# Linux System User Elasticsearch

**URL:** <https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456>\
**Category:** Elasticsearch\
**Created:** [January 9, 2026, 1:09pm UTC](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456 "2026-01-09T13:09:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![aurora](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@aurora](https://discuss.elastic.co/u/aurora)\
**Post date:** [January 9, 2026, 1:09pm UTC](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456/1 "2026-01-09T13:09:53Z")

</div>

I’m pretty sure I installed v9.0.2 from a tarball on an ubuntu fork, so I didn’t automatically get a no-login user created to run a systemd unit. Are there any elasticsearch specific things I need to know about creating a no-login user to run elasticsearch as? Just created a systemd unit for elasticsearch.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 9, 2026, 2:25pm UTC](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456/2 "2026-01-09T14:25:17Z")

</div>

If you use ES from tarball no Linux user will be created. Only installation packages create Linux users.

In the service mode - systemd, user(manually create) which starts ES, must have permissions to:

- create/modify files where are data and logs.  
`path.data: /path/data`  
`path.logs: /path/log/`
- read certificates for network and https communication
- create/modify files where is repository for snapshot/backup:  
`path.repo: /path2/backups`

The production environment needs additional [configuration](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/important-system-configuration). In general to start ES it's enough to extract, set elasticsearch.yml and run it.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [January 10, 2026, 11:39am UTC](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456/3 "2026-01-10T11:39:05Z")

</div>

You can also just look at the pre and post install steps that a RPM/deb installation does. e.g. under ubuntu

```auto
$ apt install elasticsearch --download-only
$ mkdir /tmp/test
$ cd /tmp/test
$ dpkg-deb -e /var/cache/apt/archives/elasticsearch_9.2.3_amd64.deb
$ find . -type f
./DEBIAN/postrm
./DEBIAN/prerm
./DEBIAN/md5sums
./DEBIAN/conffiles
./DEBIAN/preinst
./DEBIAN/postinst
./DEBIAN/control

```
