# KEYSTORE\_PASSWORD\_FILE

**URL:** <https://discuss.elastic.co/t/keystore-password-file/339627>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [July 30, 2023, 6:22pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627 "2023-07-30T18:22:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![toughcoding](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toughcoding/32/124083_2.png) [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Post date:** [July 30, 2023, 6:22pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627/1 "2023-07-30T18:22:48Z")

</div>

Running Elasticsearch as docker container with  
`--env KEYSTORE_PASSWORD_FILE=/run/secrets/keystore_password`

does not setup password for elasticsearch keystore. Although I am successfull with Elasticsearch password itself  
`--env ELASTIC_PASSWORD_FILE=/run/secrets/bootstrap_password \`

I cannot get keystore password protected from the start. Permissions for secrets are 400.  
I noticed in logs it looks ok but does not work

```auto
Setting ELASTIC_PASSWORD from ELASTIC_PASSWORD_FILE at /run/secrets/bootstrap_password
Setting KEYSTORE_PASSWORD from KEYSTORE_PASSWORD_FILE at /run/secrets/bootstrap_password
Created elasticsearch keystore in /usr/share/elasticsearch/config/elasticsearch.keystore

```

Tried also variables without \_FILE suffix and same result - working as elastic bootstrap password but does not as keystore. Any idea guys?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [July 31, 2023, 5:58am UTC](https://discuss.elastic.co/t/keystore-password-file/339627/2 "2023-07-31T05:58:22Z")

</div>

I think the [docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-keystore-bind-mount) might have been unclear. The `KEYSTORE_PASSSWORD` or its file variation is used to provide password to an already encrypted password. It does _not_ create a new keystore with it. The keystore is always created with no password. Quote from the docs

> If you’ve already created the keystore and don’t need to update it, you can bind-mount the `elasticsearch.keystore` file directly. You can use the `KEYSTORE_PASSWORD` environment variable to provide the keystore password to the container at startup

---

<div class="post-metadata">

**Author:** ![toughcoding](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toughcoding/32/124083_2.png) [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Post date:** [July 31, 2023, 9:51am UTC](https://discuss.elastic.co/t/keystore-password-file/339627/3 "2023-07-31T09:51:08Z")

</div>

Indeed documentation is confusing

> You can use the contents of a file to set the value of the `ELASTIC_PASSWORD` or `KEYSTORE_PASSWORD` environment variables, by suffixing the environment variable name with `_FILE`. This is useful for passing secrets such as passwords to Elasticsearch without specifying them directly.

So the only solution is the precreate keystore using custom startup script. and then use KEYSTORE\_PASSWORD\_FILE for further accessing that keystore. Is it right?

---

<div class="post-metadata">

**Author:** ![toughcoding](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toughcoding/32/124083_2.png) [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Post date:** [August 1, 2023, 7:27pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627/4 "2023-08-01T19:27:39Z")

</div>

Tried workaround with precreated keystore but does not work. I think this is bug. Created entry for it

> <https://github.com/elastic/elasticsearch/issues/98115>
>
> \### Elasticsearch Version
> 
> 8.9.0
> 
> \### Installed Plugins
> 
> \_No response\_
> 
> \### Java… Version
> 
> \_bundled\_
> 
> \### OS Version
> 
> ubuntu:20.04 Linux 753c3b2604ff 5.15.49-linuxkit-pr #1 SMP PREEMPT Thu May 25 07:27:39 UTC 2023 aarch64 aarch64 aarch64 GNU/Linux
> 
> \### Problem Description
> 
> When starting Elasticsearch as a docker container with \*\*KEYSTORE\_PASSWORD\*\* and \*\*ELASTIC\_PASSWORD\*\* set and keystore being password secured, it does not working properly as \*\*bootstrap.password\*\* is not setup correctly.
> When checking value of bootstrap.password it is returning empty string. Thus command line \[54\](https://github.com/elastic/dockerfiles/blob/8.9/elasticsearch/bin/docker-entrypoint.sh)
> \`(echo "$COMMANDS" | elasticsearch-keystore add -x 'bootstrap.password')\`
> 
> is not causing bootstrap.password entry being created although running these commands manually in the container are successfull.
> 
> In Contrary Running with non-encrypted keystore making bootstrap.password to be setup properly like below
> \`\`\`
> docker run --rm \\
> \-d \\
> \-e ELASTIC\_PASSWORD="123456" \\
> docker.elastic.co/elasticsearch/elasticsearch:8.9.0
> \`\`\`
> 
> 
> \### Steps to Reproduce
> 
> Create container only to make encrypted keystore
> 
> \`\`\`
> docker run --rm \\
> \--name elk \\
> \-d \\
> \-v esconf:/usr/share/elasticsearch/config \\
> docker.elastic.co/elasticsearch/elasticsearch:8.9.0
> \`\`\`
> 
> Run command to setup password for already created keystore setting password as 123456
> \`docker exec -it elk elasticsearch-keystore passwd\`
> 
> \`\`\`
> docker exec -it elk elasticsearch-keystore list  
> Enter password for the elasticsearch keystore : 
> keystore.seed
> xpack.security.http.ssl.keystore.secure\_password
> xpack.security.transport.ssl.keystore.secure\_password
> xpack.security.transport.ssl.truststore.secure\_password
> \`\`\`
> 
> Stop container 
> \`docker stop elk\`
> 
> Start another container with password variables
> 
> \`\`\`
> docker run --rm \\
> \--name elk \\
> \-d \\
> \-v esconf:/usr/share/elasticsearch/config \\
> \-e ELASTIC\_PASSWORD="987654" \\
> \-e KEYSTORE\_PASSWORD="123456" \\
> docker.elastic.co/elasticsearch/elasticsearch:8.9.0
> \`\`\`
> 
> Checking if bootstrap password entry got created
> \`\`\`
> docker exec -it elk elasticsearch-keystore list
> Enter password for the elasticsearch keystore : 
> bootstrap.password
> keystore.seed
> xpack.security.http.ssl.keystore.secure\_password
> xpack.security.transport.ssl.keystore.secure\_password
> xpack.security.transport.ssl.truststore.secure\_password
> \`\`\`
> 
> Run command to display bootstrap.password that normally should be equal to ELASTIC\_PASSWORD
> \`docker exec -it elk elasticsearch-keystore show bootstrap.password\`
> 
> BUT it is returning empty string thus bug.
> 
> 
> 
> \### Logs (if relevant)
> 
> Beginning of logs after starting second container. Script asking twice for keystore password.
> docker run --rm \\
> \--name elk \\
> \-v esconf:/usr/share/elasticsearch/config \\
> \-e ELASTIC\_PASSWORD="123456" \\
> \-e KEYSTORE\_PASSWORD="123456" \\
> docker.elastic.co/elasticsearch/elasticsearch:8.9.0
> Enter password for the elasticsearch keystore : Enter password for the elasticsearch keystore : {"@timestamp":"2023-08-01T19:08:33.302Z", "log.level": "INFO",

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2023, 7:27pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627/5 "2023-08-29T19:27:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
