# Getting plugins behind a proxy

**URL:** <https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997>\
**Category:** Elasticsearch\
**Created:** [May 20, 2015, 4:55pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997 "2015-05-20T16:55:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jim\_h](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jim\_h](https://discuss.elastic.co/u/jim_h)\
**Post date:** [May 20, 2015, 4:55pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/1 "2015-05-20T16:55:40Z")

</div>

The current model of running "plugin -i" is not going to work well in organizations that are leery about changes directly from the Internet.

Please consider making everything available as a static download with some form of validation (hash values, public key signatures, etc.) so that environments where servers do not (and should never) have access to the Internet can get the deployments after sufficient testing by the user.

Thanks!

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 20, 2015, 5:12pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/2 "2015-05-20T17:12:41Z")

</div>

I'm not sure there is much point to this. We're one of those organizations  
that doesn't allow internet access from the production cluster and we  
_also_ have a standard mechanism for deploying blobs like the plugin jars.  
I guess I'm saying that many organizations which doesn't allow internet  
access from the cluster are already going to have a blob deployment setup  
anyway and will want to use that instead of the Elasticsearch plugin  
installer.

That's just my suspicion given my experience though.

---

<div class="post-metadata">

**Author:** ![jim\_h](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jim\_h](https://discuss.elastic.co/u/jim_h)\
**Post date:** [May 20, 2015, 5:19pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/3 "2015-05-20T17:19:02Z")

</div>

Hmmm - I think I am asking for the same thing. I want to be able to download the code as a file (blob, tgz, zip, whatever) and validate that Elastic created it (somehow).  
Then test it in a non-prod environment and finally push it to prod.

While most elasticsearch plugins are available this way, not all are and even the ones that are are often quite hard to find.

I'm just asking that all available files be offered as easily available downloads somewhere.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 20, 2015, 5:27pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/4 "2015-05-20T17:27:30Z")

</div>

Plugin manager supports --url option which might help in that case.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 20, 2015, 5:37pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/5 "2015-05-20T17:37:22Z")

</div>

Ah! I get it, yeah. We do this all the time, but its true that there isn't  
a single place where the plugins live.

For the most part we get plugins from maven central and we just validate  
the checksums there before we push them to prod using our own proxy system.

If you run the installer in verbose mode you should be able to see where it  
gets the file. Normally those places have some way to recheck the checksums.

Do you think Elasticsearch should have something else?

---

<div class="post-metadata">

**Author:** ![jim\_h](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jim\_h](https://discuss.elastic.co/u/jim_h)\
**Post date:** [May 20, 2015, 6:14pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/6 "2015-05-20T18:14:47Z")

</div>

OK - couple things:

1. If the location of plugin download files (with checksums or sigs) were more easily found on the site, that would help a lot.

2. I know about how to install with "plugin -url" _once_ I have the file (but thanks)

3. If I use "plugin -v" I need to run it with the permissions that could write to the directory and then hit Ctrl-C _really_ fast so I don't actually write anything.

Would it be possible to add a "-n" option that says "don't actually do this, just tell me what you would do"?  
So:  
plugin -inv would output  
-\> Installing elasticsearch/  
Trying [http://download.elasticsearch.org/elasticsearch/](http://download.elasticsearch.org/elasticsearch/).zip...  
Quitting - as you told me not to actually _do_ anything

Or maybe a "-d" option that would "Download only" the file to (say) the current directory ?

Just thoughts,  
Jim

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [May 20, 2015, 6:32pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/7 "2015-05-20T18:32:24Z")

</div>

+1 for -d

I usually run it on my laptop and let it fetch the files so a -n option  
isn't a big deal for me. But -d would dovetail nicely with --url.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 20, 2015, 6:37pm UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/8 "2015-05-20T18:37:22Z")

</div>

Lot of things are going to change for the plug manager. [https://github.com/elastic/elasticsearch/pull/9998](https://github.com/elastic/elasticsearch/pull/9998) [https://github.com/elastic/elasticsearch/pull/9998](https://github.com/elastic/elasticsearch/pull/9998)

It might open the road from other changes as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:12am UTC](https://discuss.elastic.co/t/getting-plugins-behind-a-proxy/997/9 "2017-07-06T00:12:57Z")

</div>


