# Is webhook validation possible for eck running in single namespace

**URL:** <https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [May 19, 2020, 5:40pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383 "2020-05-19T17:40:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 19, 2020, 5:40pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/1 "2020-05-19T17:40:21Z")

</div>

If you install ECK in a Kubernetes namespace (not cluster wide) can you use the webhook validator?

I installed everything (eck 1.1) in a single namespace and it seems to run fine but when I attempt to enable webhook validation I run into errors.

If I run

```auto
./elastic-operator manager --enable-webhook 

```

i get: "unable to setup and fill the webhook certificates" error:"resource name may not be empty"  
If I run

```auto
./elastic-operator manager --manage-webhook-certs

```

i get: error:"secrets is forbidden. User system:serviceaccount:mynamespace:mycloud cannot list resource secrets in the api group at the cluster scope.

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 19, 2020, 7:08pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/2 "2020-05-19T19:08:00Z")

</div>

I noticed the `elastic-webhook-server-cert` isn't in my namespace. Do I need to manually create this? Are there instructions for doing this in a single namespace?

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 19, 2020, 8:48pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/3 "2020-05-19T20:48:47Z")

</div>

I noticed the webhook template is in the all-in-one directory and not in the namespace directory. Does that imply you can't do webhook validations if installed in the namespace?

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 19, 2020, 9:06pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/4 "2020-05-19T21:06:54Z")

</div>

Also I see the operator template in namespace doesn't open a port for the validating server but all-in-one does so I guess it seems you can't validate your submissions when installing in a namespace. Is this correct?

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [May 20, 2020, 10:25am UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/5 "2020-05-20T10:25:24Z")

</div>

Hey @data_smith, sorry about that we're currently thinking about making it easier for everyone to customize ECK manifest for deployments in a single namespace. It's work in progress, see [this issue](https://github.com/elastic/cloud-on-k8s/issues/2406).

You will likely have to customize the namespace manifest to create the `elastic-webhook-server-cert` secret in the right namespace. You also indeed need to override the operator StatefulSet manifest to open the webhook port (9443), similar to how done in the all-in-one manifest.

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 20, 2020, 1:02pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/6 "2020-05-20T13:02:27Z")

</div>

Ok. Thanks for the info.

---

<div class="post-metadata">

**Author:** ![data\_smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/data_smith/32/124122_2.png) [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Post date:** [May 20, 2020, 3:03pm UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/7 "2020-05-20T15:03:59Z")

</div>

For anyone curious. I copied what was in the all-in-one statefulset over to the namespace statefulset (create empty cert, mount it, open port, etc). Then I got an error about access to validatingwebhookconfiguration. I got the api group and resource from that error and created a cluster role that gives access to that and then i created a clusterrolebinding to bind that cluster role with the eck service account. I did this on a private network and can't easily move it over to the internet but maybe the description will help you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:58am UTC](https://discuss.elastic.co/t/is-webhook-validation-possible-for-eck-running-in-single-namespace/233383/8 "2022-11-04T07:58:56Z")

</div>


