# Retrieving APM Secret from Elastic EC Provider

**URL:** <https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653>\
**Category:** APM\
**Tags:** server\
**Created:** [November 10, 2022, 12:12pm UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653 "2022-11-10T12:12:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hayden\_WB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayden_wb/32/100898_2.png) [@Hayden\_WB](https://discuss.elastic.co/u/Hayden_WB)\
**Post date:** [November 10, 2022, 12:12pm UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/1 "2022-11-10T12:12:33Z")

</div>

Hi folks!

| Key | Value |
| --- | --- |
| Kibana version | 8.3.3 |
| Elasticsearch version | 8.3.3 |
| APM version | 8.3.3 |
| APM Agent language and version | N/A |
| Browser version | N/A |
| Original install method and version | Terraform Integrations Server Block |
| Fresh install or upgraded from other version? | Fresh |
| Is there anything special in your setup? | N/A |

**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:

I can create an Integrations Server using the Elastic EC Terraform Provider by creating an integrations\_server within the ec\_deployment block, as below:

```hcl
resource "ec_deployment" "ec_configuration" {
  name = local.deployment_name
  region = var.aws_region
  version = var.elastic_version
  deployment_template_id = "aws-storage-optimized-v3"

  elasticsearch { [...] }

  lifecycle { [...] }

  kibana { [...] }

  dynamic "integrations_server" {
    for_each = var.globals.stage == "dev" ? [1] : []

    content {
      topology {
        size = "1g"
      }
    }
  }
}

```

But I need to save the APM Secret Token in secure cloud storage, so that this can be picked up by the agents when they are installed (via automation). The [elastic documentation](https://registry.terraform.io/providers/elastic/ec/latest/docs/resources/ec_deployment) states that:

> apm DEPRECATED (Optional) APM instance definition, can only be specified once. It should only be used with deployments with a version prior to 8.0.0.

And that the integrations\_server should instead be used:

> integrations\_server (Optional) Integrations Server instance definition, can only be specified once. It has replaced apm in stack version 8.0.0.

But in the [Attributes Reference](https://registry.terraform.io/providers/elastic/ec/latest/docs/resources/ec_deployment#attributes-reference) section there is no ability to grab the APM secret token when using the integrations\_server block

> - apm\_secret\_token - Auto-generated APM secret\_token, **empty unless an apm resource is specified**.
> - integrations\_server.#.resource\_id - Integrations Server resource unique identifier.
> - integrations\_server.#.region - Integrations Server region.
> - integrations\_server.#.http\_endpoint - Integrations Server resource HTTP endpoint.
> - integrations\_server.#.https\_endpoint - Integrations Server resource HTTPs endpoint.
> - integrations\_server.#.fleet\_https\_endpoint - HTTPs endpoint for Fleet Server.
> - integrations\_server.#.apm\_https\_endpoint - HTTPs endpoint for APM Server.

Is there a way of retrieving the secret token using integrations\_server, or should I instead opt for a workaround: a post-deploy script that interacts with the API to retrieve the secret?

**Steps to reproduce** :

1. Create an Integrations Server using Elastic EC Terraform Provider

**Provide logs and/or server output (if relevant)**:

Terraform error from CI/CD output:

```auto
╷
│ Error: Missing required argument
│ 
│ on main.tf line 38, in module "operations_infrastructure":
│ 38: module "operations_infrastructure" {
│ 
│ The argument "apm_secret_token" is required, but no definition was found.
╵

```

Thanks ever so much in advance!

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [November 14, 2022, 3:22am UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/2 "2022-11-14T03:22:37Z")

</div>

> [@Hayden\_WB](#):
>
> Is there a way of retrieving the secret token using integrations\_server, or should I instead opt for a workaround: a post-deploy script that interacts with the API to retrieve the secret?

There's no way to fetch the secret token from the Elastic Cloud API for integrations\_server - it must instead be fetched from the Fleet integration policy via Kibana. Here's an example of how we're doing that in our testing setup:

> <https://github.com/elastic/apm-server/blob/77aa33f1d43f69ea7ab39dc4e1f67f8e808ea78f/testing/infra/terraform/modules/ec_deployment/deployment.tf#L202-L210>

> <https://github.com/elastic/apm-server/blob/main/testing/infra/terraform/modules/ec_deployment/scripts/secret_token.tftpl>

Alternatively, you can create an API Key via Elasticsearch or Kibana ([APM agent Key API | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/agent-key-api.html)), and configure the agents to use API Key auth.

---

<div class="post-metadata">

**Author:** ![Hayden\_WB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayden_wb/32/100898_2.png) [@Hayden\_WB](https://discuss.elastic.co/u/Hayden_WB)\
**Post date:** [November 17, 2022, 10:55am UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/3 "2022-11-17T10:55:19Z")

</div>

Hi Andrew!

Thanks for your reply - I've actually made some headway in the last day or so, though I'm not entirely sure what changed. I'll share my working:

My ec\_deployment block is unchanged:

```auto
resource "ec_deployment" "ec_configuration" {
  name = local.deployment_name
  region = var.aws_region
  version = var.elastic_version
  deployment_template_id = "aws-storage-optimized-v3"

  elasticsearch { [...] }

  lifecycle { [...] }

  kibana { [...] }

  dynamic "integrations_server" {
    for_each = var.globals.stage == "dev" ? [1] : []

    content {
      topology {
        size = "1g"
      }
    }
  }
}

```

But I am now seeing a value returning for apm\_secret\_token when using integrations\_server in the ec\_deployment block. So the following output block works.

```auto
output "integration_resource_id" {
  value = ec_deployment.ec_configuration.integrations_server[0].resource_id
}

```

Looks like you can grab the apm\_secret\_token when not using the apm block.

I **was** having issues with this before, so will run some additional tests in a clean environment to see if I get the token every time.

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [November 18, 2022, 12:19am UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/4 "2022-11-18T00:19:40Z")

</div>

@Hyaden\_WB `resource_id` and secret token are different things. The resource ID uniquely identifies the integrations server, and (AFAIK) isn't used for authentication. If it can be used for authentication, that would be surprising and probably a bug.

---

<div class="post-metadata">

**Author:** ![Hayden\_WB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hayden_wb/32/100898_2.png) [@Hayden\_WB](https://discuss.elastic.co/u/Hayden_WB)\
**Post date:** [November 18, 2022, 12:26pm UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/5 "2022-11-18T12:26:07Z")

</div>

Thanks Andrew - actually, this was a mistake on my part. I copied the wrong block of code over. It should have been as below:

```auto
output "apm_secret_token" {
  value = ec_deployment.ec_configuration.apm_secret_token
  sensitive = true
}

```

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2022, 8:26am UTC](https://discuss.elastic.co/t/retrieving-apm-secret-from-elastic-ec-provider/318653/6 "2022-12-09T08:26:50Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
