# Metricbeat credentials config help

**URL:** <https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283>\
**Category:** Beats\
**Tags:** docker, metricbeat\
**Created:** [June 15, 2022, 1:29pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283 "2022-06-15T13:29:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sadik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sadik/32/95771_2.png) [@sadik](https://discuss.elastic.co/u/sadik)\
**Post date:** [June 15, 2022, 1:29pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/1 "2022-06-15T13:29:40Z")

</div>

HI Team,

In " metricbeat.yml" configuration file we are using the below values for estrablish the connection to AWS.

```auto
metricbeat.modules:
  - module: aws
    period: 300s
    metricsets:
      - lambda
    access_key_id: $${AWS_ACCESS_KEY_ID}
    secret_access_key: $${AWS_SECRET_ACCESS_KEY}
    role_arn: ${ROLE_ARN}

```

But here the "AWS\_ACCESS\_KEY\_ID" and "AWS\_SECRET\_ACCESS\_KEY" are expired every 90 days so it's may be problem to us to remenber and reproduce the credentils to use it.

So can you please suggest any alternatives we can use in this metricbeat configuration instead of "AWS\_ACCESS\_KEY\_ID" and "AWS\_SECRET\_ACCESS\_KEY".

Thanks in advance!!!

Regards,  
Syed

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [June 15, 2022, 2:39pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/2 "2022-06-15T14:39:39Z")

</div>

Hi @sadik,

I know it sounds obvious, but you could set your access/secret key not to expire, that would be one way to solve it.

However there are other things you can also try, like using `role_arn` authentication.

Look at our documentation regarding AWS credentials: [AWS module | Metricbeat Reference [master] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/master/metricbeat-module-aws.html#aws-credentials-config) it lists all the possible options, you can try them out and see which one works best for you.

Another option would be to automate the credentials generation and restart of Metricbeat every couple of months.

---

<div class="post-metadata">

**Author:** ![sadik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sadik/32/95771_2.png) [@sadik](https://discuss.elastic.co/u/sadik)\
**Post date:** [June 28, 2022, 12:46pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/3 "2022-06-28T12:46:43Z")

</div>

Hi @TiagoQueiroz ,

Thanks for your reply, here i miss one step, my aws service wanna connect to K8s service, below is sample one,

```auto
processors:
  - add_cloud_metadata:

fields_under_root: true
fields:
  kubernetes.cluster: ${CLUSTER}

```

So, by using role\_arn authentication, how we wanna connect it, please provide any sample articles so it's so helpfull to complete our task.

Thank you!!!

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [July 6, 2022, 7:52am UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/4 "2022-07-06T07:52:43Z")

</div>

You can use the [add\_kubernetes\_metadata](https://www.elastic.co/guide/en/beats/metricbeat/current/add-kubernetes-metadata.html) processor for that, on the documentation link there is information on how to configure authentication.

---

<div class="post-metadata">

**Author:** ![sadik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sadik/32/95771_2.png) [@sadik](https://discuss.elastic.co/u/sadik)\
**Post date:** [July 12, 2022, 2:47pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/5 "2022-07-12T14:47:50Z")

</div>

Hi @TiagoQueiroz ,

I have go through the add\_kubernetes\_metadata processor documentation but not find any IAM role level authentication configuration in that document which will help to complete the task . So please suggest any other alternatives.

Thank you!!!

---

<div class="post-metadata">

**Author:** ![TiagoQueiroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagoqueiroz/32/107061_2.png) [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Post date:** [July 13, 2022, 2:37pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/6 "2022-07-13T14:37:46Z")

</div>

Yes, it doe not mention IAM role direct, but it does show how you can set the `host` and `kube_config` parameters to configure the access to the cluster.

I believe you have a way to access your kubernetes cluster, right? A way to run `kubectl` and inspect/modify the state of the cluster. Metricbeat can leverage the same configuration file as `kubectl` to connect to Kubernetes.

Both, `host` and `kube_config`, are documented on the link I provided as well as there is an example:

```nohighlight
processors:
  - add_kubernetes_metadata:
      host: <hostname>
      # If kube_config is not set, KUBECONFIG environment variable will be checked
      # and if not present it will fall back to InCluster
      kube_config: ~/.kube/config
      default_indexers.enabled: false
      default_matchers.enabled: false
      indexers:
        - ip_port:
      matchers:
        - fields:
            lookup_fields: ["metricset.host"]
      #labels.dedot: true
      #annotations.dedot: true

```

This will allow Metricbeat to connect to Kubernetes and get the necessary metadata.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2022, 4:38pm UTC](https://discuss.elastic.co/t/metricbeat-credentials-config-help/307283/7 "2022-08-10T16:38:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
