# Recommended way of storing credentials in Beats configuration file?

**URL:** <https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 31, 2020, 4:19pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081 "2020-05-31T16:19:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![curiousmind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/curiousmind/32/69452_2.png) [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Post date:** [May 31, 2020, 4:19pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081/1 "2020-05-31T16:19:15Z")

</div>

What is the recommended way of storing the credentials like username and passwords in the beats configuration file?  
Our deployment is via terraform and ansible, which essentially stores the credentials in the environment.  
Is this a good practice?  
if not, what is the recommended practice?  
Would like to get a pretty good picture on this as we are going to deal with healthcare client for this deployment.  
Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [May 31, 2020, 9:23pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081/2 "2020-05-31T21:23:29Z")

</div>

Now, the best solution will be to stick to using keystore content especially for passwords.

> **[Secrets keystore for secure settings | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/keystore.html#add-keys-to-keystore)**

For something like  
`cat /file/containing/setting/value | filebeat keystore add ES_PWD --stdin --force`  
and then use it in the yml file:  
`output.elasticsearch.password: "${ES_PWD}"`

How to use that in ansible, I don't want to reinvent the wheel.  
Here you should find a working example, you just need to translate it from kibana to filebeat command style:

> [@How to fill keystore via ansible script](https://discuss.elastic.co/t/how-to-fill-keystore-via-ansible-script/212117/4):
>
> During creating the Bug Report I found this on github: With the given information there I was able to get it running: - name: keystore tasks block: - name: create keystore if not existing yet shell: cmd: "./kibana-keystore create" chdir: "/usr/share/kibana/bin" creates: /var/lib/kibana/kibana.keystore - name: keystore - add elasticsearch.password shell: cmd: "/usr/share/kibana/bin/kibana-keystore add elasticsearch.password --stdin --forc…

The similar should be possible with a remote exec provisioner:

> **[Provisioner: remote-exec | Terraform | HashiCorp Developer](https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec)**
>
> The \`remote-exec\` provisioner invokes a script on a remote resource after it is created. This can be used to run a configuration management tool, bootstrap into a cluster, etc. To invoke a local process, see the \`local-exec\` provisioner instead. The...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2020, 9:23pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081/3 "2020-06-28T21:23:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
