# Installing Elasticsearch as an external service at OpenShift

**URL:** <https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845>\
**Category:** Elasticsearch\
**Created:** [July 20, 2023, 5:55am UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845 "2023-07-20T05:55:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yasser\_Alsawy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yasser_alsawy/32/120976_2.png) [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Post date:** [July 20, 2023, 5:55am UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845/1 "2023-07-20T05:55:21Z")

</div>

We have OpenShift cluster and we want to install elasticsearch at ocp to serve both internal and external audit shipment. our design should be something like this:  
FileBeat (outside ocp) --\> Logstash (inside ocp) --\> Elasticsearch (inside ocp) --\> Kibana (inside ocp)

I found ocp operator (internal/core service) for ECK. However, it does not include logstach. so my question is:

- should I create logstash pod at one project and use CRD from ECK operator then expose only logstash as a route for external calls?
- how could I call CRD and pods from the operator to define logstash?
- if I want to expose only logstash to outside as a route before calling ECK (elasticsearch) internally, what is proper way to do the same?
- do you have any best practice for implementing the same?  
Thanks

---

<div class="post-metadata">

**Author:** ![dike](https://avatars.discourse-cdn.com/v4/letter/d/e95f7d/32.png) [@dike](https://discuss.elastic.co/u/dike)\
**Post date:** [July 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845/2 "2023-07-26T14:38:21Z")

</div>

Hi @Yasser_Alsawy,

Can you confirm you're going through our official ECK operator? [Supported versions | Elastic Cloud on Kubernetes [2.9] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s_supported_versions.html)

Please refer to the same documentation to add the Logstash specification to your configuration file: [Quickstart | Elastic Cloud on Kubernetes [2.9] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-logstash-quickstart.html).

You can decide indeed to only expose Logstash externally and output Logstash to the internal Elasticsearch endpoint.

Best practice will depend on your specific case, which is usually tied to the Elasticsearch architecture that bets fits your use cases. Other than that, go with general Kubernetes/Openshift best practices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845/3 "2023-08-23T14:38:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
