# How to set up 3 dedicate master + 4 data nodes also master elegible

**URL:** <https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887>\
**Category:** Elasticsearch\
**Created:** [July 20, 2023, 1:44pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887 "2023-07-20T13:44:34Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 20, 2023, 1:44pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/1 "2023-07-20T13:44:34Z")

</div>

i need to set up 3 master node dedicate and 4 data node and master elegibles  
this is my yml configuration

```auto
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
bootstrap.memory_lock: true

cluster.name: Cluster-Lab
node.name: master1
node.roles: [master]
network.host: ['192.168.100.84']
http.port: 9200

cluster.initial_master_nodes: ['192.168.100.84', '192.168.100.82', '192.168.100.81']
discovery.seed_hosts: ['192.168.100.84', '192.168.100.82', '192.168.100.81']

# security settings
xpack.security.enabled: true
xpack.security.autoconfiguration.enabled: false
# transport ssl
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.key: certs/master1/master1.key
xpack.security.transport.ssl.certificate: certs/master1/master1.crt
xpack.security.transport.ssl.certificate_authorities: certs/ca/ca.crt
## http ssl
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.key: certs/master1/master1.key
xpack.security.http.ssl.certificate: certs/master1/master1.crt
xpack.security.http.ssl.certificate_authorities: certs/ca/ca.crt

```

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 20, 2023, 2:30pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/2 "2023-07-20T14:30:19Z")

</div>

I'm not sure if there is a way to force one of your dedicated masters to be the active master instead of one of the four data/master eligible nodes.

Try it, tell us what happens.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 20, 2023, 3:15pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/3 "2023-07-20T15:15:50Z")

</div>

> [@hlcxpl](#):
>
> i need to set up 3 master node dedicate and 4 data node and master elegibles

Any reason to set the data node as master elegibles? If you have 3 dedicated master nodes I see no reason to also have the master nodes as master elegibles.

You can not choose the master, Elastic will elect one of the master elegibles as the master nodes and the only way to change it is if the node is restarted.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 20, 2023, 3:35pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/4 "2023-07-20T15:35:19Z")

</div>

i have seem this scheme before i just want to replicate into elastic 8.8.2 the reason is, if the 3 dedicates master for no reason shut down one of the 4 data nodes still being the master the continuation of the process will have never shut down in my case.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/5 "2023-07-20T15:37:58Z")

</div>

also i need help to configure the 3 dedicate master i mean not to receive data to configure only for master

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 20, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/6 "2023-07-20T16:01:29Z")

</div>

> [@hlcxpl](#):
>
> also i need help to configure the 3 dedicate master i mean not to receive data

The `elasticsearch.yml` you shared is already correct for creating a dedicate master, what issue you are having? What error do you have in the logs? You need to share it.

> [@hlcxpl](#):
>
> i have seem this scheme before i just want to replicate into elastic 8.8.2 the reason is, if the 3 dedicates master for no reason shut down one of the 4 data nodes still being the master the continuation of the process will have never shut down in my case.

But in this scenario it makes no sense to have dedicated master nodes.

From the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-node.html#dedicated-master-node) you have this:

> It is important for the health of the cluster that the elected master node has the resources it needs to fulfill its responsibilities. **If the elected master node is overloaded with other tasks then the cluster will not operate well**. The most reliable way to avoid overloading the master with other tasks is to configure all the master-eligible nodes to be _dedicated master-eligible nodes_ which only have the `master` role, allowing them to focus on managing the cluster.

If you are going to use data nodes as master eligible you may have some cases where the data node acting as master is overload and you may have issues in your cluster.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 20, 2023, 6:09pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/7 "2023-07-20T18:09:30Z")

</div>

Interesting i share this information to my lab team, thanks again for the knowledge, and pretty insterested in know more about elastic 8.8.2 🤩 🤗

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 20, 2023, 7:12pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/8 "2023-07-20T19:12:02Z")

</div>

> [@hlcxpl](#):
>
> Interesting i share this information to my lab team, thanks again for the knowledge, and pretty insterested in know more about elastic 8.8.2

This didn't change in version 8, it is the same recommendation for the past versions.

Not sure from where you got the configuration to mix up dedicated and non-dedicated master nodes, but I would not recommend it if you can have dedicated master nodes.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 20, 2023, 8:57pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/9 "2023-07-20T20:57:03Z")

</div>

nice i start the cluster with the right implementation

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c92e621834acc50dbc077b757e1c4c44a78f6cb.jpeg)

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 21, 2023, 7:47pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/10 "2023-07-21T19:47:22Z")

</div>

Hi, is me again if i'm configuring logstash, i have to create a certificate for logstash intance.yml in tmp and the thing is if i have to asigne a password or phrase but i was searching for keystore in logstash but there is not keystore file there how could i, secure configure logstash with the same private phrasse structure ? or i have to generate a single pem certificate for logstash self-signed? or configured one without --pass flag.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 21, 2023, 8:37pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/11 "2023-07-21T20:37:39Z")

</div>

I didn't tested with Logstash and I'm not sure Logstash supports PEM keys with passphrase.

What I use is the CRT file for the CA.

use `cacert => "/path/to/the/ca.crt"`

If this do not work you will probably need to regenerate all the certificates for your cluster withtout the `--pass` parameter.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 21, 2023, 8:44pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/12 "2023-07-21T20:44:35Z")

</div>

🥴 if i generate all the certificate again that will shutdown my cluster and we are ingesting the cluster with data already. could it be a way todo it in a secure way? also i tried without the --pass flag and gave me an error, if i have to generate all the certificates only will be the ca.crt but i think i will have to create also the pem .crt and .key for the nodes too if i change the main certificatte ca.crt  
?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 21, 2023, 8:55pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/13 "2023-07-21T20:55:20Z")

</div>

> [@hlcxpl](#):
>
> if i generate all the certificate again that will shutdown my cluster and we are ingesting the cluster with data already.

Yes, if you want to regenerate and change certificates you need a full cluster restart.

But I don't think you need it, you can just use the CRT file of the Certificate Authority you created and used to create the node certificates. Have you tried it?

When you created the CA you have a `.key` file and `.crt` file, copy the `.crt` file to the logstash server and configure the `cacert` option in the Elasticsearch output, it should work, this is what I use in production.

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 21, 2023, 9:03pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/14 "2023-07-21T21:03:24Z")

</div>

but i create a password for that how could i pass the password to logstash?

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 21, 2023, 9:04pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/15 "2023-07-21T21:04:58Z")

</div>

i will try like that

---

<div class="post-metadata">

**Author:** ![hlcxpl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hlcxpl/32/123290_2.png) [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Post date:** [July 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/16 "2023-07-25T19:05:02Z")

</div>

it works with the ca certificate and write the ingest line the node.roles: [ingets] section o one of my data nodes thank and i also have a permision problem with one of my file. the elastic data ingesting works succesfully.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2023, 7:05pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887/17 "2023-08-22T19:05:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
