# Setting up Minimal Security with ElasticSearch Docker Image fails

**URL:** <https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [April 1, 2024, 2:45pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562 "2024-04-01T14:45:28Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 1, 2024, 2:45pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/1 "2024-04-01T14:45:28Z")

</div>

Hello everyone,

I was wondering if I could get some assistance with setting up Minimal Security (Username + Password to access the console as outlined here: [Set up minimal security for Elasticsearch | Elasticsearch Guide [8.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html)) with containers.

The Dockerfile right now is simple:

```auto
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/

```

Just copying over some configs as we're running this on Kubernetes. Here's our elasticsearch.yml file:

```auto
# Cluster settings
cluster.name: test-elasticsearch-cluster
network.host: 0.0.0.0

#cluster settings
cluster.routing.allocation.disk.threshold_enabled: true
cluster.routing.allocation.disk.watermark.low: 512mb
cluster.routing.allocation.disk.watermark.high: 256mb
cluster.routing.allocation.disk.watermark.flood_stage: 128mb
discovery.type: single-node

# cluster security settings
xpack.security.enabled: false

```

Now I've tried a number of different things to change the password of the "elastic" user to start setting up the Minimal Security, but they don't seem to work for me for building the container. These containers are going to be ran on a Kubernetes cluster

For example, I've tried updating the Dockerfile like so from [this thread](https://discuss.elastic.co/t/automate-elasticsearch-reset-password-in-bash-script/317429/5):

```auto
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/
WORKDIR /usr/share/elasticsearch/
RUN printf "elk-testing" | ./bin/elasticsearch-keystore add "bootstrap.password" -x -f

```

But that didn't seem to update the password as I had thought it would. I've also tried to build this Dockerfile, that I also saw from the same post, this seemed like it would accomplish what I needed but couldn't get it to complete the Docker build:

```auto
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/
WORKDIR /usr/share/elasticsearch/
RUN printf "elk-testing" | ./bin/elasticsearch-reset-password -b -i -u elastic

```

I also came across this [API documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-change-password.html) but couldn't get it to work as I need to authenticate as the "elastic" user which we haven't set up a password for yet.

Any guidance would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 1, 2024, 2:50pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/2 "2024-04-01T14:50:55Z")

</div>

Hi @tryin2stupelk Welcome to the community

> [@tryin2stupelk](#):
>
> `xpack.security.enabled: false`

You have turned off all security with that setting... so you can not set users and passwords.

I would review the documents here for minimal security

> **[Set up minimal security for Elasticsearch | Elasticsearch Guide \[8.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html)**

Also the official docker documentation [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html)

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 1, 2024, 4:04pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/3 "2024-04-01T16:04:30Z")

</div>

Thank you for the welcome! Oh sorry about that, that's a Copy/Paste typo as I was editing, I do in fact have `xpack.security.enabled: true`, I'll edit the original post. Looks like I can no longer edit the original post. This is what I currently have:

```auto
# Cluster settings
cluster.name: test-elasticsearch-cluster
network.host: 0.0.0.0

#cluster settings
cluster.routing.allocation.disk.threshold_enabled: true
cluster.routing.allocation.disk.watermark.low: 512mb
cluster.routing.allocation.disk.watermark.high: 256mb
cluster.routing.allocation.disk.watermark.flood_stage: 128mb
discovery.type: single-node

# cluster security settings
xpack.security.enabled: true

```

Thank you for the Documentation link! That's the same documentation I was following, but was having difficulty importing those changes into a Dockerfile to be used as a Docker Container with the Minimal Security setup.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 1, 2024, 4:12pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/4 "2024-04-01T16:12:19Z")

</div>

> [@tryin2stupelk](#):
>
> ```auto
> cluster.routing.allocation.disk.threshold_enabled: true
> cluster.routing.allocation.disk.watermark.low: 512mb
> cluster.routing.allocation.disk.watermark.high: 256mb
> cluster.routing.allocation.disk.watermark.flood_stage: 128mb
> 
> ```

Those are pretty tiny...

