# Repository-s3 plugin does not support S3-compatible services as documentation says

**URL:** <https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [February 10, 2021, 12:05pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866 "2021-02-10T12:05:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krzysztof\_Szymanski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krzysztof_szymanski/32/83666_2.png) [@Krzysztof\_Szymanski](https://discuss.elastic.co/u/Krzysztof_Szymanski)\
**Post date:** [February 10, 2021, 12:05pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866/1 "2021-02-10T12:05:32Z")

</div>

Hi is there anyone who achieve configuring repository-s3 plugin to work with S3-compatible service like CEPH. I completely follow the documentation (and many forums) and try to configure it but every time I failed. I did following things:

I installed repository-s3 plugin:

```auto
bin/elasticsearch-plugin install --batch repository-s3

```

I set appropriate parameters in elasticsearch.yml config file (on all of my tree nodes) and restart each node:

```auto
s3:
  client:
    default:
      region: "default"
      max_retries: 3
      protocol: "https"
      endpoint: "<my_ceph_endpoint>"
      signer_override: "S3SignerType"
      read_timeout: "180s"

```

I add secret key and access key to keystore (on all of my tree nodes) as documentation says:

```auto
echo <access_key> | bin/elasticsearch-keystore add --stdin s3.client.default.access_key
echo <secret_key> | bin/elasticsearch-keystore add --stdin s3.client.default.secret_key

```

I reload secure settings (on all of my tree nodes):

```auto
curl -u <user>:<password> -X POST "https://<elasticsearch_url>:9200/_nodes/reload_secure_settings"

```

Then I try to create snapshot repository (bucket exists and was created with usage of the same access and secret keys):

```auto
curl -u <user>:<password> -X PUT https://<elasticsearch_url>:9200/_snapshot/test1 -H 'Content-Type: application/json' -d'
{
  "type": "s3",
  "settings": {
    "client": "default",
    "bucket": "<bucket_name>"
  }
}'

```

No matter what I do I always get response like this:

```auto
{"error":{"root_cause":[{"type":"repository_verification_exception","reason":"[test1] path is not accessible on master node"}],"type":"repository_verification_exception","reason":"[test1] path is not accessible on master node","caused_by":{"type":"i_o_exception","reason":"Unable to upload object [tests-Ds-i_M2TRf2fl5D1W4ovMg/master.dat] using a single upload","caused_by":{"type":"sdk_client_exception","reason":"The requested metadata is not found at http://169.254.169.254/latest/meta-data/iam/security-credentials/"}}},"status":500}

```

It seems that it always asks this endpoint `http://169.254.169.254/latest/meta-data/iam/security-credentials/` but my instances are not AWS (they are on OpenStack).

Can anyone explain me what happens here? Is there anything that I missed? Or it is simply impossible with current repository-s3 plugin and documentation is faulty?

I tried it on Elasticsearch 7.7.0 and on 7.10.0 versions

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 10, 2021, 12:28pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866/2 "2021-02-10T12:28:37Z")

</div>

> [@Krzysztof\_Szymanski](#):
>
> Can anyone explain me what happens here? Is there anything that I missed? Or it is simply impossible with current repository-s3 plugin and documentation is faulty?

It's definitely possible, but if your cluster is accessing `http://169.254.169.254/latest/meta-data/iam/security-credentials/` then you have not configured the credentials in the keystore correctly on all nodes.

---

<div class="post-metadata">

**Author:** ![Krzysztof\_Szymanski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krzysztof_szymanski/32/83666_2.png) [@Krzysztof\_Szymanski](https://discuss.elastic.co/u/Krzysztof_Szymanski)\
**Post date:** [February 10, 2021, 1:30pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866/3 "2021-02-10T13:30:16Z")

</div>

Thank you very much that tip was helpful, my script which saves that keys in keystore was somewhere faulty

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2021, 1:31pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-s3-compatible-services-as-documentation-says/263866/4 "2021-03-10T13:31:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
