# Run elasticsearch as root

**URL:** <https://discuss.elastic.co/t/run-elasticsearch-as-root/174338>\
**Category:** Elasticsearch\
**Created:** [March 28, 2019, 12:58pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338 "2019-03-28T12:58:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![freaka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freaka/32/41962_2.png) [@freaka](https://discuss.elastic.co/u/freaka)\
**Post date:** [March 28, 2019, 12:58pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338/1 "2019-03-28T12:58:50Z")

</div>

Hi,

I have read on multiple occasions that you cannot run elasticsearch as root. I understand the principle behind this and I agree. However, due to very specific installation constraints, we do not install our solution (a series of java modules + elasticsearch) ourselves, we create an installer (a bash script) and the customer runs it as root.  
This last part (running as root) is new information to us and now we are sort of stuck and don't know how to run elasticsearch.

Is it a good idea to fork the elasticsearch project, modify the part that throws the exception, package it and use this modified version instead of the official elasticsearch? It sounds like a bad idea to do so but we cannot find a proper workaround so far.

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 28, 2019, 2:07pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338/2 "2019-03-28T14:07:22Z")

</div>

> [@freaka](#):
>
> Is it a good idea to fork the elasticsearch project, modify the part that throws the exception, package it and use this modified version instead of the official elasticsearch? It sounds like a bad idea to do so but we cannot find a proper workaround so far.

You are correct that this is a bad idea. You should work with your customer(s) to identify or create a non-`root` user as whom you can run Elasticsearch.

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [March 28, 2019, 2:25pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338/3 "2019-03-28T14:25:34Z")

</div>

If your scripts run as root why not let the script create the elasticsearch user and then use that?

---

<div class="post-metadata">

**Author:** ![freaka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freaka/32/41962_2.png) [@freaka](https://discuss.elastic.co/u/freaka)\
**Post date:** [March 28, 2019, 4:37pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338/4 "2019-03-28T16:37:50Z")

</div>

Thanks for the inputs. We will have a `bash` fluent engineer or two look into that issue before considering the very bad solution I mentioned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2019, 4:38pm UTC](https://discuss.elastic.co/t/run-elasticsearch-as-root/174338/5 "2019-04-25T16:38:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
