# Reset elastic user password in docker container

**URL:** <https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [August 10, 2022, 9:26pm UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884 "2022-08-10T21:26:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![single.track.mind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/single.track.mind/32/97440_2.png) [@single.track.mind](https://discuss.elastic.co/u/single.track.mind)\
**Post date:** [August 10, 2022, 9:26pm UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884/1 "2022-08-10T21:26:19Z")

</div>

I have inherited a 7.16.2 elastic cluster with Basic license, running in docker containers(using docker-compose) and am trying to add xpack.security.enabled=true as an intermediate step to configure internal user passwords before applying the rest of the TLS/xpack related config(transport, http).

The issue I'm having is that someone before me has already ran `elasticsearch-setup-passwords` so I cannot run it again and ultimately not able to figure out how to reset the current elastic user password to continue on.

I have tried to use ELASTIC\_PASSWORD=passwd and also ELASTIC\_PASSWORD\_FILE=/path/to/file in my docker compose file to no avail. I'm not sure if i'm missing something related to docker but I did `docker rm` the elastic containers for a fresh start before bringing up configs with these changes. The other solutions that i'm finding don't seem to apply to elasticsearch running in containers.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [August 10, 2022, 10:39pm UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884/2 "2022-08-10T22:39:13Z")

</div>

> **[Install Elasticsearch with Docker | Elasticsearch Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/docker.html#docker-configuration-methods)**

use `ELASTIC_PASSWORD_FILE`, just don't forget to mount the file into the container... and when you run your container, check logs..

---

<div class="post-metadata">

**Author:** ![single.track.mind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/single.track.mind/32/97440_2.png) [@single.track.mind](https://discuss.elastic.co/u/single.track.mind)\
**Post date:** [August 10, 2022, 10:54pm UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884/3 "2022-08-10T22:54:24Z")

</div>

I did add the password file to the volume i'm using for the certs I intend on using. After fixing some file perms, I got the elasticsearch containers to start with this in the logs, which suggests it should be working:

`Setting ELASTIC_PASSWORD from ELASTIC_PASSWORD_FILE at /usr/share/elasticsearch/config/ssl/elastic_password`

The password I added to the file did not work to authenticate a curl request. Does using the ELASTIC\_PASSWORD\_FILE override a previously set password? I'm curious because the documentation is referring to this method as an 'Elasticsearch bootstrap password', which perhaps suggests that one isn't already set??

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [August 11, 2022, 12:30am UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884/4 "2022-08-11T00:30:55Z")

</div>

You can just go into one of the container and manually add a file realm superuser following this [doc page](https://www.elastic.co/guide/en/elasticsearch/reference/current/users-command.html). Then use the file realm superuser to change other user's password.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2022, 12:31am UTC](https://discuss.elastic.co/t/reset-elastic-user-password-in-docker-container/311884/5 "2022-09-08T00:31:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
