# How to get ECK APM to work with any type of agent at all!?!

**URL:** <https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429>\
**Category:** APM\
**Tags:** docker, nodejs, server\
**Created:** [August 23, 2023, 6:14am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429 "2023-08-23T06:14:59Z")\
**Posts on this page:** 9\
**Page:** 2

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [August 31, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/22 "2023-08-31T06:58:38Z")

</div>

They do match what? Which secret are they copied from?

---

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [August 31, 2023, 6:59am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/23 "2023-08-31T06:59:53Z")

</div>

Wait. Just found out the tls.crt is empty. It works now. I will check if env is still needed. It doesn't make sense at all because all of these env are configurable at the elastic-node-apm settings. Will update.

---

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [August 31, 2023, 7:01am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/24 "2023-08-31T07:01:38Z")

</div>

One more thing. Can you please confirm if BOTH `ELASTIC_APM_SECRET_TOKEN` and `ELASTIC_APM_SERVER_CA_CERT_FILE` are needed? My impression, based on our past communication, is that only either one of them is needed?

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [August 31, 2023, 7:02am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/25 "2023-08-31T07:02:15Z")

</div>

They are both required. `ELASTIC_APM_SERVER_URL` is the address of the APM Server, `ELASTIC_APM_SECRET_TOKEN` is an auth token.

---

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [August 31, 2023, 7:03am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/26 "2023-08-31T07:03:16Z")

</div>

I meant `ELASTIC_APM_SERVER_CA_CERT_FILE`. Are both this and the `ELASTIC_APM_SECRET_TOKEN` needed at the same time?

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [August 31, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/27 "2023-08-31T07:05:04Z")

</div>

Right. Yes those are both required too.

`ELASTIC_APM_SERVER_CA_CERT_FILE` is for verifying the server's TLS certificate. That's so the client can confirm that it is communicating with the correct server. `ELASTIC_APM_SECRET_TOKEN` is so the server knows the client is authorized to send data.

---

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [August 31, 2023, 7:23am UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/28 "2023-08-31T07:23:40Z")

</div>

> <https://github.com/elastic/apm-agent-nodejs/issues/3598>
>
> \*\*Describe the bug\*\*
> Having these options in the configuration of your library …does NOT work at all! We still have to define the env \`ELASTIC\_APM\_SECRET\_TOKEN\` and \`ELASTIC\_APM\_SERVER\_URL\` in our pod spec!
> 
> 
> 
> \*\*To Reproduce\*\*
> 
> Steps to reproduce the behavior: 
> 1. Use this config '...'
> 2. Then call '....'
> 3. Then do '....'
> 4. See error
> 
> \*\*Expected behavior\*\*
> 
> 
> 
> \*\*Environment (please complete the following information)\*\*
> 
> \- OS: \[e.g. Linux\] Ubuntu 23.04
> \- Node.js version: 
> \- APM Server version:
> \- Agent version:
> 
> \*\*How are you starting the agent? (please tick one of the boxes)\*\*
> 
> \- \[x\] Calling \`agent.start()\` directly (e.g. \`require('elastic-apm-node').start(...)\`)
> \- \[\] Requiring \`elastic-apm-node/start\` from within the source code
> \- \[\] Starting node with \`-r elastic-apm-node/start\`
> 
> \*\*Additional context\*\*
> 
> 
> 
> Agent config options: 
> \<details\>
> \<summary\>Click to expand\</summary\>
> 
> \`\`\`
> var apm = require('elastic-apm-node').start({
> // Override service name from package.json
> // Allowed characters: a-z, A-Z, 0-9, -, \_, and space
> serviceName: 'my-apm',
> secretToken: process.env.ELASTIC\_APM\_SECRET\_TOKEN,
> // Set custom APM Server URL (default: http://127.0.0.1:8200)
> serverUrl: 'https://my-apm-http:8200',
> // Only activate the agent if it's running in production
> active: process.env.NODE\_ENV === 'production',
> // verifyServerCert: false,
> serverCaCertFile: '/etc/ca-certificates/tls.crt',
> \`\`\`
> \</details\>
> 
> \`package.json\` dependencies:
> \<details\>
> \<summary\>Click to expand\</summary\>
> 
> \`\`\`
> replace this line with your dependencies section from package.json
> \`\`\`
> \</details\>

---

<div class="post-metadata">

**Author:** ![weekstonz](https://avatars.discourse-cdn.com/v4/letter/w/4da419/32.png) [@weekstonz](https://discuss.elastic.co/u/weekstonz)\
**Post date:** [September 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/29 "2023-09-02T16:01:08Z")

</div>

I'm not a Node.js expert, but I think that the system CA certificates are not used by default. The agent docs seem to suggest that bundled Mozilla CA certs are used by default.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429/30 "2023-09-30T16:01:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/how-to-get-eck-apm-to-work-with-any-type-of-agent-at-all/341429.md?page=1)
