# Possible problem with Elasticsearch readinessProbe?

**URL:** <https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [January 30, 2020, 2:31am UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094 "2020-01-30T02:31:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tadgh](https://avatars.discourse-cdn.com/v4/letter/t/9f8e36/32.png) [@tadgh](https://discuss.elastic.co/u/tadgh)\
**Post date:** [January 30, 2020, 2:31am UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094/1 "2020-01-30T02:31:22Z")

</div>

Hey all, I am trying to setup a google cloud Ingress object to route traffic to the Elasticsearch service in ECK, but it appears as though the Ingress object attempts the health check using the HTTP protocol, instead of HTTPS. I was under the impression that the readinessProbe defined in the operator overrode the default check at `/` looking for `200`

Here is my toy ES Config:

```
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: quickstart
spec:
  http:
service:
  spec:
    type: LoadBalancer
  version: 7.5.2
  nodeSets:
  - name: default
count: 1
config:
  node.master: true
  node.data: true
  node.ingest: true
  node.store.allow_mmap: false

```

Here is the accompanying ingress resource:

```
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: elastic-ingress
  annotations: 
    kubernetes.io/ingress.global-static-ip-name: name-of-my-address
    kubernetes.io/ingress.allow-http: "true"
spec:
  rules:
  - http:
      paths:
      - path: /*
        backend:
          serviceName: quickstart-es-http
          servicePort: 9200

```

A few minutes after I start this ingress, I get the following in the cloud console:

 ![2020-01-29_18-29](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f941da7ca09c8c40e48987cad107ad3c1a493dbf.png)

And in my elasticsearch pod logs, I get the following warnings, which seem to indicate that the health checks are being rejected:

```auto
{"type": "server", "timestamp": "2020-01-30T02:29:14,832Z", "level": "WARN", "component": "o.e.x.s.t.n.SecurityNetty4HttpServerTransport", "cluster.name": "quickstart", "node.name": "quickstart-es-default-0", "message": "received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/10.16.0.23:9200, remoteAddress=/10.128.0.3:36878}", "cluster.uuid": "Oxno1fnRTluho2wlekONMA", "node.id": "DtOKi0UcS6K8NyAwDtsryA" }

```

Is there some simple way to resolve this?

Cheers

---

<div class="post-metadata">

**Author:** ![Anya\_Sabo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anya_sabo/32/49903_2.png) [@Anya\_Sabo](https://discuss.elastic.co/u/Anya_Sabo)\
**Post date:** [January 30, 2020, 3:28am UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094/2 "2020-01-30T03:28:32Z")

</div>

The google docs are a little confusing. The [health checks](https://cloud.google.com/kubernetes-engine/docs/concepts/ingress#health_checks) section makes it seem like it requires an http check (where we use an exec check). But the sections on [https betwen the LB and the service](https://cloud.google.com/kubernetes-engine/docs/concepts/ingress#https_tls_between_load_balancer_and_your_application) and [disabling HTTP](https://cloud.google.com/kubernetes-engine/docs/concepts/ingress#disabling_http) seem to indicate that in this case (where you want HTTPS from the client to the LB to the Elasticsearch service), you would want to add these annotations:  
`cloud.google.com/app-protocols: '{"http":"HTTPS"}'`  
`kubernetes.io/ingress.allow-http: "false"`

It's not 100% clear that the latter will keep it from using HTTP health checks. I suspect it would start using https checks, but it will try and access it without authenticating which will still error out.

---

<div class="post-metadata">

**Author:** ![tadgh](https://avatars.discourse-cdn.com/v4/letter/t/9f8e36/32.png) [@tadgh](https://discuss.elastic.co/u/tadgh)\
**Post date:** [January 30, 2020, 11:20pm UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094/3 "2020-01-30T23:20:27Z")

</div>

Thanks for the response!

No such luck unfortunately. After modifying the elasticsearch resource to add this annotation

```auto
metadata:
  name: quickstart
  annotations:
    cloud.google.com/app-protocols: '{"http":"HTTPS"}'

```

and setting the ingress to not allow HTTP, the health checks that are created still have the protocol set to http. I will wait on this: [https://github.com/elastic/cloud-on-k8s/issues/2489](https://github.com/elastic/cloud-on-k8s/issues/2489)

I have the option of also just using a LoadBalancer http service, but then I'm stuck either relying on the self-signed cert, or a self-managed cert, where I want to use the google ManagedCertificate.

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [January 31, 2020, 4:33pm UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094/4 "2020-01-31T16:33:52Z")

</div>

> [@tadgh](#):
>
> After modifying the elasticsearch resource to add this annotation

The annotation has to be on the service template and I had to enable anonymous access for the health check to pass (I used the monitoring user role but this could be restricted further) :

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: quickstart
spec:
  version: 7.5.2
  http:
    service:
      metadata:
        annotations:
          cloud.google.com/app-protocols: '{"https":"HTTPS"}'
      spec: 
        type: NodePort
  nodeSets:
  - name: default
    count: 3
    config:
      xpack.security.authc:
        anonymous:
          username: anonymous_user 
          roles: monitoring_user

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:42am UTC](https://discuss.elastic.co/t/possible-problem-with-elasticsearch-readinessprobe/217094/5 "2022-11-04T07:42:45Z")

</div>


