              secretKeyRef:
                name: es-azure-snapshot-secret
                key: azure.client.default.account
          - name: AZURE_ACCESS_KEY
            valueFrom:
              secretKeyRef:
                name: es-azure-snapshot-secret
                key: azure.client.default.key  
          command:
          - sh
          - -c
          - |
            echo $AZURE_ACCESS_ACCOUNT | bin/elasticsearch-keystore add --stdin --force azure.client.default.account
            echo $AZURE_ACCESS_KEY | bin/elasticsearch-keystore add --stdin --force azure.client.default.key                            
    volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data # Do not change this name unless you set up a volume mount for the data path.
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 4Gi
  http:
    tls:
      certificate:
        secretName: elastic-tls           
---

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
    annotations:
        kubernetes.io/ingress.class: nginx
        cert-manager.io/issuer: "letsencrypt"
        ingress.kubernetes.io/force-ssl-redirect: "true"
        nginx.ingress.kubernetes.io/backend-protocol: HTTPS       
    name: elastic-ingress
    namespace: default
spec:
    rules:
        - host: elastic.dev.mydomain.com
          http:
              paths:
                  - path: /
                    pathType: Prefix
                    backend:
                        service:
                            name: elasticsearch-es-http
                            port:
                                number: 9200
    tls:
        - hosts:
              - elastic.dev.mydomain.com
          secretName: elastic-tls

```

Fleet Agent Yaml:

```auto

apiVersion: agent.k8s.elastic.co/v1alpha1
kind: Agent
metadata:
  name: fleet-agent

spec:
  version: 7.17.0
  elasticsearchRefs:
    - name: elasticsearch   
  mode: fleet
  fleetServerEnabled: true
  http:
    service:
      spec:
         type: ClusterIP
  daemonSet:
    podTemplate:
      spec:
        automountServiceAccountToken: true
        serviceAccountName: elastic-agent
        mode: fleet
---

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: elastic-agent
rules:
- apiGroups: [""] # "" indicates the core API group
  resources:
  - namespaces
  - pods
  - nodes
  - nodes/metrics
  - nodes/proxy
  - nodes/stats
  - events
  - configmaps
  - services
  - endpoints
  - deployments
  verbs:
  - get
  - watch
  - list
- nonResourceURLs:
  - /metrics
  verbs:
  - get
  - watch
  - list
- apiGroups: ["coordination.k8s.io"]
  #
  # at the HTTP level, the name of the resource for accessing Job
  # objects is "jobs"
  resources:
  - leases
  verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: elastic-agent
  namespace: default
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: elastic-agent
subjects:
- kind: ServiceAccount
  name: elastic-agent
  namespace: default
roleRef:
  kind: ClusterRole
  name: elastic-agent
  apiGroup: rbac.authorization.k8s.io

```

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [July 28, 2022, 10:10am UTC](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408/2 "2022-07-28T10:10:25Z")

</div>

Duplicate of [Cannot deploy Fleet Server with a secure elasticsearch on k8s · Issue #5888 · elastic/cloud-on-k8s · GitHub](https://github.com/elastic/cloud-on-k8s/issues/5888) where this was answered.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2022, 10:10am UTC](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408/3 "2022-08-25T10:10:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
