# Unable to use mounted elastic-agent.yml if running in elastic-agent container

**URL:** <https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202>\
**Category:** Beats\
**Tags:** elastic-agent\
**Created:** [June 29, 2020, 11:57pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202 "2020-06-29T23:57:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [June 29, 2020, 11:57pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/1 "2020-06-29T23:57:49Z")

</div>

Hi,

I am using `elastic-agent-7.9.0-SNAPSHOT` docker image (also tested and encountered the same error with `elastic-agent-8.0.0-SNAPSHOT` docker image).  
My `docker-compose.yml`:

```auto
version: '3.7'
services:
  elastic-agent:
    image: docker.elastic.co/beats/elastic-agent:7.9.0-SNAPSHOT
    container_name: elastic-agent
    command: ["enroll", "http://kibana:5601", "<enrollment_token>"]
    environment:
      - "FLEET_ENROLL=1"
      - "FLEET_SETUP=1"
      - "KIBANA_HOST=http://kibana:5601"
    volumes:
      - ./elastic-agent.yml:/usr/share/elastic-agent/elastic-agent.yml

```

Error message:

```auto
fail to enroll: could not save enrollment information: could not backup /usr/share/elastic-agent/elastic-agent.yml: rename /usr/share/elastic-agent/elastic-agent.yml /usr/share/elastic-agent/elastic-agent.yml.2020-06-29T23-51-39.7743.bak: device or resource busy

```

This error leads to another issue: I am not able to specify the `ca.crt` for Metricbeat and Filebeat running in the `elastic-agent` container.

This also breaks if ES requires authentication, because I am not able to specify ES `username` and `password` in `elastic-agent.yml` for Metricbeat and Filebeat.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 30, 2020, 6:01am UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/2 "2020-06-30T06:01:08Z")

</div>

Hi @hendry.lim Thanks for trying out the Elastic Agent. Based on your error, I assume you are using the Elastic Agent together with the Ingest Manager and tried to enroll the agent?

The error indicates, that the elastic agent is missing the permissions to rename / backup the config. He needs to have these permissions because when enrolling into Ingest Manager, the existing config is backed up and overwritten by the config coming from Ingest Manager.

If you are using Ingest Manager, you don't need to copy your own configuration into the container. Also username / password are replaced by API Keys when used with Ingest Manager, so no need to specify it.

Did you perhaps wanted to run Agent in standalone mode? If yes, you need to remove the enrollment part.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [June 30, 2020, 6:20am UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/3 "2020-06-30T06:20:49Z")

</div>

Hi @ruflin Thank you for your prompt reply.

> Based on your error, I assume you are using the Elastic Agent together with the Ingest Manager and tried to enroll the agent?

That is correct. I am trying out Elastic Agent with Ingest Manager and Fleet. I am able to get the Elastic Agent to run in container, but Filebeat and Metricbeat are unable to connect back to ES due to SSL error caused by using self-signed certificate.  
How do I configure `ca.crt` or `ca_sha256` for Filebeat and Metricbeat running in the same Elastic Agent container?

```auto
Ping request failed with: Get https://es01:9200: x509: certificate signed by unknown authority

```

I just found out that I am unable to edit the Elastic Agent configuration data source with the latest `7.9.0` snapshot. It's the same for a new configuration.

 ![system-config](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8b69fa50ada4d6522dc2aeb5737970207c23ce5.png)

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [June 30, 2020, 1:24pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/4 "2020-06-30T13:24:01Z")

</div>

Saw this issue [#19504](https://github.com/elastic/beats/issues/19504) raised, hopefully this will be the solution for the custom certificate authority use case.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [July 1, 2020, 12:58pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/5 "2020-07-01T12:58:19Z")

</div>

Yes, that should solve it. @pierhugues Can you think of a temporary workaround?

---

<div class="post-metadata">

**Author:** ![sej7278](https://avatars.discourse-cdn.com/v4/letter/s/8c91f0/32.png) [@sej7278](https://discuss.elastic.co/u/sej7278)\
**Post date:** [July 2, 2020, 5:00pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/6 "2020-07-02T17:00:37Z")

</div>

elastic-agent-7.8.0-x86\_64.rpm and elastic-agent-7.8.0-linux-x86\_64.tar.gz have the same issue, setting `ssl.certificate_authorities` in elastic-agent.yml didn't work as it does for the beats when they're not under the agent.

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [July 8, 2020, 1:41pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/7 "2020-07-08T13:41:21Z")

</div>

The latest `elastic-agent-7.9.0-SNAPSHOT` seems to be broken.

```auto
# docker-compose.yml
version: '3.7'
services:
  elastic-agent:
    image: docker.elastic.co/beats/elastic-agent:7.9.0-SNAPSHOT
    container_name: elastic-agent
    environment:
      - "FLEET_ENROLL=1"
      - "KIBANA_HOST=http://kibana:5601"
      - "FLEET_ENROLLMENT_TOKEN=<token>"

```

Errors:

```auto
Error: accepts 2 arg(s), received 1
Usage:
  elastic-agent enroll <kibana_url> <enrollment_token> [flags]

Flags:
  -p, --ca_sha256 string Comma separated list of certificate authorities hash pins used for certificate verifications
  -a, --certificate_authorities string Comma separated list of root certificate for server verifications
  -f, --force Force overwrite the current and do not prompt for confirmation
  -h, --help help for enroll

Global Flags:
  -c, -- string Configuration file, relative to path.config (default "elastic-agent.yml") (default "elastic-agent.yml")
      --path.config string Configuration path (default "${path.home}")
      --path.data string Data path contains Agent managed binaries (default "/usr/share/elastic-agent/data")
      --path.home string Agent root path (default "/usr/share/elastic-agent")
      --strict.perms Strict permission checking on config files (default true)

accepts 2 arg(s), received 1

```

It still works if I use `command: ["enroll", "http://kibana:5601", "<token>"]`  
instead of using `FLEET_ENROLLMENT_TOKEN`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 3:41pm UTC](https://discuss.elastic.co/t/unable-to-use-mounted-elastic-agent-yml-if-running-in-elastic-agent-container/239202/8 "2020-08-05T15:41:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