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 1, 2024, 4:35pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/5 "2024-04-01T16:35:03Z")

</div>

Would you recommend something like the following? We're thinking to use smaller nodes:

```auto
# Cluster settings
cluster.name: test-elasticsearch-cluster
network.host: 0.0.0.0

#cluster settings
cluster.routing.allocation.disk.threshold_enabled: true
cluster.routing.allocation.disk.watermark.low: 4gb
cluster.routing.allocation.disk.watermark.high: 2gb
cluster.routing.allocation.disk.watermark.flood_stage: 1gb
discovery.type: single-node

# cluster security settings
xpack.security.enabled: true

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 1, 2024, 4:38pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/6 "2024-04-01T16:38:16Z")

</div>

All depends on your use case.... just be aware....

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 2, 2024, 2:22am UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/7 "2024-04-02T02:22:03Z")

</div>

> [@tryin2stupelk](#):
>
> But that didn't seem to update the password as I had thought it would.

Does your node preserve its data directory between restarts (hopefully it does, or you'll lose all your data every time).  
If it does, and you already have a password for the `elastic` user (which may have been auto generated) then setting `bootstrap.password` won't help you - security has already been bootstrapped.

It's hard to give useful advice because I don't understand your current state very well.

There are several options for configuring security on docker because docker is used for a wide variety of use cases from throw away test containers to long-running development instances, to mission critical production workloads. There will be an option that suits you, but you'll need to decide which one it is.

If you want to start a brand new container (with no existing data) with a known password for the `elastic` user, then you can set `ELASTIC_PASSWORD` to the value of the password. That's not ideal because it leaves the password in clear text in the environment variable and inside the node's keystore. But for a throwaway / dev instance that's super easy.

For more security you can do the above, and then change the password via the API after the cluster has formed.

You can run an interactive container (`-i -t`) and the randomly generated `elastic` password will be provided in the console. That's good for local manual setup, but not so good for scripted setup.

You can enter the docker container and run reset-password

You can configure a file realm user as part of your initial set up so that you have a separate superuser with a password under your control.

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 2, 2024, 2:56pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/8 "2024-04-02T14:56:43Z")

</div>

Thank you for your response Tim!

> Does your node preserve its data directory between restarts

This is a great point! Right now we do have an external mount that the Pods can use to persist data, we'll have to make sure to use it for the Elastic Pods as well!

For the first option of setting `ELASTIC_PASSWORD`, will the following work (We're using kubernetes configmap for the value of `elasticsearch.hosts:` in the kibana yaml config file)?

**elasticsearch Dockerfile:**

```auto
# Elasticsearch Dockerfile
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/
ENV ELASTIC_PASSWORD test-elastic-pass
ENV KIBANA_PASSWORD test-kibana-pass

```

* * *

**elasticsearch.yaml:**

```auto
# Cluster settings
cluster.name: test-elastic-cluster
network.host: 0.0.0.0

#cluster settings
cluster.routing.allocation.disk.threshold_enabled: true
cluster.routing.allocation.disk.watermark.low: 4gb
cluster.routing.allocation.disk.watermark.high: 2gb
cluster.routing.allocation.disk.watermark.flood_stage: 1gb
discovery.type: single-node

# security settings
xpack.security.enabled: true

```

* * *

**Kibana Dockerfile:**

```auto
FROM docker.elastic.co/kibana/kibana:8.12.2
COPY --chown=1000:0 config/kibana.yml /usr/share/kibana/config/kibana.yml
RUN ./bin/kibana-keystore create
RUN printf "test-kibana-pass" | ./bin/kibana-keystore add elasticsearch.password --stdin
RUN ./bin/kibana

```

* * *

**kibana.yml:**

```auto
server.name: kibana
server.host: "0.0.0.0"
elasticsearch.hosts: ["${ELASTICSEARCH_URL}"]
elasticsearch.username: "kibana_system"
monitoring.ui.container.elasticsearch.enabled: true

```

If the above looks correct, would we access the API inside the Pod to update the password, or could we do it from outside the Pod as well?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 3, 2024, 1:35am UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/9 "2024-04-03T01:35:52Z")

</div>

I don't believe there is any option to set `KIBANA_PASSWORD` like that.

The docker compose example in the docs uses the API to set the Kibana password.

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 3, 2024, 3:37pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/10 "2024-04-03T15:37:03Z")

</div>

Hey Tim,

So I deployed the following Dockerfile, the same as above but removed the Kibana Password, for the Elasticsearch container:

