# Support in Puppet Module for Elasticsearch 6.x initial password setup

**URL:** <https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387>\
**Category:** Elasticsearch\
**Created:** [October 22, 2018, 11:27am UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387 "2018-10-22T11:27:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![arnold79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnold79/32/141473_2.png) [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Post date:** [October 22, 2018, 11:27am UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387/1 "2018-10-22T11:27:16Z")

</div>

Hi All,

Currently busy setting up a Puppet Ent. configuration by using the official Elastic module. We can easily deploy the elasticsearch node with the configuration, but we struggling setting up the initial passwords using the bootstrap initial key in the keystore by using the official module. Currently we are using the elasticsearch-setup-password interactive command.

Is this task already supported by the latest module ?

@tylerjl : Can you answer this question, since you seem to be the creator 🙂

---

<div class="post-metadata">

**Author:** ![tylerjl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylerjl/32/44965_2.png) [@tylerjl](https://discuss.elastic.co/u/tylerjl)\
**Post date:** [October 22, 2018, 9:41pm UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387/2 "2018-10-22T21:41:00Z")

</div>

One approach that should work would be to set the `bootstrap.password` keystore setting to your desired password value using the supported `secrets` parameter for the Elasticsearch module. [This documentation page summarizes how `bootstrap.password` works](https://www.elastic.co/guide/en/x-pack/current/setting-up-authentication.html#bootstrap-elastic-passwords), and the ability to configure secrets in the module [is documented here](https://forge.puppet.com/elastic/elasticsearch#keystore-settings).

Does that help?

---

<div class="post-metadata">

**Author:** ![arnold79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnold79/32/141473_2.png) [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Post date:** [October 23, 2018, 6:51am UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387/3 "2018-10-23T06:51:03Z")

</div>

Hi @tylerjl thanks for your answer. This should do the trick. We will verify this.

---

<div class="post-metadata">

**Author:** ![Mugjuh](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Mugjuh](https://discuss.elastic.co/u/Mugjuh)\
**Post date:** [October 23, 2018, 10:03am UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387/4 "2018-10-23T10:03:36Z")

</div>

It helps a bit, because you are only changing the password for the elastic user  
The other default accounts still have the keystore.seed password?

It keeps on adding the bootstrap.password and removing the keystore.seed when running puppet.  
set purge\_secrets to true.

> Info: Applying configuration version '1540378180'  
> Notice: /Stage[main]/Elasticsearch/Elasticsearch::Instance[instance]/File[/etc/elasticsearch/instance/elasticsearch.keystore]/content:  
> Binary files /etc/elasticsearch/instance/elasticsearch.keystore and /tmp/puppet-file20181024-31767-mx9wfp differ

> Notice: /Stage[main]/Elasticsearch/Elasticsearch::Instance[instance]/Elasticsearch\_keystore[instance]/settings: added: bootstrap.password

It would also be nice to use Sensitive for the bootstrap.password, now the password shows in puppet reports.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2018, 10:03am UTC](https://discuss.elastic.co/t/support-in-puppet-module-for-elasticsearch-6-x-initial-password-setup/153387/5 "2018-11-20T10:03:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
