# S3 repository creation failing for cluster

**URL:** <https://discuss.elastic.co/t/s3-repository-creation-failing-for-cluster/121591>\
**Category:** Elasticsearch\
**Created:** [February 27, 2018, 4:28am UTC](https://discuss.elastic.co/t/s3-repository-creation-failing-for-cluster/121591 "2018-02-27T04:28:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pri](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@pri](https://discuss.elastic.co/u/pri)\
**Post date:** [February 27, 2018, 4:28am UTC](https://discuss.elastic.co/t/s3-repository-creation-failing-for-cluster/121591/1 "2018-02-27T04:28:53Z")

</div>

Hi,

I am trying to register a s3 repository for my elasticsearch cluster which has 2 data nodes, 1 master and 1 client. The ES version is 6.1  
When I issue the \_snapshot command, I get the following error

> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "repository\_verification\_exception",  
> "reason": "[hcdd\_stg\_repository] [[\_KD96f6KR6iS8qrGDTSXXA, 'RemoteTransportException[[dd-es-stg-node-1][xx.xxx.xx.xxx:9300][internal:admin/repository/verify]]; nested: RepositoryMissingException[[hcdd\_stg\_repository] missing];'], [OAjFobxlRYeauUGZL2m21w, 'RemoteTransportException[[dd-es-stg-node-2][yy.yyy.yy.yy:9300][internal:admin/repository/verify]]; nested: RepositoryMissingException[[hcdd\_stg\_repository] missing];']]"  
> }  
> ],  
> "type": "repository\_verification\_exception",  
> "reason": "[hcdd\_stg\_repository] [[\_KD96f6KR6iS8qrGDTSXXA, 'RemoteTransportException[[dd-es-stg-node-1][xx.xxx.xx.xxx:9300][internal:admin/repository/verify]]; nested: RepositoryMissingException[[hcdd\_stg\_repository] missing];'], [OAjFobxlRYeauUGZL2m21w, 'RemoteTransportException[[dd-es-stg-node-2][yy.yyy.yy.yy:9300][internal:admin/repository/verify]]; nested: RepositoryMissingException[[hcdd\_stg\_repository] missing];']]"  
> },  
> "status": 500  
> }

I added DEBUG logging but did not find anything useful. I have tried putting and deleting files to s3 directly from my ec2 instances (ES nodes) without issues using AWS cli. This proves that permissions are not an issue. I have the IAM role created and assigned to these instances and my IAM policy looks like this:

> {  
> "Statement": [  
> {  
> "Action": [  
> "s3:ListBucket",  
> "s3:GetBucketLocation",  
> "s3:ListBucketMultipartUploads",  
> "s3:ListBucketVersions"  
> ],  
> "Effect": "Allow",  
> "Resource": [  
> "arn:aws:s3:::snaps.example.com"  
> ]  
> },  
> {  
> "Action": [  
> "s3:GetObject",  
> "s3:PutObject",  
> "s3:DeleteObject",  
> "s3:AbortMultipartUpload",  
> "s3:ListMultipartUploadParts"  
> ],  
> "Effect": "Allow",  
> "Resource": [  
> "arn:aws:s3:::snaps.example.com/\*"  
> ]  
> }  
> ],  
> "Version": "2012-10-17"  
> }

When I try registering the repository as read only, it succeeds.  
What am I missing? Thanks for your help.

---

<div class="post-metadata">

**Author:** ![pri](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@pri](https://discuss.elastic.co/u/pri)\
**Post date:** [March 13, 2018, 12:42am UTC](https://discuss.elastic.co/t/s3-repository-creation-failing-for-cluster/121591/2 "2018-03-13T00:42:06Z")

</div>

A restart of elasticsearch on all the cluster nodes fixed the issue. I think it has to do with the fact that the IAM role was created and assigned to these ec2 instances that were already running. Thought will provide an update if somebody else faces the same issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 12:42am UTC](https://discuss.elastic.co/t/s3-repository-creation-failing-for-cluster/121591/3 "2018-04-10T00:42:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
