# Variables substitution doesn't work from keystore in username/password fields of metricbeat.yml in autodiscover.providers.templates.config section

**URL:** <https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [June 17, 2019, 5:23pm UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125 "2019-06-17T17:23:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nevmerzhitsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nevmerzhitsky/32/48238_2.png) [@nevmerzhitsky](https://discuss.elastic.co/u/nevmerzhitsky)\
**Post date:** [June 17, 2019, 5:23pm UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125/1 "2019-06-17T17:23:04Z")

</div>

Hi there!

How can I use keystore variables in `autodiscover.providers.templates.config` section of metricbeat.yml? It looks like broken. Version 7.1.0.

How to reproduce:

1. Setup Docker for running next services
2. Setup Elasticsearch and configure Metricbeat to connect to it
3. Run a RabbitMQ service with an username and a password for authorization
4. Add QUEUE\_USERNAME and QUEUE\_PASSWORD to Metricbeat keystore via `metricbeat keystore add` with appropriate values
5. Add a block like this to metricbeat.yml:

```auto
  autodiscover:
    providers:
      - type: docker
        templates:
          - condition:
              equals:
                docker.container.labels.com.docker.swarm.service.name: depth-history_queue
            config:
              - module: rabbitmq
                period: 10s
                hosts: ['${data.host}:${data.port}']
                username: ${QUEUE_USERNAME}
                password: ${QUEUE_PASSWORD}

```

1. Start the beat

Expected:  
Metricbeat successfully connected to RabbitMQ service.

But it doesn't.

Interesting additional info:

1. For debugging purposes, you can use "`${QUEUE_PASSWORD}`" as a value for field `output.elasticsearch.hosts` of metricbeat.yml and you will see the finish value of `QUEUE_PASSWORD` variable from the keystore in logs of the beat (in error messages about the connection to Elasticsearch). Therefore the keystore really store the correct value.

2. If you replace `${QUEUE_USERNAME}` and `${QUEUE_PASSWORD}` by hard-coded values in metricbeat.yml and restart the beat it will work. Therefore Metricbeat can connect to RabbitMQ with auth.

3. Even if you return the vars back to metricbeat.yml and add 2 Linux env vars `QUEUE_USERNAME` and `QUEUE_PASSWORD` and restart the beat it will work too. Therefore some variables substitution works in the `autodiscover.providers.templates.config` section.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 18, 2019, 9:25am UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125/2 "2019-06-18T09:25:28Z")

</div>

Hi @nevmerzhitsky,

Thank you for your feedback. Just want to make sure I understood this, did you test this very same config without the keystore references? If the answer is yes that would probably mean there is an issue when using keystore variables from autodiscover templates. Could you open a bug report for this? [https://github.com/elastic/beats/issues](https://github.com/elastic/beats/issues)

Best regards

---

<div class="post-metadata">

**Author:** ![nevmerzhitsky](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nevmerzhitsky/32/48238_2.png) [@nevmerzhitsky](https://discuss.elastic.co/u/nevmerzhitsky)\
**Post date:** [June 18, 2019, 1:02pm UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125/3 "2019-06-18T13:02:40Z")

</div>

Yes, I did it - mentioned as point 2 in the last list in the post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2019, 1:02pm UTC](https://discuss.elastic.co/t/variables-substitution-doesnt-work-from-keystore-in-username-password-fields-of-metricbeat-yml-in-autodiscover-providers-templates-config-section/186125/4 "2019-07-16T13:02:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
