# Permission denied when starting Elasticsearch 7.17.0 installed via RPM

**URL:** <https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192>\
**Category:** Elasticsearch\
**Created:** [April 25, 2022, 6:12pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192 "2022-04-25T18:12:49Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 25, 2022, 6:12pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/1 "2022-04-25T18:12:49Z")

</div>

We are trying to expand our cluster size from 3 nodes to 5 nodes. After installing Elasticsearch via RPM on the new nodes we receive the following 'Permission denied' error when starting the service.

```plaintext
[root@host user]# sudo -i service elasticsearch start
Starting elasticsearch: /usr/share/elasticsearch/bin/elasticsearch-env: line 87: /etc/sysconfig/elasticsearch: Permission denied
                                                           [FAILED]

```

Line 87 in `/usr/share/elasticsearch/bin/elasticsearch-env` refers to:

```plaintext
 87 source /etc/sysconfig/elasticsearch

```

The permissions on that file and directory look OK to my eyes:

```plaintext
[root@host user]# ls -la /etc/sysconfig
total 228
drwxr-xr-x. 8 root root 4096 Apr 25 14:03 .
[root@host user]# ls -la /etc/sysconfig/elasticsearch
-rw-rw---- 1 root elasticsearch 1676 Jan 28 03:39 /etc/sysconfig/elasticsearch

```

I have looked at the following threads and still do not understand what the issue is:

> [@Elasticsearch-6.2.2 installation issue](https://discuss.elastic.co/t/elasticsearch-6-2-2-installation-issue/125700):
>
> hi, Installed elasicsearch-6.2.2 When running using sudo service elasticsearch start elasticsearch is not starting and even not getting log files aslo so, went to messages and see there find Mar 27 12:34:54 RFG-LOG-01 systemd: Started Elasticsearch. Mar 27 12:34:54 RFG-LOG-01 systemd: Starting Elasticsearch... Mar 27 12:34:54 RFG-LOG-01 elasticsearch: /usr/share/elasticsearch/bin/elasticsearch-env: line 70: /etc/sysconfig/elasticsearch: Permission denied Mar 27 12:34:54 RFG-LOG-01 systemd:…

> [@“Permission Denied” starting Elasticsearch-7.0](https://discuss.elastic.co/t/permission-denied-starting-elasticsearch-7-0/179336):
>
> I'm getting a permission denied error for /etc/default/elasticsearch when starting Elasticsearch: $ sudo systemctl status elasticsearch ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled) Active: inactive (dead) Docs: http://www.elastic.co $ curl -s -O https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.0.1-amd64.deb && sudo dpkg -i --force-confnew elasticsearch-7.0.1-amd64.deb (Read…

> [@Cannot start elasticsearch under user](https://discuss.elastic.co/t/cannot-start-elasticsearch-under-user/226587):
>
> When I try to start elasticsearch , I get the following [gefela@gefela bin] ./elasticsearch ./elasticsearch-env: line 75: /etc/sysconfig/elasticsearch: Permission denied [gefela@gefela bin] ^C What do I need to do to fix this ?

Our nodes are Chef-managed so they get provisioned with nearly the same configuration, so the discrepancy here is not clear to me.

Any assistance would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 25, 2022, 7:26pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/2 "2022-04-25T19:26:22Z")

</div>

did you check permission on "/etc/Elasticsearch" ? may be message is misleading.

---

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 25, 2022, 7:43pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/3 "2022-04-25T19:43:38Z")

</div>

```nohighlight
[root@host ~]# ls -la /etc/elasticsearch/
total 196
drwxr-s--- 4 root elasticsearch 4096 Apr 25 15:37 .

```

This matches the other 3 nodes where Elasticsearch is running without issue. Elasticsearch runs under the `elasticsearch` user on those nodes, same as the new node.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 25, 2022, 9:11pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/4 "2022-04-25T21:11:56Z")

</div>

anything more detail in any log?

what about journelctl -xe  
does it even creates any log?

