# I want to set up the initial password without any environment variables after "xpack.security.enabled: true"

**URL:** <https://discuss.elastic.co/t/i-want-to-set-up-the-initial-password-without-any-environment-variables-after-xpack-security-enabled-true/291209>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [December 8, 2021, 10:20am UTC](https://discuss.elastic.co/t/i-want-to-set-up-the-initial-password-without-any-environment-variables-after-xpack-security-enabled-true/291209 "2021-12-08T10:20:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tadashi.oya](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@tadashi.oya](https://discuss.elastic.co/u/tadashi.oya)\
**Post date:** [December 8, 2021, 10:20am UTC](https://discuss.elastic.co/t/i-want-to-set-up-the-initial-password-without-any-environment-variables-after-xpack-security-enabled-true/291209/1 "2021-12-08T10:20:32Z")

</div>

Hi there.  
I'm trying to use [T-Pot](https://github.com/telekom-security/tpotce) with "xpack.security.enabled: true".

I want to set up passwords for Elasticsearch's built-in users (elastic, kibana\_system, and so on) as following conditions.

1. Use as few interactive or prompting procedures as possible.
2. Environment variables are not available. (See [this article](https://discuss.elastic.co/t/environment-xpack-security-enabled-true-does-not-work-with-docker-compose/290389/2))

I applied "[File-based user authentication](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/file-realm.html)" and got the following.

```auto
# cd /data/elk
# cat ./users <<<created beforehand with the elasticsearch-users command.
tpotsuper:$2a$10$ByOIIGbAPP4oc2Zi4WYu2e6ZLironun6le8yZ5JFwtnjieb4VqLze
# cat ./users_roles
superuser:tpotsuper

```

```auto
# cat /opt/tpot/etc/tpot.yml <<<created beforehand
(snip)
  elasticsearch:
(snip)
    volumes:
     - /data:/data
     - /data/elk/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml
     - /data/elk/users:/usr/share/elasticsearch/config/users
     - /data/elk/users_roles:/usr/share/elasticsearch/config/users_roles

```

```auto
# systemctl stop tpot
# systemctl start tpot

```

```auto
# curl -u tpotsuper:tpotsuper -X POST "localhost:64298/_security/user/elastic/_password" -H 'Content-Type: application/json' -d '{"password": "elastic_password"}'

```

```auto
# curl -u elastic:elastic_password http://localhost:64298/
{
  "name" : "tpotcluster-node-01",
  "cluster_name" : "tpotcluster",
  "cluster_uuid" : "CUF8YNVTThm8QqKvWeeXGg",
  "version" : {
    "number" : "7.15.1",
    "build_flavor" : "default",
    "build_type" : "tar",
    "build_hash" : "83c34f456ae29d60e94d886e455e6a3409bba9ed",
    "build_date" : "2021-10-07T21:56:19.031608185Z",
    "build_snapshot" : false,
    "lucene_version" : "8.9.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

```auto
# systemctl stop tpot
# rm /data/elk/users
# rm /data/elk/users_roles
# touch /data/elk/users <<<replace with empty file
# touch /data/elk/users_roles
# systemctl start tpot

```

Is there a simpler way?  
Thanks.

---

<div class="post-metadata">

**Author:** ![tadashi.oya](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@tadashi.oya](https://discuss.elastic.co/u/tadashi.oya)\
**Post date:** [December 9, 2021, 3:02pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-the-initial-password-without-any-environment-variables-after-xpack-security-enabled-true/291209/2 "2021-12-09T15:02:00Z")

</div>

Is this the simplest way with conditions in this post?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2022, 3:02pm UTC](https://discuss.elastic.co/t/i-want-to-set-up-the-initial-password-without-any-environment-variables-after-xpack-security-enabled-true/291209/3 "2022-01-06T15:02:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
