# Unable to set xpack.security.authc.realms.oidc.oidc1.rp.client\_secret property through yml file

**URL:** <https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988>\
**Category:** Elasticsearch\
**Created:** [February 5, 2020, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988 "2020-02-05T12:38:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![viveknagar](https://avatars.discourse-cdn.com/v4/letter/v/cdc98d/32.png) [@viveknagar](https://discuss.elastic.co/u/viveknagar)\
**Post date:** [February 5, 2020, 12:38pm UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/1 "2020-02-05T12:38:43Z")

</div>

Hello,  
I want to deploy elasticsearch with OpenId connect authentication . I am using keycloack as my open id connect provider. I have done all my configuration as per documentations. Below is my elasticsearch.yml file.

cluster.name: my-elastic-cluster  
network.host: "0.0.0.0"  
path.repo: ["/usr/share/elasticsearch/data/"]  
xpack.security.enabled: true  
xpack.security.authc.token.enabled: true  
xpack.security.authc.realms.oidc.oidc1:  
order: 2  
rp.client\_id: "kibana"  
rp.response\_type: code  
rp.redirect\_uri: "[http://10.98.245.1:5601/api/security/v1/oidc](http://10.98.245.1:5601/api/security/v1/oidc)"  
op.issuer: "[http://34.85.46.112:30023/auth/realms/oidc1](http://34.85.46.112:30023/auth/realms/oidc1)"  
op.authorization\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/auth](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/auth)"  
op.token\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/token](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/token)"  
op.jwkset\_path: "/usr/share/elasticsearch/config/jwkt"  
connect/certs"  
op.userinfo\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/userinfo](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/userinfo)"  
op.endsession\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/logout](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/logout)"  
rp.post\_logout\_redirect\_uri: "[http://10.98.245.1:5601/](http://10.98.245.1:5601/)"  
claims.principal: sub  
claims.groups: "[http://example.info/claims/group](http://example.info/claims/group)"

I want to add xpack.security.authc.realms.oidc.oidc1.rp.client\_secret property from yml file .Is there any way to do so?

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [February 5, 2020, 1:57pm UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/2 "2020-02-05T13:57:09Z")

</div>

@viveknagar - I do not think you can define `client_secret` in `elasticsearch.yml` file. As documented [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/oidc-guide-authentication.html), this is a secure setting and as such is not defined in the realm configuration in `elasticsearch.yml` but added to the [elasticsearch keystore](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/secure-settings.html). For example:

```auto
bin/elasticsearch-keystore add xpack.security.authc.realms.oidc.oidc1.rp.client_secret

```

---

<div class="post-metadata">

**Author:** ![viveknagar](https://avatars.discourse-cdn.com/v4/letter/v/cdc98d/32.png) [@viveknagar](https://discuss.elastic.co/u/viveknagar)\
**Post date:** [February 5, 2020, 2:16pm UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/3 "2020-02-05T14:16:02Z")

</div>

But I am deploying elasticsearch through kubernetes .So I have to deploy it from yaml files. I have no other option for it other than deploying through files .

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [February 6, 2020, 1:54am UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/4 "2020-02-06T01:54:20Z")

</div>

@viveknagar Could you tell us more how you are planning to deploy Elasticsearch on Kubernetes? Are you using [Elastic Cloud on Kubernetes](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html)?

---

<div class="post-metadata">

**Author:** ![viveknagar](https://avatars.discourse-cdn.com/v4/letter/v/cdc98d/32.png) [@viveknagar](https://discuss.elastic.co/u/viveknagar)\
**Post date:** [February 6, 2020, 6:19am UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/5 "2020-02-06T06:19:53Z")

</div>

Thanks for quick response!!!

