# Recommended way of storing credentials in Beats configuration file?

**URL:** <https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 31, 2020, 4:19pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081 "2020-05-31T16:19:14Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [May 31, 2020, 9:23pm UTC](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081/2 "2020-05-31T21:23:29Z")

</div>

Now, the best solution will be to stick to using keystore content especially for passwords.

> **[Secrets keystore for secure settings | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/keystore.html#add-keys-to-keystore)**

For something like  
`cat /file/containing/setting/value | filebeat keystore add ES_PWD --stdin --force`  
and then use it in the yml file:  
`output.elasticsearch.password: "${ES_PWD}"`

How to use that in ansible, I don't want to reinvent the wheel.  
Here you should find a working example, you just need to translate it from kibana to filebeat command style:

> [@How to fill keystore via ansible script](https://discuss.elastic.co/t/how-to-fill-keystore-via-ansible-script/212117/4):
>
> During creating the Bug Report I found this on github: With the given information there I was able to get it running: - name: keystore tasks block: - name: create keystore if not existing yet shell: cmd: "./kibana-keystore create" chdir: "/usr/share/kibana/bin" creates: /var/lib/kibana/kibana.keystore - name: keystore - add elasticsearch.password shell: cmd: "/usr/share/kibana/bin/kibana-keystore add elasticsearch.password --stdin --forc…

The similar should be possible with a remote exec provisioner:

> **[Provisioner: remote-exec | Terraform | HashiCorp Developer](https://developer.hashicorp.com/terraform/language/resources/provisioners/remote-exec)**
>
> The \`remote-exec\` provisioner invokes a script on a remote resource after it is created. This can be used to run a configuration management tool, bootstrap into a cluster, etc. To invoke a local process, see the \`local-exec\` provisioner instead. The...

---

_[View the full topic](https://discuss.elastic.co/t/recommended-way-of-storing-credentials-in-beats-configuration-file/235081)._
