# How to pass pass username and password as env variable when search-gaurd is securing the ES cluster that is running as docker image

**URL:** <https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507>\
**Category:** Search Guard\
**Created:** [May 20, 2019, 9:52am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507 "2019-05-20T09:52:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![viveksinghggits](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/viveksinghggits/32/538_2.png) [@viveksinghggits](https://forum.search-guard.com/u/viveksinghggits)\
**Post date:** [May 20, 2019, 9:52am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/1 "2019-05-20T09:52:48Z")

</div>

I am not adding configuration files, because this is just an implementation question and I am not getting any error because of the configuration.  
So, I secured official docker image of elastic search by installing the plugin and other required things in the Dockerfile itself.  
If I build the Dockerfile and run the image everything works as expected with the default password `admin/admin`. Now, what I am trying to do is to get the password as env variable while running the image so that we can decide the password while running the image.  
What I am doing right now is accepting the password while we run `docker build` and changed the `sg_internal_users.yml` with the given password then copy this updated `sg_internal_users.yml` config file to the correct location in search-guard.  
My question is how can achieve this is I want to give the password while running the image using `docker run`.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 22, 2019, 11:12am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/2 "2019-05-22T11:12:20Z")

</div>

If you are running SG version 25.0 or above, you can use environment variables in the Search Guard configuration files.

For example, if the **password hash** for your admin user is stored in an environment variable called ADMIN\_PWD\_HASH you can use it like:

```
admin:
  hash: ${env.ADMIN_PWD_HASH}

```

If your **cleartext password** is stored in an environment variable called ADMIN\_PWD, SG can automatically convert it to a hash when replacing the variables, like:

```
admin:
  hash: ${envbc.ADMIN_PWD}

```

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 22, 2019, 11:12am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/3 "2019-05-22T11:12:48Z")

</div>



---

<div class="post-metadata">

**Author:** ![viveksinghggits](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/viveksinghggits/32/538_2.png) [@viveksinghggits](https://forum.search-guard.com/u/viveksinghggits)\
**Post date:** [May 22, 2019, 12:59pm UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/4 "2019-05-22T12:59:59Z")

</div>

Thanks for response and I will have to pass these variables while running the image using `docker run` using the flag `-e "ADMIN_PWD=adminpassw0rd"`, is that correct.  
If you want to see the Dockerfile I can share the link with you.  
`com.floragunn:search-guard-7:7.0.1-35.0.0` is the artifact of the search-guard project that we are using.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 24, 2019, 4:39pm UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/5 "2019-05-24T16:39:55Z")

</div>

Yes, that would be correct. Use the -e flag to pass env variables to Docker, and when applying the configuration files Search Guard will use them.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [June 14, 2019, 4:39pm UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/6 "2019-06-14T16:39:57Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
