# Kubernetes beats deployment yaml syntax error linked from support documents to GitHub

**URL:** <https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722>\
**Category:** Beats\
**Tags:** beats-development\
**Created:** [May 30, 2023, 8:20pm UTC](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722 "2023-05-30T20:20:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndrewDatTeranet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewdatteranet/32/86108_2.png) [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Post date:** [May 30, 2023, 8:20pm UTC](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722/1 "2023-05-30T20:20:35Z")

</div>

I believe there is a syntax error in the daemonset configuration in all the beats example/refrence yaml's in the elastic beats repo on GitHub. see below for the issue with the filbeat config (though it looks like that section is repeated in all other examples given under [beats/deploy/kubernetes at main · elastic/beats · GitHub](https://github.com/elastic/beats/tree/main/deploy/kubernetes) )

on line 164 at [https://raw.githubusercontent.com/elastic/beats/8.7/deploy/kubernetes/filebeat-kubernetes.yaml](https://raw.githubusercontent.com/elastic/beats/8.7/deploy/kubernetes/filebeat-kubernetes.yaml) it reads:

```auto
  spec:
    serviceAccountname: filebeat

```

which is not the way to refrence the serviceaccount to run the daemonset, it should be:

```auto
  spec:
    serviceAccount: filebeat

```

Judging by the makefile in that repo the following files should be updated and make(looks like a jenkins job) rerun

deploy/kubernetes/metricbeat/metricbeat-daemonset.yaml  
deploy/kubernetes/filebeat/filebeat-daemonset.yaml  
deploy/kubernetes/auditbeat/auditbeat-daemonset.yaml  
deploy/kubernetes/heartbeat/heartbeat-daemonset.yaml

I actually have a case with this open with elastic but this was a bit tricky as they seem to be more familiar with the support docs not git itself. FYI these files are referenced in the support documents:

> **[Run Filebeat on Kubernetes | Filebeat Reference \[8.8\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubernetes.html)**

> **[Run Metricbeat on Kubernetes | Metricbeat Reference \[8.8\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-kubernetes.html)**

> **[Running Auditbeat on Kubernetes | Auditbeat Reference \[8.8\] | Elastic](https://www.elastic.co/guide/en/beats/auditbeat/current/running-on-kubernetes.html)**

> **[Running Heartbeat on Kubernetes | Heartbeat Reference \[8.8\] | Elastic](https://www.elastic.co/guide/en/beats/heartbeat/current/running-on-kubernetes.html)**

I would normally open a GitHub pull to fix this but the default issue template appears to heavily imply I should report it here first.

can someone else here confirm and suggest what I should do next? (open a ticket and pull request?, Wait for an elastic engineer to update?, etc.)

---

<div class="post-metadata">

**Author:** ![AndrewDatTeranet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewdatteranet/32/86108_2.png) [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Post date:** [May 30, 2023, 10:15pm UTC](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722/2 "2023-05-30T22:15:52Z")

</div>

> [@AndrewDatTeranet](#):
>
> ```auto
> spec:
> serviceAccountname:
> 
> ```

So I actually tracked down the Issue, apparently in a previous Kubernetes version they deprecated the serviceaccount syntax and changed it to serviceaccountname using the version of Kubernetes we use locally it does not seem to support this new field name.

Not a bug just API version deprecation's and pain for those of us that don't follow the bleeding edge. hopefully this helps someone else out there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2023, 12:16am UTC](https://discuss.elastic.co/t/kubernetes-beats-deployment-yaml-syntax-error-linked-from-support-documents-to-github/334722/3 "2023-06-28T00:16:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
