# Unable to Reload certificates on filebeat container for Kafka

**URL:** <https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 23, 2023, 3:02pm UTC](https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742 "2023-01-23T15:02:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![kadalin](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@kadalin](https://discuss.elastic.co/u/kadalin)\
**Post date:** [January 23, 2023, 3:02pm UTC](https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742/1 "2023-01-23T15:02:11Z")

</div>

I'm trying to integrate filebeat with Kafka with SSL Handshake. The certificates are obtained from vault and they are valid for only 7 days. A different mechanism is applied to get the certificates renewed with a new private key every 2 days so that the service will have zero down time (ZDT) and it reloads the certificates before they expire.

I've done the following configuration which monitors the certificates file path and reloads them when they've been changed.

```auto

filebeat.config.inputs:
  enabled: true
  path: /usr/share/filebeat/reload-configs/*.yml
  reload.enabled: true
  reload.period: 10s

output.kafka:
  hosts: '${KAFKA_HOSTS}'
  ssl.certificate: '${CERTS_PATH}/filebeat.pki.crt'
  ssl.key: '${CERTS_PATH}/filebeat.pki.key'
  ssl.authorities: ['${CERTS_PATH}/root_ca.pem']
  topic: '${KAFKA_TOPIC}'
  codec.format:
    string: '{"timestamp": "%{[@timestamp]}", "message": %{[message]}, "host": %{[host]}}'
  close_inactive: 10m
  required_acks: 1
  partition.round_robin:
    reachable_only: false
  keep-alive: 30000ms

```

**kafka\_filebeat\_reload\_configs.yml**

```auto
- type: filestream
  id: pki-crt
  paths:
    - ${CERTS_PATH}/filebeat.pki.crt
  scan_frequency: 10s
- type: filestream
  id: pki-key
  paths:
    - ${CERTS_PATH}/filebeat.pki.key
  scan_frequency: 10s

```

There are couple of problems with this approach:

1. It's outputting the file contents to Kafka topic
2. It only reloads the files if number of lines are increased in these files (treating them as logs/filestream)

Is there any cleaner approach to reload the certificates without having to restart the filebeat process?

References:

> **[Load external configuration files | Filebeat Reference \[8.6\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration-reloading.html)**

> **[Configure inputs | Filebeat Reference \[8.6\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-filebeat-options.html#filebeat-input-types)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2023, 5:02pm UTC](https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742/2 "2023-02-20T17:02:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
