# How to add basic user/pass authentication to elastic.yaml

**URL:** <https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 4, 2020, 2:21pm UTC](https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662 "2020-12-04T14:21:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![yattaes](https://avatars.discourse-cdn.com/v4/letter/y/b9e5f3/32.png) [@yattaes](https://discuss.elastic.co/u/yattaes)\
**Post date:** [December 4, 2020, 2:21pm UTC](https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662/1 "2020-12-04T14:21:31Z")

</div>

Hi,  
I am using the yaml file below to deploy ElasticSearch to Azure Kubernetes.

I can reach the Elasticsearch with port forwarding "localhost:9200" without authentication.  
How can I add a basic user/pass authentication in this file? I would be appreciated if you provide a code sample

Thanks!

```
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: elastic
spec:
  http:
    service:
      metadata:
        annotations:
          service.beta.kubernetes.io/azure-load-balancer-internal: "true"
      spec:
        loadbalancerIP: 10.10.10.10
        type: LoadBalancer
    tls:
      selfSignedCertificate:
        disabled: true
        subjectAltNames:
        - ip: 10.10.10.10
  nodeSets:
  - config:
      node.data: true
      node.ingest: false
      node.master: true
      node.ml: false
      node.store.allow_mmap: false
      xpack.security.authc:
        anonymous:
          authz_exception: true
          roles: superuser
          username: anonymous
    count: 1
    name: masters
    podTemplate:
      metadata: {}
      spec:
        containers:
        - env:
          - name: ES_JAVA_OPTS
            value: -Xms150m -Xmx150m
          name: elasticsearch
          resources:
            limits:
              memory: 3Gi
    volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 10Gi
        storageClassName: elastic-storageclass
  - config:
      indices.memory.index_buffer_size: 40%
      node.data: true
      node.ingest: true
      node.master: false
      node.ml: true
      node.store.allow_mmap: false
      xpack.security.authc:
        anonymous:
          authz_exception: false
          roles: superuser
          username: anonymous
    count: 1
    name: data
    podTemplate:
      metadata: {}
      spec:
        containers:
        - env:
          - name: ES_JAVA_OPTS
            value: -Xms150m -Xmx150m
          name: elasticsearch
          resources:
            limits:
              memory: 3Gi
    volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 10Gi
        storageClassName: elastic-storageclass
  version: 7.5.1
---
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
  name: elastic-storageclass
parameters:
  kind: Managed
  storageaccounttype: Premium_LRS
provisioner: kubernetes.io/azure-disk
reclaimPolicy: Retain
volumeBindingMode: Immediate
```

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [December 6, 2020, 5:53pm UTC](https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662/2 "2020-12-06T17:53:51Z")

</div>

You need to:

1. Enable security with `xpack.security.enabled: true`
2. Configure a [security realm](https://www.elastic.co/guide/en/elasticsearch/reference/master/realms.html)
3. Probably also remove the `anonymous` configuration (otherwise any unauthenticated request will be accepted as `superuser` role)

Read [configuring security Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/master/configuring-security.html) for more information.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 7, 2020, 1:07am UTC](https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662/3 "2020-12-07T01:07:03Z")

</div>

If you are using the Elastic provided K8s operator ("ECK") as it appears you are, then you should have authentication enabled by default.

> **[Security | Elastic Cloud on Kubernetes \[1.3\] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/1.3/k8s-security.html)**

> [@yattaes](#):
>
> I can reach the Elasticsearch with port forwarding "localhost:9200" without authentication.

What response do you get at that endpoint?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2021, 1:07am UTC](https://discuss.elastic.co/t/how-to-add-basic-user-pass-authentication-to-elastic-yaml/257662/4 "2021-01-04T01:07:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
