# How to disable security authentication in ECK?

**URL:** <https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** elastic-stack-security\
**Created:** [May 23, 2023, 12:48am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057 "2023-05-23T00:48:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Teresajw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teresajw/32/119937_2.png) [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Post date:** [May 23, 2023, 12:48am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/1 "2023-05-23T00:48:45Z")

</div>

**How to disable security authentication in ECK? 🥶**  
_When I was looking for how to disable security authentication in eck, I found this configuration in the official documentation_

**1. The following Elasticsearch settings are managed by ECK:**

- `cluster.name`
- `discovery.seed_hosts`
- `discovery.seed_providers`
- `discovery.zen.minimum_master_nodes` [7.0]Deprecated in 7.0.
- `cluster.initial_master_nodes` [7.0]Added in 7.0.
- `network.host`
- `network.publish_host`
- `path.data`
- `path.logs`
- `xpack.security.authc.reserved_realm.enabled`
- `xpack.security.enabled`
- `xpack.security.http.ssl.certificate`
- `xpack.security.http.ssl.enabled`
- `xpack.security.http.ssl.key`
- `xpack.security.transport.ssl.certificate`
- `xpack.security.transport.ssl.enabled`
- `xpack.security.transport.ssl.key`
- `xpack.security.transport.ssl.verification_mode`  
**[doc here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-reserved-settings.html)**

**2.So I do the following configuration**

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: quickstart
spec:
  version: 7.17.9
  nodeSets:
  - name: default
    count: 1
    config:
      xpack.security.enabled: false
      xpack.security.transport.ssl.enabled: false
volumeClaimTemplates:
    - metadata:
        name: elasticsearch-data
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 2Gi
        storageClassName: nfs-es

```

What is the reason why I kept reporting the following error when I created elasticsearch resource?

```auto
{"type": "server", "timestamp": "2023-05-23T00:36:57,255Z", "level": "INFO", "component": "o.e.i.g.GeoIpDownloader", "cluster.name": "quickstart", "node.name": "quickstart-es-default-0", "message": "successfully downloaded geoip database [GeoLite2-Country.mmdb]", "cluster.uuid": "fbWNprfOSvuig0cGqRH06A", "node.id": "9T-S0uFGQsSv8T37xON4yw" }
{"type": "server", "timestamp": "2023-05-23T00:36:57,531Z", "level": "INFO", "component": "o.e.i.g.DatabaseNodeService", "cluster.name": "quickstart", "node.name": "quickstart-es-default-0", "message": "successfully reloaded changed geoip database file [/tmp/elasticsearch-3503673210484512476/geoip-databases/9T-S0uFGQsSv8T37xON4yw/GeoLite2-Country.mmdb]", "cluster.uuid": "fbWNprfOSvuig0cGqRH06A", "node.id": "9T-S0uFGQsSv8T37xON4yw" }
{"type": "server", "timestamp": "2023-05-23T00:36:58,014Z", "level": "INFO", "component": "o.e.i.g.DatabaseNodeService", "cluster.name": "quickstart", "node.name": "quickstart-es-default-0", "message": "successfully reloaded changed geoip database file [/tmp/elasticsearch-3503673210484512476/geoip-databases/9T-S0uFGQsSv8T37xON4yw/GeoLite2-City.mmdb]", "cluster.uuid": "fbWNprfOSvuig0cGqRH06A", "node.id": "9T-S0uFGQsSv8T37xON4yw" }
{"timestamp": "2023-05-23T00:37:00+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:05+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:10+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:15+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:20+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:25+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:30+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:34+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:39+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:45+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:50+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:37:55+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:00+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:05+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:08+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:10+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:15+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:20+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:24+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:30+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:34+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:39+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:45+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:50+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:38:54+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:00+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:04+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:09+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:14+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:19+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:25+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:29+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:33+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:34+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:39+00:00", "message": "readiness probe failed", "curl_rc": "35"}
{"timestamp": "2023-05-23T00:39:44+00:00", "message": "readiness probe failed", "curl_rc": "35"}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 23, 2023, 1:27am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/2 "2023-05-23T01:27:22Z")

</div>

Hi @Teresajw  
EDIT: I do not think ECK supports running insecure.

@Sunile_Manjee (our resident ECK expert) and comments?

Of course, we will both ask why you want to run ECK insecure?

---

<div class="post-metadata">

**Author:** ![Teresajw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teresajw/32/119937_2.png) [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Post date:** [May 23, 2023, 1:48am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/3 "2023-05-23T01:48:06Z")

</div>

Thank you! I think it is more convenient to remove it from the internal test environment. I am also testing here and found that this parameter setting is not effective. May I ask whether eck does not support this parameter setting 😀

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 23, 2023, 2:02am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/4 "2023-05-23T02:02:04Z")

</div>

> [@Teresajw](#):
>
> xpack.security.enabled

As the docs say this setting is managed by ECK ... so no I do not think you can disable security, I pinged a friend who is more of an ECKspert 😉 that I am, let's see what he says.

I can tell you ECK by design, is intended to be secure.

---

<div class="post-metadata">

**Author:** ![Teresajw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teresajw/32/119937_2.png) [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Post date:** [May 23, 2023, 2:40am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/5 "2023-05-23T02:40:57Z")

</div>

I also thought configuration managed by eck was unchangeable, but the following sentence makes me think so again,Other configurations besides this configuration are supported 🤣 🤣 🤣，I changed it to enable security.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9dfcd1d074493025a8f081cf5563e3bb475dab2.png)

---

<div class="post-metadata">

**Author:** ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)\
**Post date:** [May 23, 2023, 3:59am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/6 "2023-05-23T03:59:42Z")

</div>

thanks @stephenb.

Running ECK secure shouldn't impact you (unless there is a super obvious reason why). The install is mostly transparent in terms of security so using the defaults shouldn't require you to do anything (ie bring your own certs, signed by ca, etc) special. Even you when you launch Kibana on ECK, it is automatically secured via self signed certs. You can BYO certs but the install of ECK is mostly a beautiful experience (I'm slightly biased)

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [May 23, 2023, 7:34am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/7 "2023-05-23T07:34:11Z")

</div>

> [@Teresajw](#):
>
> I also thought configuration managed by eck was unchangeable, but the following sentence makes me think so again

Maybe to clarify the wording in the documentation here:

- "setting is managed by ECK" means you cannot use any of these settings no matter what value you want to set
- "setting is not supported by ECK" means you cannot use the particular settings value listed here. This currently affects only one setting. Note that this means that only the `required` value for `client_authentication` is not supported when running on ECK. The other possible values which are in this case `none` and `optional` are supported.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2023, 7:34am UTC](https://discuss.elastic.co/t/how-to-disable-security-authentication-in-eck/334057/8 "2023-06-20T07:34:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
