# Kubernetes agent with self signed certificate

**URL:** <https://discuss.elastic.co/t/kubernetes-agent-with-self-signed-certificate/312434>\
**Category:** Elastic Observability\
**Tags:** docker\
**Created:** [August 19, 2022, 7:36am UTC](https://discuss.elastic.co/t/kubernetes-agent-with-self-signed-certificate/312434 "2022-08-19T07:36:35Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![deborggraever](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deborggraever/32/109861_2.png) [@deborggraever](https://discuss.elastic.co/u/deborggraever)\
**Post date:** [August 22, 2022, 12:57pm UTC](https://discuss.elastic.co/t/kubernetes-agent-with-self-signed-certificate/312434/2 "2022-08-22T12:57:30Z")

</div>

After more trying i found a working solution.

I have mounted the custom CA directly into the /etc/ssl/certs folder and removed the env vars for CA.

```auto
apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: elastic-agent
  namespace: kube-system
  labels:
    app: elastic-agent
spec:
  selector:
    matchLabels:
      app: elastic-agent
  template:
    metadata:
      labels:
        app: elastic-agent
    spec:
      ...
      containers:
        - name: elastic-agent
          image: docker.elastic.co/beats/elastic-agent:8.3.3
          env:
            - name: FLEET_ENROLL
              value: "1"
            # Set to true in case of insecure or unverified HTTP
            - name: FLEET_INSECURE
              value: "true"
              # The ip:port pair of fleet server
            - name: FLEET_URL
              value: "https://elastic-fleet.xxxx:8220"
              # If left empty KIBANA_HOST, KIBANA_FLEET_USERNAME, KIBANA_FLEET_PASSWORD are needed
            - name: FLEET_ENROLLMENT_TOKEN
              value: "xxxxx"
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
          ...
          volumeMounts:
            ...
            - name: elastic-ca
              mountPath: /etc/ssl/certs/elastic-ca.crt
              subPath: elastic-ca.crt
              readOnly: true
      volumes:
        ...
        - name: elastic-ca
          secret:
            secretName: elastic-ca

```

---

_[View the full topic](https://discuss.elastic.co/t/kubernetes-agent-with-self-signed-certificate/312434)._
