# Setup well know user / roles / credentials on cluster setup

**URL:** <https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 23, 2021, 3:26pm UTC](https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218 "2021-02-23T15:26:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aiqu4poo](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@Aiqu4poo](https://discuss.elastic.co/u/Aiqu4poo)\
**Post date:** [February 23, 2021, 3:26pm UTC](https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218/1 "2021-02-23T15:26:09Z")

</div>

I set up a cluster by using Elastic Cloud on Kubernetes.  
I want t provide our predefined custom users / roles as well as predefined credentials for the `elastic` user.  
Setup the password for the `elastic` user by providing the `<clustername>-es-elastic-user secret` works. 🙂

For our custom users I provide secrets for my roles, users and users\_roles relations as described in [Users and roles | Elastic Cloud on Kubernetes [1.2] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/1.2/k8s-users-and-roles.html) .  
The credentials for the users I've created as described in the linked documentation with the `elasticsearch-users` command.  
I just get a HTTP 401 when I try to communicate with the cluster and the API shows no custom users / roles. So no users or roles are created at cluster startup ☹

My cluster-setup is very basic yet. The nodeset contains just one node without any specification similar to the "quickstart" example. Do I need more configuration for getting the usermanagement working? (We currently run version 1.2.1 of the eck operator.)

The cluster:

```
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: mycluster
spec:
  version: 7.9.1
  auth:
    # define our custom roles here
    roles:
      - secretname: mycluster-roles
    # define our users here
    fileRealm:
      - secretname: mycluster-users
      - secretname: mycluster-users-roles
[...]

```

mycluster-roles:

```
kind: Secret
apiVersion: v1
metadata:
    name: mycluster-roles
    namespace: my-namspace
stringData:
    roles.yml: |-
        my-role:
          run_as: []
          cluster: ['monitor']
          [...]

```

mycluster-users:

```
apiVersion: v1
kind: Secret
metadata:
    name: mycluster-users
    namespace: my-namspace
stringData:
    users: |-
        my-user1:<clear text password | brypted password - does no matter>
        my-user2:<clear text password | brypted password - does no matter>
        my-user3:<clear text password | brypted password - does no matter>
```

---

<div class="post-metadata">

**Author:** ![idanmo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/idanmo/32/50092_2.png) [@idanmo](https://discuss.elastic.co/u/idanmo)\
**Post date:** [February 23, 2021, 10:05pm UTC](https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218/2 "2021-02-23T22:05:17Z")

</div>

This seems like a syntax issue in your cluster definition yaml.  
The secret name key should be in camel case: `secretName`:

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: mycluster
spec:
  version: 7.9.1
  auth:
    # define our custom roles here
    roles:
      - secretName: mycluster-roles
    # define our users here
    fileRealm:
      - secretName: mycluster-users
      - secretName: mycluster-users-roles
[...]

```

---

<div class="post-metadata">

**Author:** ![Aiqu4poo](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@Aiqu4poo](https://discuss.elastic.co/u/Aiqu4poo)\
**Post date:** [February 24, 2021, 7:23am UTC](https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218/3 "2021-02-24T07:23:18Z")

</div>

Oh no. Really? Shame on me ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 7:23am UTC](https://discuss.elastic.co/t/setup-well-know-user-roles-credentials-on-cluster-setup/265218/4 "2021-03-24T07:23:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
