# Openshift 4 - Fleet and Elastic Agent permission denied

**URL:** <https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent-permission-denied/325403>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** fleet\
**Created:** [February 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent-permission-denied/325403 "2023-02-13T15:26:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [February 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent-permission-denied/325403/1 "2023-02-13T15:26:02Z")

</div>

Hi,  
I have been stuck with this issue for a couple of days and can't get it working.  
We are using Openshift 4.12 & argoCD with the elastic operator in Openshift.

I followed the official eck k8s 2.6 documentation and created the required resources.

Worth mentioning is that we implemented the compliance operator and have used the CIS operator to hardening the platform.

```auto
apiVersion: agent.k8s.elastic.co/v1alpha1
kind: Agent
metadata:
  name: fleet-server-dev
  namespace: elastic-dev
spec:
  version: 8.6.1
  kibanaRef:
    name: kibanadev
  elasticsearchRefs:
  - name: esdev01
  mode: fleet
  fleetServerEnabled: true
  deployment:
    replicas: 1
    podTemplate:
      spec:
        serviceAccountName: elastic-agent
        automountServiceAccountToken: true
        securityContext:
          runAsUser: 0
---
apiVersion: agent.k8s.elastic.co/v1alpha1
kind: Agent
metadata:
  name: elastic-agent-dev
  namespace: elastic-dev
spec:
  version: 8.6.1
  kibanaRef:
    name: kibanadev
  fleetServerRef:
    name: fleet-server-dev
  mode: fleet
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: elastic-agent
        automountServiceAccountToken: true
        securityContext:
          runAsUser: 0
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: elastic-agent
rules:
- apiGroups: [""] # "" indicates the core API group
  resources:
  - pods
  - nodes
  - namespaces
  verbs:
  - get
  - watch
  - list
- apiGroups: ["coordination.k8s.io"]
  resources:
  - leases
  verbs:
  - get
  - create
  - update
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: elastic-agent
  namespace: elastic-dev
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: elastic-agent
subjects:
- kind: ServiceAccount
  name: elastic-agent
  namespace: elastic-dev
roleRef:
  kind: Role
  name: elastic-agent
  apiGroup: rbac.authorization.k8s.io

```

Rolebinding

```auto
Name: elastic-agent-rb
Labels: <none>
Annotations: <none>
Role:
  Kind: ClusterRole
  Name: system:openshift:scc:privileged
Subjects:
  Kind Name Namespace
  ---- ---- ---------
  ServiceAccount elastic-agent elastic-dev

```

The hostpath is created on the physical machine but we are still getting permissions denied!

```auto
Error: preparing STATE_PATH(/usr/share/elastic-agent/state) failed: mkdir /usr/share/elastic-agent/state/data: permission denied
For help, please see our troubleshooting guide at https://www.elastic.co/guide/en/fleet/8.6/fleet-troubleshooting.html

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent-permission-denied/325403/2 "2023-03-13T15:26:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
