# How to use Azure Storage plugin in ECK for Snapshot

**URL:** <https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [June 17, 2020, 4:52pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513 "2020-06-17T16:52:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [June 17, 2020, 4:52pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/1 "2020-06-17T16:52:51Z")

</div>

Hi All,

I have to configure snapshot in ECK Deployment. Elasticsearch documentation has given example for Google cloud. Please can anyone list the steps for that.

I tried this -  
Created a file azure.client.default.credentials\_file

```auto
{
"azure.client.default.account": "ddddadsdasascs",
"azure.client.default.key": "csvtbdv"
} 

```

Create secret -

```auto
kubectl create secret generic azure-snapshot-credentials --from-file=azure.client.default.credentials_file -n dev

```

and updated the file with this -

```auto
spec:
  secureSettings:
  - secretName: "azure-snapshot-credentials"

```

But I see the pod started crashing with following error -

_java.lang.IllegalArgumentException: unknown secure setting [azure.client.default.credentials\_file] please check that any required plugins are installed, or check the breaking changes documentation for removed settings_

I am pretty sure, i am doing something wrong. Please can someone help me on this.  
Thanks

Regards  
AK

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [June 18, 2020, 8:23am UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/2 "2020-06-18T08:23:28Z")

</div>

You probably want to install the [azure repository plugin](https://www.elastic.co/guide/en/elasticsearch/plugins/7.7/repository-azure.html).  
Please look at [ECK plugins documentation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-init-containers-plugin-downloads.html).

---

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [June 18, 2020, 9:05am UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/3 "2020-06-18T09:05:47Z")

</div>

Hi Sebastien @sebgl, I am using custom build image with plugin. Please let me know anything else need to be done.

```auto
FROM ${repository_url}/elasticsearch:7.7.0
RUN bin/elasticsearch-plugin install --batch https://<repository_url>/repository-azure-7.7.0.zip

```

Thanks.

---

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [June 22, 2020, 3:55pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/4 "2020-06-22T15:55:12Z")

</div>

Hi Sebgl,

I am able to proceed further via correcting some information. I created a secret with following yaml file.

```auto
apiVersion: v1
kind: Secret
metadata:
  name: azure-snapshot-scret
type: Opaque
data:
  azure.client.default.account: <base-64 account name>
  azure.client.default.key: <base-64 key>

```

Now when i am running repository test following error is coming

```auto

{"type": "server", "timestamp": "2020-06-22T15:32:19,515Z", "level": "WARN", "component": "r.suppressed", "cluster.name": "emptydir-els", "node.name": "emptydir-els-es-master-0", "message": "path: /_snapshot/test/_verify, params: {repository=test}", "cluster.uuid": "hZne8eJ5SgOeGeslyLvJkw", "node.id": "0c1AOl99Ta-w-6fE7ivrzA" ,  
"stacktrace": ["org.elasticsearch.common.settings.SettingsException: Invalid azure client settings with name [default]", 
"at org.elasticsearch.repositories.azure.AzureStorageService.client(AzureStorageService.java:112) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureStorageService.writeBlob(AzureStorageService.java:327) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureBlobStore.writeBlob(AzureBlobStore.java:119) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureBlobContainer.writeBlob(AzureBlobContainer.java:101) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureBlobContainer.writeBlobAtomic(AzureBlobContainer.java:109) ~[?:?]", 
"at org.elasticsearch.repositories.blobstore.BlobStoreRepository.startVerification(BlobStoreRepository.java:1065) ~[elasticsearch-7.7.0.jar:7.7.0]", 
"at org.elasticsearch.repositories.RepositoriesService$3.doRun(RepositoriesService.java:246) ~[elasticsearch-7.7.0.jar:7.7.0]", 
"at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingAbstractRunnable.doRun(ThreadContext.java:692) [elasticsearch-7.7.0.jar:7.7.0]", 
"at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-7.7.0.jar:7.7.0]", 
"at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1130) [?:?]", 
"at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:630) [?:?]", 
"at java.lang.Thread.run(Thread.java:832) [?:?]", 
"Caused by: java.security.InvalidKeyException: Storage Key is not a valid base64 encoded string.", 
"at com.microsoft.azure.storage.StorageCredentials.tryParseCredentials(StorageCredentials.java:68) ~[?:?]", 
"at com.microsoft.azure.storage.CloudStorageAccount.tryConfigureServiceAccount(CloudStorageAccount.java:664) ~[?:?]", 
"at com.microsoft.azure.storage.CloudStorageAccount.parse(CloudStorageAccount.java:285) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureStorageService.createClient(AzureStorageService.java:140) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureStorageService.buildClient(AzureStorageService.java:117) ~[?:?]", 
"at org.elasticsearch.repositories.azure.AzureStorageService.client(AzureStorageService.java:110) ~[?:?]", 
"... 11 more"] } 

