# Security Error while integrating SSO with elastic cloud cluster using Terraform

**URL:** <https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967>\
**Category:** Elasticsearch\
**Created:** [March 3, 2023, 6:00pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967 "2023-03-03T18:00:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saicharan\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saicharan_m/32/118024_2.png) [@Saicharan\_M](https://discuss.elastic.co/u/Saicharan_M)\
**Post date:** [March 3, 2023, 6:00pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967/1 "2023-03-03T18:00:17Z")

</div>

I've been trying to provision elastic cluster with SSO configured. As per the latest ec provider documentation we should be able to achieve this in a single workflow. But however, I do see below error while provisioning cluster.

[tiebreaker-0000000002] fatal exception while booting Elasticsearch java.lang.IllegalStateException: security initialization failed at org.elasticsearch.xpack.security.Security.createComponents(Security.java:578) ~[?:?] at org.elasticsearch.node.Node.lambda$new$16(Node.java:721) ~[elasticsearch-8.6.2.jar:?] at org.elasticsearch.plugins.PluginsService.lambda$flatMap$0(PluginsService.java:252) ~[elasticsearch-8.6.2.jar:?] at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:273) ~[?:?] at java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:197) ~[?:?] at java.util.AbstractList$RandomAccessSpliterator.forEachRemaining(AbstractList.java:722) ~[?:?] at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:509) ~[?:?] at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:499) ~[?:?] at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:575) ~[?:?] at java.util.stream.AbstractPipeline.evaluateToArrayNode(AbstractPipeline.java:260) ~[?:?] at java.util.stream.ReferencePipeline.toArray(ReferencePipeline.java:616) ~[?:?] at java.util.stream.ReferencePipeline.toArray(ReferencePipeline.java:622) ~[?:?] at java.util.stream.ReferencePipeline.toList(ReferencePipeline.java:627) ~[?:?] at org.elasticsearch.node.Node.(Node.java:736) ~[elasticsearch-8.6.2.jar:?] at org.elasticsearch.node.Node.(Node.java:322) ~[elasticsearch-8.6.2.jar:?] at org.elasticsearch.bootstrap.Elasticsearch$2.(Elasticsearch.java:214) ~[elasticsearch-8.6.2.jar:?] at org.elasticsearch.bootstrap.Elasticsearch.initPhase3(Elasticsearch.java:214) ~[elasticsearch-8.6.2.jar:?] at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:67) ~[elasticsearch-8.6.2.jar:?] Caused by: org.elasticsearch.common.settings.SettingsException: The configuration setting [xpack.security.authc.realms.oidc.oidc1.rp.client\_secret] is required at org.elasticsearch.xpack.security.authc.oidc.OpenIdConnectRealm.buildRelyingPartyConfiguration(OpenIdConnectRealm.java:256) ~[?:?] at org.elasticsearch.xpack.security.authc.oidc.OpenIdConnectRealm.(OpenIdConnectRealm.java:98) ~[?:?] at org.elasticsearch.xpack.security.authc.InternalRealms.lambda$getFactories$7(InternalRealms.java:169) ~[?:?] at org.elasticsearch.xpack.security.authc.Realms.initRealms(Realms.java:288) ~[?:?] at org.elasticsearch.xpack.security.authc.Realms.(Realms.java:109) ~[?:?] at org.elasticsearch.xpack.security.Security.createComponents(Security.java:686) ~[?:?] at org.elasticsearch.xpack.security.Security.createComponents(Security.java:566) ~[?:?]

But however in my terraform code , I am providing the keystore value as below -

resource "ec\_deployment\_elasticsearch\_keystore" "client\_secret" {  
deployment\_id = ec\_deployment.test\_deployment.id  
setting\_name = "xpack.security.authc.realms.oidc.oidc1.rp.client\_secret"  
value = ""  
}

And here's elasticsearch.yaml file content :  
xpack:  
security:  
authc:  
realms:  
oidc:  
oidc1:  
order: 2  
rp.client\_id: "\<\>"  
rp.response\_type: "code"  
rp.requested\_scopes: ["openid", "email", "groups", "profile"]  
rp.redirect\_uri: "${kibana\_url}/api/security/oidc/callback"  
op.issuer: "\<\>"  
op.authorization\_endpoint: "\<\>"  
op.token\_endpoint: "\<\>"  
op.userinfo\_endpoint: "\<\>"  
op.endsession\_endpoint: "\<\>"  
op.jwkset\_path: "\<\>"  
claims.principal: "user"  
claim\_patterns.principal: "^([^@]+)$"  
claims.groups: "groups"

Any help would be appreciated.

Thanks,  
Sai

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 3, 2023, 7:08pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967/2 "2023-03-03T19:08:16Z")

</div>

Hi @Saicharan_M Welcome to the community.

Can you format your code and logs please using the `</>` button and make sure you yml is properly formatted it.

Would you perhaps share your tf configuration?

Which documentation shows a single flow... is it [this](https://registry.terraform.io/providers/elastic/ec/latest/docs/guides/configuring-sso-ec-deployment). I think that assume all the values are in the `es.yml`

What I do think I am reading from the errors is that the deployment is trying to use the keystore / get values before the keystore is ready...

I suspect you may need to create the deployment with the keystore and then apply the SAML config.

However I am not a TF expert but that is what I read from the logs

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2023, 7:08pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967/3 "2023-03-17T19:08:54Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
