# \[NEW\] Openshift 4 - Fleet and Elastic Agent permission denied

**URL:** <https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** fleet\
**Created:** [April 26, 2023, 12:58pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841 "2023-04-26T12:58:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![demon86rm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/demon86rm/32/120243_2.png) [@demon86rm](https://discuss.elastic.co/u/demon86rm)\
**Post date:** [April 26, 2023, 12:58pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841/1 "2023-04-26T12:58:56Z")

</div>

Hi,

I'd like to reopen the old post from [splitmessage88](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent-permission-denied/325403) as I'm facing the exact same issue while trying to configure an Elastic Agent on an ARO cluster. I've followed all the existing instructions for deploy the ECK operator on Openshift but in the end the only result is that the daemonSet is not able to mkdir the /usr/share/elastic-agent/state hostPath directory even with privileged scc serviceAccount or runAsUser:0 securityContext.

Has anyone ever achieved deploying successfully on Openshift or on **Managed Openshift service (like ARO/ROSA)** an elastic-agent daemonSet running?

If it's not possibile, can be specified on the docs that ECK **can't be deployed successfully on managed platforms** or that it hasn't been tested at least so it might not work even if the steps on the docs are followed?

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [April 26, 2023, 1:24pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841/2 "2023-04-26T13:24:03Z")

</div>

> [@demon86rm](#):
>
> privileged scc serviceAccount or runAsUser:0 securityContext.

IIRC being in the privileged scc is not enough, could you also check that the container is privileged:

```auto
    podTemplate:
      spec:
        securityContext:
          runAsUser: 0
        containers:
          - name: agent
            securityContext:
              runAsUser: 0
              privileged: true

```

---

<div class="post-metadata">

**Author:** ![demon86rm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/demon86rm/32/120243_2.png) [@demon86rm](https://discuss.elastic.co/u/demon86rm)\
**Post date:** [April 27, 2023, 3:56pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841/3 "2023-04-27T15:56:32Z")

</div>

Thank you for your answer, that worked like a charm!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2023, 3:56pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841/4 "2023-05-25T15:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