```

---

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [June 22, 2020, 6:18pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/5 "2020-06-22T18:18:42Z")

</div>

> [@robinhood\_lko](#):
>
> ```auto
> "Caused by: java.security.InvalidKeyException: Storage Key is not a valid base64 encoded string.", 
> "at com.microsoft.azure.storage.StorageCredentials.tryParseCredentials(StorageCredentials.java:68) ~[?:?]", 
> "at com.microsoft.azure.storage.CloudStorageAccount.tryConfigureServiceAccount(CloudStorageAccount.java:664) ~[?:?]", 
> "at com.microsoft.azure.storage.CloudStorageAccount.parse(CloudStorageAccount.java:285) ~[?:?]", 
> "at org.elasticsearch.repositories.azure.AzureStorageService.createClient(AzureStorageService.java:140) ~[?:?]", 
> "at org.elasticsearch.repositories.azure.AzureStorageService.buildClient(AzureStorageService.java:117) ~[?:?]", 
> "at org.elasticsearch.repositories.azure.AzureStorageService.client(AzureStorageService.java:110) ~[?:?]", 
> "... 11 more"] }
> 
> ```

I am able to fix it now. Values for Account name and Key details after encryption were not proper. Thanks

---

<div class="post-metadata">

**Author:** ![Fikrat\_Karimli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fikrat_karimli/32/76086_2.png) [@Fikrat\_Karimli](https://discuss.elastic.co/u/Fikrat_Karimli)\
**Post date:** [October 28, 2020, 12:27pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/6 "2020-10-28T12:27:54Z")

</div>

> [@robinhood\_lko](#):
>
> `azure-snapshot-credentials`

İ did everything accordingly but still failing. I also read a Medium post about this still no result.

---

<div class="post-metadata">

**Author:** ![robinhood\_lko](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@robinhood\_lko](https://discuss.elastic.co/u/robinhood_lko)\
**Post date:** [May 12, 2021, 9:24am UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/7 "2021-05-12T09:24:46Z")

</div>

Probably in some cases I noticed the base64 of key was having a "/n". Make sure proper base64 is being generated.

---

<div class="post-metadata">

**Author:** ![dis](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@dis](https://discuss.elastic.co/u/dis)\
**Post date:** [August 11, 2021, 5:35pm UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/8 "2021-08-11T17:35:19Z")

</div>

Hi @robinhood_lko,  
Can you provide the complete infos to configure the Azure storage? I'm deploying elasticsearch using Helm

So far this is what you have done.  
1 - Create a file containing account + key and secret  
{  
"azure.client.default.account": "ddddadsdasascs",  
"azure.client.default.key": "csvtbdv"  
}

kubectl create secret generic azure-snapshot-credentials --from-file=azure.client.default.credentials\_file -n dev

What was the fix from the exception?

```auto
java.lang.IllegalArgumentException: unknown secure setting [azure.client.default.credentials_file] please check that any required plugins are installed, or check the breaking changes documentation for removed settings

```

2 - What was the fix for the base-64 account & key  
3 - Did you set any key in elasticsearch.yml and keystore?  
4 - I have installed the repository-azure plugin  
5 - Please include any infos that I did not covered above

Regards,  
Dis

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:02am UTC](https://discuss.elastic.co/t/how-to-use-azure-storage-plugin-in-eck-for-snapshot/237513/9 "2022-11-04T08:02:52Z")

</div>


