# Set metricbeat password from file in kubernetes, is it possible?

**URL:** <https://discuss.elastic.co/t/set-metricbeat-password-from-file-in-kubernetes-is-it-possible/375361>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [March 4, 2025, 10:07am UTC](https://discuss.elastic.co/t/set-metricbeat-password-from-file-in-kubernetes-is-it-possible/375361 "2025-03-04T10:07:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TomH](https://avatars.discourse-cdn.com/v4/letter/t/90db22/32.png) [@TomH](https://discuss.elastic.co/u/TomH)\
**Post date:** [March 4, 2025, 10:07am UTC](https://discuss.elastic.co/t/set-metricbeat-password-from-file-in-kubernetes-is-it-possible/375361/1 "2025-03-04T10:07:29Z")

</div>

Setting elastic password via environment variable is not particularly secure so we want to  
set it via file. The file is provided by kubernetes CSI driver.

The suggestion for metricbeat on kubernetes that I found so far is to change from the env variant:

output.elasticsearch:  
username: ${ELASTICSEARCH\_USERNAME}  
password: ${ELASTICSEARCH\_PASSWORD}

To this

output.elasticsearch:  
username: ${ELASTICSEARCH\_USERNAME}  
password: ${file:/mnt/secrets-volume/elkPassword}

There is a file in /mnt/secrets-volume/ called elkPassword that  
contains the password. This file is mounted dynamically at pod-creation by the CSI driver.

Any ideas why this does not work?

Is the syntax incorrect or is it just impossible to read  
a password from a file?

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [March 4, 2025, 1:17pm UTC](https://discuss.elastic.co/t/set-metricbeat-password-from-file-in-kubernetes-is-it-possible/375361/2 "2025-03-04T13:17:15Z")

</div>

You might be interested in this section of the docs:

> **[Secrets keystore for secure settings | Metricbeat Reference \[8.17\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/keystore.html)**

I don't personally recognize the `password: ${file:/path/to-/a/file/with/the/password}` syntax? Did you get this syntax from some sort of documentaiton?

---

<div class="post-metadata">

**Author:** ![TomH](https://avatars.discourse-cdn.com/v4/letter/t/90db22/32.png) [@TomH](https://discuss.elastic.co/u/TomH)\
**Post date:** [March 5, 2025, 7:31am UTC](https://discuss.elastic.co/t/set-metricbeat-password-from-file-in-kubernetes-is-it-possible/375361/3 "2025-03-05T07:31:46Z")

</div>

Yeah, using the keystore was my workaround. At the startup of the pod  
I run some commands that create the keystore and adds the password as ES\_PWD  
which is then picked up by metricbeat. A bit clunky but it sort of works.

It looks like this if anyone is interested:

Set up output.elasticsearch as normal:

```auto
output.elasticsearch:
username: ${ELASTICSEARCH_USERNAME}
password: ${ES_PWD}

```

and then I added to my Daemonset in the containers section:

```auto
containers: [
{
    lifecycle: {
    postStart: {
        exec: {
            command: ["/bin/sh", "-c", "metricbeat keystore create; cat /mnt/secrets-volume/elkPassword | metricbeat keystore add ES_PWD --stdin --force"]
        }
    }
},                    
name: "metricbeat",
...

```

Note that this requires the file to be mounted at the /mnt/... path using  
volumes and volumeMount and actually injecting the file at runtime (using a CSI driver for example).

Regarding the ${file:/mnt/... syntax, I cannot find it again, done some extensive searching, very possible it was dreamed up by an attempt to  
get some info from an AI 🙂

Thanks for looking at this!
