# This node does not have the remote\_cluster\_client role

**URL:** <https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294>\
**Category:** Elasticsearch\
**Tags:** ccr-cross-cluster-replication\
**Created:** [March 4, 2021, 9:48pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294 "2021-03-04T21:48:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dylan0911](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan0911/32/84992_2.png) [@dylan0911](https://discuss.elastic.co/u/dylan0911)\
**Post date:** [March 4, 2021, 9:48pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294/1 "2021-03-04T21:48:47Z")

</div>

Hi all,

Been going through the doc, the topics and github. Can't seem to find an answer tho this one.

I have 2 clusters running in 2 different regions and wanted to test CCR. Both of them are running on 7.11.1. I was able to setup the remote clusters on both of them and can even do cross cluster searching on them. However, when I try to configure the cross cluster replication, I get the following error in Kibana:

 ![Screen Shot 2021-03-04 at 4.26.19 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6759682c85640f2bc5dfca382349d1c5ddf44d.png)

Also tried it through the API:

`{"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"this node does not have the remote_cluster_client role"}],"type":"illegal_argument_exception","reason":"this node does not have the remote_cluster_client role"},"status":400}`

I checked the logs and even tried setting the logger to trace. Unfortunately, nothing relevant to this comes up.

If I try to query the nodes API on both clusters, this is what I get:

In the ON region:

```auto
root@logs-ing-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/remote_cluster_client:true" | jq '._nodes'
{
  "total": 0,
  "successful": 0,
  "failed": 0
}
#=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
root@logs-ing-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/ingest:true" | jq '._nodes'
{
  "total": 2,
  "successful": 2,
  "failed": 0
}
#=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
root@logs-ing-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/ingest:true" | jq -c '.nodes[] | {"name": .name, "roles":.roles}'
{"name":"logs-ing-02.on","roles":["ingest","ml","remote_cluster_client","transform"]}
{"name":"logs-ing-01.on","roles":["ingest","ml","remote_cluster_client","transform"]}

```

In the QC region:

```auto
 root@logs-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/remote_cluster_client:true" | jq '._nodes'
{
  "total": 0,
  "successful": 0,
  "failed": 0
}
#=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
root@logs-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/ingest:true" | jq '._nodes '
{
  "total": 2,
  "successful": 2,
  "failed": 0
}
#=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
root@logs-02 ~: curl -nks "https://127.0.0.1:9200/_nodes/ingest:true" | jq -c '.nodes[] | {"name": .name, "roles":.roles}'
{"name":"logs-ing-01","roles":["ingest","ml","remote_cluster_client","transform"]}
{"name":"logs-ing-02","roles":["ingest","ml","remote_cluster_client","transform"]}

```

Both clusters can talk to each other on the http and transport ports and they are using the same CA for their certs.

Has anybody encountered this behaviour before and/or can anyone point me to how I can debug this?

---

<div class="post-metadata">

**Author:** ![dylan0911](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan0911/32/84992_2.png) [@dylan0911](https://discuss.elastic.co/u/dylan0911)\
**Post date:** [March 9, 2021, 9:51pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294/2 "2021-03-09T21:51:45Z")

</div>

Ok think I figured it out.

Seems like CCR needs the masters to also have the role for some reason. Added the remote\_cluster\_client role to my masters and now it works.

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [March 9, 2021, 10:27pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294/3 "2021-03-09T22:27:51Z")

</div>

I'm sorry that you did not have a good experience here. I've opened a [PR](https://github.com/elastic/elasticsearch/pull/70186) so that we can clarify this in the docs.

---

<div class="post-metadata">

**Author:** ![dylan0911](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dylan0911/32/84992_2.png) [@dylan0911](https://discuss.elastic.co/u/dylan0911)\
**Post date:** [March 12, 2021, 9:01pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294/4 "2021-03-12T21:01:53Z")

</div>

HI Jason,

No worries. I'm still struggling with getting it setup properly, but I just saw an interesting bit in your PR that might fix my issue 🙂

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2021, 9:02pm UTC](https://discuss.elastic.co/t/this-node-does-not-have-the-remote-cluster-client-role/266294/5 "2021-04-09T21:02:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
