# Unable to connect remote cluster

**URL:** <https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [April 21, 2021, 5:27pm UTC](https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884 "2021-04-21T17:27:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmssath](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@rmssath](https://discuss.elastic.co/u/rmssath)\
**Post date:** [April 21, 2021, 5:27pm UTC](https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884/1 "2021-04-21T17:27:22Z")

</div>

Hi Team,  
We are trying to configure remote cluster with ECK and facing the below issue

cluster1 (Master) - Managed by ECK which has es, kibana & fluentd  
cluster2 (Remote) - Managed by ECK which has es & fluentd

1. In cluster1, Execute the eck.yml & configured fluentd. After this step, we are able to get indices by (curl -u elastic:XXXXXXXXX -k "[https://elasticsearch-es-http:9200/\_cat/indices](https://elasticsearch-es-http:9200/_cat/indices))

```auto
eck.yml:
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: elasticsearch
  namespace: es-test
  labels:
    app: elasticsearch
spec:
  version: 7.9.3
  nodeSets:
  - name: default
    count: 3
    config:
      node.master: true
      node.data: true
      node.ingest: true
      node.store.allow_mmap: false
  http:
    service:
      spec:
        type: LoadBalancer
        ports:
          - port: 9200
            targetPort: 9200
            protocol: TCP
			
---
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: kibana
  namespace: es-test
spec:
  version: 7.9.3
  count: 1
  elasticsearchRef:
    name: elasticsearch
  http:
    tls:
      selfSignedCertificate:
        disabled: true

```

1. In cluster2, Same step1 is followed except kibana.
2. In cluster2, we have exposed svc with transport port 9300.

```auto
es-svc.yml:
apiVersion: v1
kind: Service
metadata:
  name: elasticsearch-logging
  namespace: "es-test"
  labels:
    app: elasticsearch
spec:
  selector:
    common.k8s.elastic.co/type: elasticsearch
    elasticsearch.k8s.elastic.co/cluster-name: elasticsearch
  ports:
  - port: 9200
    name: rest
  - port: 9300
    name: inter-node

```

```auto
cluster1:
[root@k8s-master01 eck]# kubectl get po -n es-test
NAME READY STATUS RESTARTS AGE
elasticsearch-es-default-0 1/1 Running 0 97m
elasticsearch-es-default-1 1/1 Running 0 98m
elasticsearch-es-default-2 1/1 Running 0 100m
fluentd-8bb4q 1/1 Running 0 150m
fluentd-h8j6m 1/1 Running 0 150m
fluentd-h8lst 1/1 Running 0 150m
fluentd-p9j2g 1/1 Running 0 150m
kibana-kb-55c7584fd6-r62lc 1/1 Running 0 107m
[root@k8s-master01 eck]# kubectl get svc -n es-test
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
elasticsearch-es-default ClusterIP None <none> <none> 5h5m
elasticsearch-es-http LoadBalancer x.x.x.x <pending> 9200:31300/TCP 5h5m
kibana-kb-http ClusterIP x.x.x.x <none> 5601/TCP 107m

```

```auto
cluster2:
[root@k8s-master01 eck]# kubectl get po -n es-test
NAME READY STATUS RESTARTS AGE
elasticsearch-es-default-0 1/1 Running 0 97m
elasticsearch-es-default-1 1/1 Running 0 98m
elasticsearch-es-default-2 1/1 Running 0 100m
fluentd-8bb4q 1/1 Running 0 150m
fluentd-h8j6m 1/1 Running 0 150m
fluentd-h8lst 1/1 Running 0 150m
fluentd-p9j2g 1/1 Running 0 150m
[root@k8s-master01 eck]# kubectl get svc -n es-test
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
elasticsearch-es-default ClusterIP None <none> <none> 5h5m
elasticsearch-es-http LoadBalancer x.x.x.x <pending> 9200:31300/TCP 5h5m
elasticsearch-logging ClusterIP x.x.x.x <none> 9200/TCP,9300/TCP 9h
kibana-kb-http ClusterIP x.x.x.x <none> 5601/TCP 107m

```

1. Copied remote.ca.crt from cluster2 to cluster1 and created secret in cluster1

```auto
kubectl get secret elasticsearch-es-transport-certs-public -n es-test -o go-template='{{index .data "ca.crt" | base64decode}}' > remote.ca.crt

kubectl create secret generic remote-certs --from-file=remote.ca.crt -n es-test

```

-- Same has been done from cluster1 to cluster2.

1. In both cluster, updated elasticsearch with remote.ca.crt

```auto
  nodeSets:
  - config:
      xpack.security.transport.ssl.certificate_authorities:
      - /usr/share/elasticsearch/config/other/remote.ca.crt
    name: default
    count: 3
    podTemplate:
       spec:
         containers:
         - name: elasticsearch
           volumeMounts:
           - mountPath: /usr/share/elasticsearch/config/other
             name: remote-certs
         volumes:
           - name: remote-certs
             secret:
               secretName: remote-certs

```

1. In cluster2, created virtual service for elasticsearch-logging.es-test:9300 with nodeip 1.1.1.1:9300

2. In cluster1 kibana, remote cluster config

```auto
{
  "persistent": {
    "cluster": {
      "remote": {
        "cluster-test": {
          "mode": "proxy",
          "proxy_address": "1.1.1.1:9300"
        }
      }
    }
  }
}

```

We are getting below error in cluster1 and cluster2:

```auto
ES logs in cluster1:
Java exception with signature check failed and PKIX path validation failed

ES logs in cluster2:
{"type": "server", "timestamp": "2021-04-21T06:36:16,892Z", "level": "WARN", "component": "o.e.x.c.s.t.n.SecurityNetty4Transport", "cluster.name": "elasticsearch", "node.name": "elasticsearch-es-default-2", "message": "client did not trust this server's certificate, closing connection Netty4TcpChannel{localAddress=/x.x.x.x:9300, remoteAddress=/x.x.x.x:21989}", "cluster.uuid": "cEJL5C68Sqy7ZhT5yh3VSA", "node.id": "fBD_2ISDS0CIsDbzGXxMpw" }

```

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [April 28, 2021, 4:28pm UTC](https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884/2 "2021-04-28T16:28:20Z")

</div>

Is it a duplication of [Remote cluster - TCP connection is not happened with Istio ingress](https://discuss.elastic.co/t/remote-cluster-tcp-connection-is-not-happened-with-istio-ingress/271040) or here you haven't configure Istio?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 3, 2021, 3:04am UTC](https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884/3 "2021-05-03T03:04:06Z")

</div>

Can u check the certificate of the remote node? I suspect whole the CA may be good, the common name or subject alternative name doesn't match the IP you're using which is why you're getting the certificate validation error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 3:05am UTC](https://discuss.elastic.co/t/unable-to-connect-remote-cluster/270884/4 "2021-05-31T03:05:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
