# Update elasticsearch.yml in elastic cloud through API

**URL:** https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598
**Category:** Elasticsearch
**Created:** [July 26, 2021, 7:37am UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598 "2021-07-26T07:37:33Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![idelix](https://avatars.discourse-cdn.com/v4/letter/i/ecd19e/32.png) [@idelix](https://discuss.elastic.co/u/idelix)
#### Post date: [July 26, 2021, 7:37am UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598/1 "2021-07-26T07:37:34Z")

</div>

Hello,

I deployed Elastic Cloud in Azure using terraform provider hovewer I cannot use terraform to update elasticsearch.yml (below) since OpenID configuration ([Secure your clusters with OpenID Connect | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-secure-clusters-oidc.html)) requires keystore secret to be added first otherwise setting change fails.

```auto
 config {
   user_settings_yaml = data.template_file.elasticsearch_settings.rendered
 }

```

So I need to update elasticsearch.yml after cluster is created and currently I couldn't find way to do it.

I know I can see API version of my deployment and I saw how you can for example add Kibana through API [Create a first deployment: Just an Elasticsearch cluster | Elastic Cloud Enterprise Reference [2.10] | Elastic](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-restful-api-examples-create-deployment.html) but I cannot find any example of adding settings.

Guess I could obtain deployment as json then parse it and try to add user settings but thought there must be easier way

---

<div class="post-metadata">

### Author: ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)
#### Post date: [July 26, 2021, 8:55pm UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598/2 "2021-07-26T20:55:08Z")

</div>

This is indeed a rough area of our Terraform implementation

Currently Terraform cannot support Keystore insertion (and our API does not support Keystore insertion _on creation_, only on update)

Therefore the steps are:

- Create the cluster with a terraform config with no OIDC YAML settings
- Add the OIDC keystore entries via the UI or API (or `ecctl` command line) ... eg [Add or remove settings from the cluster keystore | Elastic Cloud Enterprise Reference [2.10] | Elastic](https://www.elastic.co/guide/en/cloud-enterprise/current/set-es-cluster-keystore.html) for raw API, or [ecctl deployment elasticsearch keystore | Elastic Cloud Control Documentation [1.4] | Elastic](https://www.elastic.co/guide/en/ecctl/current/ecctl_deployment_elasticsearch_keystore.html) for CLI
- Update the terraform config with the OIDC YAML settings

We are aware this isn't an ideal experience for a fairly common operation, and are actively discussing how future versions can improve on this

Alex

---

<div class="post-metadata">

### Author: ![idelix](https://avatars.discourse-cdn.com/v4/letter/i/ecd19e/32.png) [@idelix](https://discuss.elastic.co/u/idelix)
#### Post date: [July 27, 2021, 8:36am UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598/3 "2021-07-27T08:36:33Z")

</div>

Thanks for information the problem is it is not possible to change configuration inside terraform without code change and pushing this change to repository.

Ideally I would just update config through API after terraform finished deploying cluster and also after I already added secret using API.

I found this instruction of how to upgrade deployment [Applying a new deployment configuration: Upgrade | Elastic Cloud Enterprise Reference [2.10] | Elastic](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-restful-api-examples-upgrade.html) but I only need to update config so wonder if you have some example of how this can be acomplished.

---

<div class="post-metadata">

### Author: ![idelix](https://avatars.discourse-cdn.com/v4/letter/i/ecd19e/32.png) [@idelix](https://discuss.elastic.co/u/idelix)
#### Post date: [July 27, 2021, 9:38am UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598/4 "2021-07-27T09:38:55Z")

</div>

Actually I think it will be fine I can add settings using dynamic block in terraform and just run terraform twice with diff parameters second after I added keystore secret

```auto
    dynamic "config" {
      for_each = var.enable_elasticsearch_config ? [1] : []
      content {
        user_settings_yaml = data.template_file.elasticsearch_settings.rendered
      }
    }
  }

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 24, 2021, 9:39am UTC](https://discuss.elastic.co/t/update-elasticsearch-yml-in-elastic-cloud-through-api/279598/5 "2021-08-24T09:39:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
