# Using Dell ECS s3 for snapshots

**URL:** <https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658>\
**Category:** Elasticsearch\
**Tags:** snapshot-and-restore\
**Created:** [February 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658 "2023-02-03T14:14:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![trwillis](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Post date:** [February 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/1 "2023-02-03T14:14:31Z")

</div>

I am trying to configure a snapshot repository to use an on-premise s3 compatible solution - Dell ECS. When I issue the command to add the repository with our internal endpoint, ES still is attempting to connect to AWS as shown in Wireshark capture. Why is it not using the endpoint I specified?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 3, 2023, 2:19pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/2 "2023-02-03T14:19:53Z")

</div>

Did you change the endpoint while creating your repository in elasticsearch?

In the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/repository-s3.html#repository-s3-compatible-services) you have this example:

```auto
PUT _snapshot/my_s3_repository
{
  "type": "s3",
  "settings": {
    "client": "my-client",
    "bucket": "my-bucket",
    "endpoint": "my.s3.endpoint"
  }
}

```

---

<div class="post-metadata">

**Author:** ![trwillis](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Post date:** [February 3, 2023, 2:27pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/3 "2023-02-03T14:27:02Z")

</div>

Here is my attempt to create the repo:

```auto
curl --insecure -X PUT -u "elastic:${ELASTIC_PASSWORD}" "https://localhost:9200/_snapshot/s3_repo" -H 'Content-Type: application/json' -d'
{
  "type": "s3",
  "settings": {
    "bucket": "my-bucket",
    "client": "default",
    "endpoint": "my.s3.provider:9020",
    "protocol": "http",
    "base_path": "snapshots"
  }
}
'

```

---

<div class="post-metadata">

**Author:** ![trwillis](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Post date:** [February 3, 2023, 2:28pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/4 "2023-02-03T14:28:24Z")

</div>

The attempt gets a connection timeout error. I ran a Wireshark capture and it is attempting to connect to 54.85.240.191 which is blocked by my org.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 3, 2023, 3:40pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/5 "2023-02-03T15:40:59Z")

</div>

It seems similar to [this post](https://discuss.elastic.co/t/snapshot-to-minio-s3-error/260365).

How many nodes do you have? If you have more than one, did you set set `access_key` and `secret_key` in all of them?

As suggested in the linked post, try to run the request again with the parameter `?error_trace` to get more information in the logs.

Also, share the response you get for the requests.

---

<div class="post-metadata">

**Author:** ![trwillis](https://avatars.discourse-cdn.com/v4/letter/t/9fc348/32.png) [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Post date:** [February 3, 2023, 4:16pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/6 "2023-02-03T16:16:18Z")

</div>

I found the issue. Originally, I tried to set the keystore secure settings using these commands:  
bin/elasticsearch-keystore add s3.client.default.access\_key  
bin/elasticsearch-keystore add s3.client.default.secret\_key

However, when I deleted those and included them in my definition, it works:

```auto
curl --insecure -X PUT -u "elastic:${ELASTIC_PASSWORD}" "https://localhost:9200/_snapshot/s3_repo" -H 'Content-Type: application/json' -d'
{
  "type": "s3",
  "settings": {
    "bucket": "my_bucket",
    "client": "default",
    "endpoint": "my.s3.provider:9020",
    "protocol": "http",
    "base_path": "snapshots",
    "path_style_access": "true",
    "canned_acl": "bucket-owner-full-control",
    "access_key": "my-access-key",
    "secret_key": "my-secret-key"
  }
}
'

```

I think the issue was ES was trying to validate the creds against AWS when they were set in the keystore. When they are set directly in the snapshot repo, it does not attempt to go out to AWS.

Regardless, I got it working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2023, 4:16pm UTC](https://discuss.elastic.co/t/using-dell-ecs-s3-for-snapshots/324658/7 "2023-03-03T16:16:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