```auto
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/
ENV ELASTIC_PASSWORD test-elastic-pass

```

When I dropped into the Pod to test the password using the command `curl -X GET "localhost:9200/_cluster/health?pretty"` I get the following authentication error:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "unable to authenticate user [elastic] for REST request [/_cluster/health?pretty]",
        "header" : {
          "WWW-Authenticate" : [
            "Basic realm=\"security\" charset=\"UTF-8\"",
            "ApiKey"
          ]
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "unable to authenticate user [elastic] for REST request [/_cluster/health?pretty]",
    "header" : {
      "WWW-Authenticate" : [
        "Basic realm=\"security\" charset=\"UTF-8\"",
        "ApiKey"
      ]
    }
  },
  "status" : 401
}

```

* * *

Is there another step to take with the environment variable being set in the Dockerfile to get it to use that password for elastic user?

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 3, 2024, 8:09pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/11 "2024-04-03T20:09:19Z")

</div>

Sorry, the correct command I used was: `curl -X GET "localhost:9200/_cluster/health?pretty" -u elastic:test-elastic-pass` passing in the password set in the Dockerfile ENV to "elastic" user which resulted in:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "unable to authenticate user [elastic] for REST request [/_cluster/health?pretty]",
        "header" : {
          "WWW-Authenticate" : [
            "Basic realm=\"security\" charset=\"UTF-8\"",
            "ApiKey"
          ]
        }
      }
    ],
    "type" : "security_exception",
    "reason" : "unable to authenticate user [elastic] for REST request [/_cluster/health?pretty]",
    "header" : {
      "WWW-Authenticate" : [
        "Basic realm=\"security\" charset=\"UTF-8\"",
        "ApiKey"
      ]
    }
  },
  "status" : 401
}

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 4, 2024, 12:04am UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/12 "2024-04-04T00:04:10Z")

</div>

I copied your dockerfile, and the yml file you posted earlier, built and ran the image and it works fine for me.

I'm not sure what you're doing differently, but what you've posted should work.

```plaintext
$ head -99 Dockerfile config/elasticsearch.yml
==> Dockerfile <==
FROM docker.elastic.co/elasticsearch/elasticsearch:8.12.2
COPY config/elasticsearch.yml config/
ENV ELASTIC_PASSWORD test-elastic-pass

==> config/elasticsearch.yml <==
# Cluster settings
cluster.name: test-elastic-cluster
network.host: 0.0.0.0

#cluster settings
cluster.routing.allocation.disk.threshold_enabled: true
cluster.routing.allocation.disk.watermark.low: 4gb
cluster.routing.allocation.disk.watermark.high: 2gb
cluster.routing.allocation.disk.watermark.flood_stage: 1gb
discovery.type: single-node

# security settings
xpack.security.enabled: true

$ docker build .
...
$ docker run -p 9200:9200 -m 2GB <image-id>
...

```

```plaintext
curl -u elastic:test-elastic-pass http://localhost:9200/_security/_authenticate | jq .
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 263 100 263 0 0 15468 0 --:--:-- --:--:-- --:--:-- 16437
{
  "username": "elastic",
  "roles": [
    "superuser"
  ],
  "full_name": null,
  "email": null,
  "metadata": {
    "_reserved": true
  },
  "enabled": true,
  "authentication_realm": {
    "name": "reserved",
    "type": "reserved"
  },
  "lookup_realm": {
    "name": "reserved",
    "type": "reserved"
  },
  "authentication_type": "realm"
}

```

---

<div class="post-metadata">

**Author:** ![tryin2stupelk](https://avatars.discourse-cdn.com/v4/letter/t/ee59a6/32.png) [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Post date:** [April 5, 2024, 2:46pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/13 "2024-04-05T14:46:04Z")

</div>

Thank you Tim! Looks like there might be something else in our environment preventing this from working since you were able to get it working with the same Dockerfile and config file.

Appreciate all the help! I can go ahead and close this topic as we have to do additional troubleshooting that's not related to Elastic at the moment. Thanks again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2024, 2:46pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562/14 "2024-05-03T14:46:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
