# Shiping logs from kubernetes to elasticsearch using beats - get: "clusterroles.rbac.authorization.k8s.io "filebeat" is forbidden: attempt to grant extra privileges"

**URL:** <https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135>\
**Category:** Beats\
**Created:** [December 17, 2017, 10:25pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135 "2017-12-17T22:25:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dinaWork](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dinaWork](https://discuss.elastic.co/u/dinaWork)\
**Post date:** [December 17, 2017, 10:25pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135/1 "2017-12-17T22:25:23Z")

</div>

following  
[https://www.elastic.co/guide/en/beats/filebeat/6.1/running-on-kubernetes.html](https://www.elastic.co/guide/en/beats/filebeat/6.1/running-on-kubernetes.html)

and the following post:

> **[Shipping Kubernetes logs with Filebeat](https://www.elastic.co/blog/shipping-kubernetes-logs-to-elasticsearch-with-filebeat)**
>
> We recently wrote about the new Filebeat features to retrieve & enrich Docker logs using Filebeat, and since the 6.0 release, you can leverage the same technology when running Kubernetes. Metadata...

`curl -L -O https://raw.githubusercontent.com/elastic/beats/6.0/deploy/kubernetes/filebeat-kubernetes.yaml`

here is full yaml:

> <https://github.com/elastic/beats/blob/6.1/deploy/kubernetes/filebeat-kubernetes.yaml>

  
I edited variables to point to my instance:

```auto
           - name: ELASTICSEARCH_HOST
          value: xxxxxxxxxx.us-central1.gcp.cloud.es.io
        - name: ELASTICSEARCH_PORT
          value: "9243"
        - name: ELASTICSEARCH_USERNAME
          value: elastic
        - name: ELASTICSEARCH_PASSWORD
          value: xxxxxxx

```

I ran `kubectl apply -f filebeat-kubernetes.yaml`

and get the following error:

```auto
    configmap "filebeat-config" created
configmap "filebeat-prospectors" created
daemonset "filebeat" created
clusterrolebinding "filebeat" created
serviceaccount "filebeat" created
Error from server (Forbidden): error when creating "filebeat-kubernetes.yaml": clusterroles.rbac.authorization.k8s.io "filebeat" is forbidden: attempt to grant extra privileges: [PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["list"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["get"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["watch"]} PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["list"]}] user=&{bob@example.com [system:authenticated] map[]} ownerrules=[PolicyRule{Resources:["selfsubjectaccessreviews"], APIGroups:["authorization.k8s.io"], Verbs:["create"]} PolicyRule{NonResourceURLs:["/api" "/api/*" "/apis" "/apis/*" "/healthz" "/swaggerapi" "/swaggerapi/*" "/version"], Verbs:["get"]}] ruleResolutionErrors=[]

```

beautify error:

```auto
Error from server (Forbidden): error when creating "filebeat-kubernetes.yaml": clusterroles.rbac.authorization.k8s.io "filebeat" is forbidden: attempt to grant extra privileges: 
    [
PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["get"]}
PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["watch"]}
PolicyRule{Resources:["namespaces"], APIGroups:[""], Verbs:["list"]}
PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["get"]}
PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["watch"]}
PolicyRule{Resources:["pods"], APIGroups:[""], Verbs:["list"]}]
user=&{bob@example.com [system:authenticated] map[]}
ownerrules=[
  PolicyRule{
    Resources:["selfsubjectaccessreviews"],
    APIGroups:["authorization.k8s.io"],
    Verbs:["create"]}
  PolicyRule{NonResourceURLs:["/api" "/api/*" "/apis" "/apis/*" "/healthz" "/swaggerapi" "/swaggerapi/*" "/version"],
              Verbs:["get"]}]
ruleResolutionErrors=[]

```

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [December 17, 2017, 10:54pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135/2 "2017-12-17T22:54:55Z")

</div>

Hi @dinaWork,

Depending on your cluster settings this error may not be fatal. But let me explain what's going on:

We setup [RBAC roles](https://kubernetes.io/docs/admin/authorization/rbac/) to ensure filebeat has access to pods metadata when enriching logs.

While this is what you want, it requires you have the cluster-admin role when deploying it, you can bind this role to your user doing something like this:

`kubectl create clusterrolebinding cluster-admin-binding --clusterrole=cluster-admin --user=carlos@elastic.co`

Just replace the user name with yours.

---

<div class="post-metadata">

**Author:** ![dinaWork](https://avatars.discourse-cdn.com/v4/letter/d/edb3f5/32.png) [@dinaWork](https://discuss.elastic.co/u/dinaWork)\
**Post date:** [December 18, 2017, 1:35pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135/3 "2017-12-18T13:35:09Z")

</div>

hi @exekias, thanks for your reply, binding the role solved my issue!!

now beats fails  
get the following log:

```auto
ERR Failed to connect: Get http://xxxxxx.us-central1.gcp.cloud.es.io:9243: read tcp 13.17.4.10:40766->31.177.77.2:9243: read: connection reset by peer
11:38:19.230 reload.go:222: INFO Dynamic config reloader stopped
11:38:19.230 crawler.go:135: INFO Crawler stopped
11:38:19.230 registrar.go:210: INFO Stopping Registrar
11:38:19.230 registrar.go:165: INFO Ending Registrar
11:38:19.231 forwarder.go:35: INFO Prospector outlet closed
11:38:19.234 metrics.go:51: INFO Total non-zero values: beat.info.uptime.ms=40449 beat.memstats.gc_next=25194960 beat.memstats.memory_alloc=13894472 beat.memstats.memory_total=43826552 filebeat.events.active=4130 filebeat.events.added=4140 filebeat.events.done=10 filebeat.harvester.closed=4 filebeat.harvester.open_files=16 filebeat.harvester.running=16 filebeat.harvester.started=20 libbeat.config.module.running=1 libbeat.config.module.starts=1 libbeat.config.reloads=2 libbeat.output.read.errors=6 libbeat.output.type=elasticsearch libbeat.output.write.bytes=1434 libbeat.pipeline.clients=0 libbeat.pipeline.events.active=4116 libbeat.pipeline.events.failed=4 libbeat.pipeline.events.filtered=20 libbeat.pipeline.events.published=4116 libbeat.pipeline.events.retry=150 libbeat.pipeline.events.total=4140 registrar.states.current=6 registrar.states.update=6 registrar.writes=8
11:38:19.234 metrics.go:52: INFO Uptime: 40.449909073s
11:38:19.234 beat.go:284: INFO filebeat stopped.

```

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [December 18, 2017, 1:46pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135/4 "2017-12-18T13:46:24Z")

</div>

It looks like you are trying to use `http` instead of `https`, try changing the host value

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2018, 10:25pm UTC](https://discuss.elastic.co/t/shiping-logs-from-kubernetes-to-elasticsearch-using-beats-get-clusterroles-rbac-authorization-k8s-io-filebeat-is-forbidden-attempt-to-grant-extra-privileges/112135/5 "2018-01-07T22:25:55Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
