# How to pass pass username and password as env variable when search-gaurd is securing the ES cluster that is running as docker image

**URL:** <https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507>\
**Category:** Search Guard\
**Created:** [May 20, 2019, 9:52am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507 "2019-05-20T09:52:47Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 22, 2019, 11:12am UTC](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/2 "2019-05-22T11:12:20Z")

</div>

If you are running SG version 25.0 or above, you can use environment variables in the Search Guard configuration files.

For example, if the **password hash** for your admin user is stored in an environment variable called ADMIN\_PWD\_HASH you can use it like:

```
admin:
  hash: ${env.ADMIN_PWD_HASH}

```

If your **cleartext password** is stored in an environment variable called ADMIN\_PWD, SG can automatically convert it to a hash when replacing the variables, like:

```
admin:
  hash: ${envbc.ADMIN_PWD}

```

---

_[View the full topic](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507)._