Below is my elasticsearch deployment file  
here is my configmap file

apiVersion: v1  
kind: ConfigMap  
metadata:  
name: es-config-sso  
namespace: kube-system  
data:  
elasticsearch.yml: |  
cluster.name: my-elastic-cluster  
network.host: "0.0.0.0"  
path.repo: ["/usr/share/elasticsearch/data/"]  
xpack.security.enabled: true  
xpack.security.authc.token.enabled: true  
xpack.security.authc.realms.oidc.oidc1:  
order: 2  
rp.client\_id: "kibana"  
rp.response\_type: code  
rp.redirect\_uri: "[http://10.98.245.1:5601/api/security/v1/oidc](http://10.98.245.1:5601/api/security/v1/oidc)"  
op.issuer: "[http://34.85.46.112:30023/auth/realms/oidc1](http://34.85.46.112:30023/auth/realms/oidc1)"  
op.authorization\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/auth](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/auth)"  
op.token\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/token](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/token)"  
op.jwkset\_path: "/usr/share/elasticsearch/config/jwkt"  
op.userinfo\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/userinfo](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/userinfo)"  
op.endsession\_endpoint: "[http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/logout](http://34.85.46.112:30023/auth/realms/oidc1/protocol/openid-connect/logout)"  
rp.post\_logout\_redirect\_uri: "[http://10.98.245.1:5601/](http://10.98.245.1:5601/)"  
claims.principal: sub  
claims.groups: "[http://example.info/claims/group](http://example.info/claims/group)"

* * *

Here is my deployment file

apiVersion: apps/v1  
kind: StatefulSet  
metadata:  
name: es-cluster-sso  
namespace: kube-system  
spec:  
serviceName: elasticsearch-sso  
replicas: 1  
selector:  
matchLabels:  
app: elasticsearch-sso  
template:  
metadata:  
labels:  
app: elasticsearch-sso  
spec:  
containers:  
- name: elasticsearch-sso  
image: elasticsearch:7.2.0  
command: ["sh", "-c", "echo 'y' | echo '26880c22-01a4-44c6-b675-7394fec008bf'| bin/elasticsearch-keystore add xpack.security.authc.realms.oidc.oidc1.rp.client\_secret"]  
resources:  
limits:  
cpu: 1000m  
requests:  
cpu: 100m  
ports:  
- containerPort: 9200  
name: rest  
protocol: TCP  
- containerPort: 9300  
name: inter-node  
protocol: TCP  
volumeMounts:  
- name: elasticsearch-config  
mountPath: /usr/share/elasticsearch/config/elasticsearch.yml  
subPath: elasticsearch.yml  
env:  
- name: cluster.name  
value: k8s-logs  
- name: node.name  
valueFrom:  
fieldRef:  
fieldPath: metadata.name  
- name: discovery.seed\_hosts  
value: "es-cluster-0.elasticsearch"  
- name: cluster.initial\_master\_nodes  
value: "es-cluster-0"  
- name: ES\_JAVA\_OPTS  
value: "-Xms512m -Xmx512m"  
- name: ELASTIC\_PASSWORD  
value: "vivek"  
volumes:  
- name: elasticsearch-config  
configMap:  
name: es-config-sso  
defaultMode: 0777  
initContainers:  
- name: fix-permissions  
image: busybox  
command: ["sh", "-c", "chown -R 1000:1000 /usr/share/elasticsearch/data"]  
securityContext:  
privileged: true  
volumeMounts:  
- name: data  
mountPath: /usr/share/elasticsearch/data  
- name: increase-vm-max-map  
image: busybox  
command: ["sysctl", "-w", "vm.max\_map\_count=262144"]  
securityContext:  
privileged: true  
- name: increase-fd-ulimit  
image: busybox  
command: ["sh", "-c", "ulimit -n 65536"]  
securityContext:  
privileged: true  
volumeClaimTemplates:

- metadata:  
name: data  
labels:  
app: elasticsearch-sso  
spec:  
accessModes: ["ReadWriteOnce"]  
storageClassName: do-block-storage  
resources:  
requests:  
storage: 10Gi

* * *

From this file, I am deploying my elasticsearch on Kubernetes

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2020, 6:19am UTC](https://discuss.elastic.co/t/unable-to-set-xpack-security-authc-realms-oidc-oidc1-rp-client-secret-property-through-yml-file/217988/6 "2020-03-05T06:19:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
