# FORBIDDEN/12/index read-only / allow delete (api)\] : indexes are set to "read only mode"

**URL:** <https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843>\
**Category:** Elasticsearch\
**Created:** [August 12, 2019, 12:27pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843 "2019-08-12T12:27:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wadhah](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Post date:** [August 12, 2019, 12:27pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843/1 "2019-08-12T12:27:21Z")

</div>

Hello,

I have deployed ELK stack (version 7.2.0) on kubernetes, and everything was working just fine till I got this error " [FORBIDDEN/12/index read-only / allow delete (api)]]" while doing some stuff on kibana. What I understood is that when the disk availability reaches the 5% limits , elasticsearch will turn all the indexes to "read only mode".  
I fixed the issue using these curl commands:

- \*curl -XPUT -H "Content-Type: application/json" [http://localhost:9200/\_cluster/settings](http://localhost:9200/_cluster/settings) -d '{ "transient": { "cluster.routing.allocation.disk.threshold\_enabled": false } }'

\*\* curl -XPUT -H "Content-Type: application/json" [http://localhost:9200/\_all/\_settings](http://localhost:9200/_all/_settings) -d '{"index.blocks.read\_only\_allow\_delete": null}'

However at that time, only 80Gb were used out of possible 150Gb (disk availability at least 40%).  
So I was wondering how is that possible ?  
And is there a permanent solution to avoid this kind of conflict?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 12, 2019, 3:20pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843/2 "2019-08-12T15:20:25Z")

</div>

This is super hard to debug from remote. In general the actions you have taken (setting the read only setting back to `null`) are good. Not sure if you want to keep the disk threshold decider disabled.

The main task would be to figure out why the decider decided to set this read-only. If this happens again using the [allocation explain API](https://www.elastic.co/guide/en/elasticsearch/reference/7.3/cluster-allocation-explain.html) - make sure you include disk info and yes decisions here.

did you have monitoring enabled by any chance? How did you check for those 40%? It could be that some merge was being executed shortly before that, so that there was some peak (note, that the removal of that index setting still requires manual intervention).

--Alex

---

<div class="post-metadata">

**Author:** ![wadhah](https://avatars.discourse-cdn.com/v4/letter/w/bc8723/32.png) [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Post date:** [August 13, 2019, 3:02pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843/3 "2019-08-13T15:02:30Z")

</div>

Helloy

Thank you for the quick update I really appreciate it @spinscale.

Well, at first i was only setting the read only setting back to "null", however, after a short time, it's set to true again on its own. For that reason I had to disable the disk threshold decider.  
Furthermore, I am not sure how can I exploit the "allocation explain API" ??  
Finally, I was relying on "stack monitoring" on kibana to deduct that 40%, i also run some "GET" on the console to verify disk availability.

Looking forward to hearing back from you

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [August 26, 2019, 1:39pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843/4 "2019-08-26T13:39:25Z")

</div>

Elasticsearch logs some detailed messages when it puts this `read-only / allow delete` block in place, describing why it did so. You should check the logs to see why this is happening.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2019, 1:39pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api-indexes-are-set-to-read-only-mode/194843/5 "2019-09-23T13:39:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
