# SSL certificate reload

**URL:** https://discuss.elastic.co/t/ssl-certificate-reload/262090
**Category:** Logstash
**Created:** [January 25, 2021, 11:34am UTC](https://discuss.elastic.co/t/ssl-certificate-reload/262090 "2021-01-25T11:34:22Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![raivis.krumins](https://avatars.discourse-cdn.com/v4/letter/r/ebca7d/32.png) [@raivis.krumins](https://discuss.elastic.co/u/raivis.krumins)
#### Post date: [January 25, 2021, 11:34am UTC](https://discuss.elastic.co/t/ssl-certificate-reload/262090/1 "2021-01-25T11:34:22Z")

</div>

I want to use hashicorp vault to manage logstash ssl certs on kubernetes.  
I am using logstash helm chart --version 7.10.1  
These pod annotations work as expected:

```auto
podAnnotations:
  vault.hashicorp.com/agent-inject: "true"
  vault.hashicorp.com/auth-path: "auth/eks"
  vault.hashicorp.com/role: "devweb-app"
  vault.hashicorp.com/agent-inject-secret-ca.crt: ""
  vault.hashicorp.com/agent-inject-template-ca.crt: |
    {{- with secret "pki_int/issue/elk" "common_name=logstash.example.com" "private_key_format=pkcs8" "ttl=1h" -}}
    {{ .Data.issuing_ca }}
    {{- end }}

  vault.hashicorp.com/agent-inject-secret-server.key: ""
  vault.hashicorp.com/agent-inject-template-server.key: |
    {{- with secret "pki_int/issue/elk" "common_name=logstash.example.com" "private_key_format=pkcs8" "ttl=1h" -}}
    {{ .Data.private_key }}
    {{- end }}

  vault.hashicorp.com/agent-inject-secret-server.crt: ""
  vault.hashicorp.com/agent-inject-template-server.crt: |
    {{- with secret "pki_int/issue/elk" "common_name=logstash.example.com" "private_key_format=pkcs8" "ttl=1h" -}}
    {{ .Data.certificate }}
    {{- end }}

```

**The problem is when logstash container gets new certs, there is no way to tell logstash to use new certs.** I have tried documented ways to reload configs: [https://www.elastic.co/guide/en/logstash/current/reloading-config.html](https://www.elastic.co/guide/en/logstash/current/reloading-config.html)  
but these apply only for config, new ssl certs are not being used.

Is there some way to make logstash aware of ssl cert rotation?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 22, 2021, 11:34am UTC](https://discuss.elastic.co/t/ssl-certificate-reload/262090/2 "2021-02-22T11:34:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