---

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 26, 2022, 1:20pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/5 "2022-04-26T13:20:55Z")

</div>

No log is created by Elasticsearch.

journalctl is not available on my system (Oracle Enterprise Linux 6.10) and I don't see anything relevant in dmesg or in system logs.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 26, 2022, 4:48pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/6 "2022-04-26T16:48:09Z")

</div>

> [@ed\_vf](#):
>
> `source /etc/sysconfig/elasticsearch`

how about you execute this at prompt? does that works?

---

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 26, 2022, 5:23pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/7 "2022-04-26T17:23:03Z")

</div>

```nohighlight
[root@host ~]# sudo -u elasticsearch bash -c 'source /etc/sysconfig/elasticsearch'
bash: /etc/sysconfig/elasticsearch: Permission denied

```

It works if I source the file as root, but that doesn't help diagnose since root has full access to everything.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 26, 2022, 6:20pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/8 "2022-04-26T18:20:13Z")

</div>

ok. I see now what is happening.  
sudo do no have access to see your /etc/sysconfig/Elasticsearch file.

check sudo -l (as user) and you should see what access you have. you need to give that use read access to that file.

---

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 26, 2022, 6:45pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/9 "2022-04-26T18:45:53Z")

</div>

I'm only using sudo to invoke commands as another user. I'm not intending to elevate the privileges of the `elasticsearch` user itself.

```nohighlight
[elasticsearch@host ~]$ whoami
elasticsearch
[elasticsearch@host ~]$ source /etc/sysconfig/elasticsearch
bash: /etc/sysconfig/elasticsearch: Permission denied

```

However I think you may have uncovered the issue. When I `su` to `elasticsearch` I get the following error:

```nohighlight
[root@host ~]# su elasticsearch
/usr/bin/id: cannot find name for group ID 1408
[elasticsearch@host ~]$ whoami
elasticsearch
[elasticsearch@host ~]$ groups
groups: cannot find name for group ID 1408
1408

```

I'm not sure why the Elasticsearch user is assigned to a group id that doesn't exist, but this explains why the user does not have permission to `/etc/sysconfig/elasticsearch`.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 26, 2022, 6:59pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/10 "2022-04-26T18:59:22Z")

</div>

yes you have to give all require sudo access to user Elasticsearch.  
or simply you can start your service as root user and have to not worry about sudo.

---

<div class="post-metadata">

**Author:** ![ed\_vf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ed_vf/32/104807_2.png) [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Post date:** [April 26, 2022, 7:28pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/11 "2022-04-26T19:28:15Z")

</div>

I appreciate your help but there's nothing in the RPM instructions ([Install Elasticsearch with RPM | Elasticsearch Guide [7.17] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/rpm.html)) that requires sudoers changes for the `elasticsearch` user.

Furthermore, we do not grant any sudo access to the `elasticsearch` user on our other 3 nodes and it runs there successfully under `elasticsearch`, not root.

The issue here is entirely caused by the GID of the `elasticsearch` being incorrectly set. I will manually correct this, although I suspect that the RPM install process caused it.

Running Elasticsearch as root is not recommended as described here: [elasticsearch/es-security-principles.asciidoc at 9958c3c2fc49a3e253b04e96cfec2e653c39d2e7 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/blob/9958c3c2fc49a3e253b04e96cfec2e653c39d2e7/x-pack/docs/en/security/es-security-principles.asciidoc#run-es-with-a-dedicated-non-root-user).

In fact, the code specifically checks for this and throws a RuntimeException if you try to do so: [elasticsearch/Bootstrap.java at v7.17.0 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/blob/v7.17.0/server/src/main/java/org/elasticsearch/bootstrap/Bootstrap.java#L107)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [April 26, 2022, 8:10pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/12 "2022-04-26T20:10:31Z")

</div>

This is what I do.  
Set /etc/group, /etc/passwd, /etc/shadow first before installing rpm on new node  
that way all GID/UID are same across all node

if you want to do that you first have to remove rpm -e and then set UID/GID and reinstall the package, configure Elasticsearch.yml and restart

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2022, 8:10pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192/13 "2022-05-24T20:10:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
