# Setup snapshots with minio, unable to retrieve secrets

**URL:** <https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [October 4, 2019, 1:42pm UTC](https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351 "2019-10-04T13:42:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kent\_Brake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kent_brake/32/51426_2.png) [@Kent\_Brake](https://discuss.elastic.co/u/Kent_Brake)\
**Post date:** [October 4, 2019, 1:42pm UTC](https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351/1 "2019-10-04T13:42:02Z")

</div>

Hi,

I'm trying to setup snapshot with a local minion instance, but I can't seem to imports secrets as documented [here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-snapshot.html).

I setup the secrets with:

kubectl create secret generic minio-credentials --from-file=s3.client.default.access\_key --from-file=s3.client.default.secret\_key

Then added it to the elasticsearch yaml file:

secureSettings:  
secretName: "minio-credentials"

I can see in the operator logs that its picked up:

```
{"level":"info","ts":1570195646.0524664,"logger":"license-validation","msg":"ValidationHandler handler called","operation":"CREATE","name":" **minio-credentials**","namespace":"default"}

```

{"level":"info","ts":1570195684.2096705,"logger":"es-validation","msg":"ValidationHandler handler called","operation":"UPDATE","name":"quickstart","namespace":"default"}

But when I setup via console

```
PUT /_snapshot/my_minio_repository

```

{  
"type": "s3",  
"settings": {  
"bucket": "esbackups",  
"endpoint": "10.1.1.220:9000",  
"protocol": "http"  
}  
}

I get this error:

```
{

```

"error": {  
"root\_cause": [  
{  
"type": "repository\_verification\_exception",  
"reason": "[my\_minio\_repository] path is not accessible on master node"  
}  
],  
"type": "repository\_verification\_exception",  
"reason": "[my\_minio\_repository] path is not accessible on master node",  
"caused\_by": {  
"type": "i\_o\_exception",  
"reason": "Unable to upload object [tests-86\_qgPYEQ3KdDtlhf6kK2g/master.dat] using a single upload",  
"caused\_by": {  
"type": "sdk\_client\_exception",  
"reason": "sdk\_client\_exception: Unable to load credentials from service endpoint",  
"caused\_by": {  
"type": "i\_o\_exception",  
"reason": "Connect timed out"  
}  
}  
}  
},  
"status": 500  
}

---

<div class="post-metadata">

**Author:** ![aros](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@aros](https://discuss.elastic.co/u/aros)\
**Post date:** [October 10, 2019, 11:11am UTC](https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351/2 "2019-10-10T11:11:34Z")

</div>

Hi,

I am experiencing the same problem with wasabi on Elasticsearch 7.4. I set the access key and secret key in the elasticsearch keystore by hand:

bin/elasticsearch-keystore add s3.client.default.access\_key  
bin/elasticsearch-keystore add s3.client.default.secret\_key

Registering a repository is done by

PUT \_snapshot/my\_wasabi\_repository  
{  
"type": "s3",  
"settings": {  
"bucket": "es-backup",  
"endpoint": "[https://s3.eu-central-1.wasabisys.com](https://s3.eu-central-1.wasabisys.com)",  
"protocol": "https"  
}  
}

The response is the same as posted by Kent, repository verification failed.

This procedure was working on 7.2, right now I am not sure if the problem is down to the credentials in the keystore or if maybe some defaults in the s3 client changed in a way that affects non AWS S3 services.

Can someone see what is wrong or missing or maybe share experiences with repositories in non AWS S3 services for elasticsearch 7.4?

Thanks in advance!  
Andrej

---

<div class="post-metadata">

**Author:** ![aros](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@aros](https://discuss.elastic.co/u/aros)\
**Post date:** [October 24, 2019, 8:43pm UTC](https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351/3 "2019-10-24T20:43:51Z")

</div>

After trying to figure out what went wrong for quite a while I can actually confirm that the registration of the repository as posted is correct and working. In my case the problem was first a wrong usage of the keystore (rtfm!), after that we figured out that creating a key from a secret in kubernetes was not working correct with the helm chart of elastic (see github for reported bug concerning keys from secrets). After updating to elastic 7.4.1 this problem was solved and keys are created from secrets in a correct way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:28am UTC](https://discuss.elastic.co/t/setup-snapshots-with-minio-unable-to-retrieve-secrets/202351/4 "2022-11-04T07:28:06Z")

</div>


