# How to update service account which is used to create snapshot

**URL:** <https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128>\
**Category:** Kibana\
**Created:** [June 28, 2023, 8:34pm UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128 "2023-06-28T20:34:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aysh14](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Post date:** [June 28, 2023, 8:34pm UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/1 "2023-06-28T20:34:28Z")

</div>

How to update service account which is used to create snapshot. I created repository from Kibana to snapshot the Elastic search indices. The snapshot location is GCS bucket. However, the repository is not getting verified as the service account being used has expired and decommissioned. I want to change the service account to a different service account. Can someone please help on how the same can be done ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 28, 2023, 9:41pm UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/2 "2023-06-28T21:41:31Z")

</div>

You just need to add the new service account json to the keystore in the same way you added it when creating the repository.

```auto
./elasticsearch-keystore add-file gcs.client.default.credentials_file /path/service-account.json

```

Check the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/8.8/repository-gcs.html#repository-gcs-client) for more information.

After you apply this to every master and data node, you will need to reload the secure settings according to the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/cluster-nodes-reload-secure-settings.html).

Basically run `POST /_nodes/reload_secure_settings` on Kibana Dev Tools.

---

<div class="post-metadata">

**Author:** ![Aysh14](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Post date:** [June 28, 2023, 10:15pm UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/3 "2023-06-28T22:15:38Z")

</div>

Thank you Leandro for the reply. Actually I am trying to configure a repository from Kibana . Not sure from where it is picking the service account. I have never applied json key in the beginning of configuration. Is it taken from the secrets ? I am sorry I am new to Elastic installation and setup.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 28, 2023, 10:32pm UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/4 "2023-06-28T22:32:05Z")

</div>

Kibana is a client to Elasticsearch, all data is on Elasticsearch.

To create a repository in Kibana you need a working client configured in Elasticsearch.

The credentials to connect to GCP using your service account are stored in the elasticsearch keystore, which is in every node of your cluster, if your service account expired you will need to get the json for the new credentials and apply it to your elasticsearch nodes as explained in the previous answer.

> [@Aysh14](#):
>
> I have never applied json key in the beginning of configuration.

Did you had snapshots working before?

---

<div class="post-metadata">

**Author:** ![Aysh14](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Post date:** [July 14, 2023, 3:35am UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/5 "2023-07-14T03:35:07Z")

</div>

Got it . I was able to update the service account in the secrets . Thank you leandrojmp

---

<div class="post-metadata">

**Author:** ![Aysh14](https://avatars.discourse-cdn.com/v4/letter/a/4af34b/32.png) [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Post date:** [July 14, 2023, 3:38am UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/6 "2023-07-14T03:38:16Z")

</div>

Can I setup a new repository for the snapshots without having to restart the data and master nodes of Elasticsearch cluster? There is no recent snapshot available. I would like to setup a repository to take the snapshots in case of a failure. However, the pods on the environment where I want to take the snapshot cannot be restarted z nor can I take a downtime. Is there a way to take new snapshot starting from recent day ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2023, 3:39am UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128/7 "2023-08-11T03:39:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
