# no permissions for \[cluster:monitor/main\]

**URL:** <https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377>\
**Category:** Search Guard\
**Created:** [March 18, 2019, 3:21pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377 "2019-03-18T15:21:01Z")\
**Posts on this page:** 4\
**Page:** 2

<div class="post-metadata">

**Author:** ![hsaly](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/hsaly/32/21_2.png) [@hsaly](https://forum.search-guard.com/u/hsaly)\
**Post date:** [June 30, 2019, 11:26am UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/21 "2019-06-30T11:26:06Z")

</div>



---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [June 30, 2019, 12:27pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/22 "2019-06-30T12:27:37Z")

</div>

Can you please post your Search Guard config files?

---

<div class="post-metadata">

**Author:** ![viveksinghggits](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/viveksinghggits/32/538_2.png) [@viveksinghggits](https://forum.search-guard.com/u/viveksinghggits)\
**Post date:** [June 30, 2019, 3:44pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/23 "2019-06-30T15:44:53Z")

</div>

I have uploaded all the files here, but I would just like to highlight once again that

```auto
everything works if I install elastic search 6.7.2 and respective search guard plugin drectly on my ubuntu machine and not on docker.

```

If you want to look at the Dockerfile I have mentioned the github repo in my previous comment, the one in 6.7 branch.  
Thanks for helping me out with this.

[sg\_roles\_mapping.yml](https://forum.search-guard.com/uploads/short-url/z7T84Z8ivptGZJjd79NltKtEBsI.yml) (548 Bytes) [sg\_roles.yml](https://forum.search-guard.com/uploads/short-url/fPvP6kzMofecU5CCqHfkVxRYkhL.yml) (7.0 KB) [sg\_config.yml](https://forum.search-guard.com/uploads/short-url/rdvC7ewGfKuo9Qss0oFlkXz7v8L.yml) (11.2 KB) [sg\_action\_groups.yml](https://forum.search-guard.com/uploads/short-url/6xqsSpzIXYQXWdM0wKfNdmoumcr.yml) (2.3 KB) [elasticsearch.yml.example](https://forum.search-guard.com/uploads/short-url/rzHCLD6NXO2KxhBHEr7hSZMd58i.example) (9.3 KB) [sg\_internal\_users.yml](https://forum.search-guard.com/uploads/short-url/f1d7vGplNZNkfjBMRU8ZfAjJkiI.yml) (407 Bytes)

---

<div class="post-metadata">

**Author:** ![viveksinghggits](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/viveksinghggits/32/538_2.png) [@viveksinghggits](https://forum.search-guard.com/u/viveksinghggits)\
**Post date:** [July 3, 2019, 4:53pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/25 "2019-07-03T16:53:51Z")

</div>

So, I somehow got elastic search version `6.5.1` working with the respective search guard version i.e. `com.floragunn:search-guard-6:6.5.1-24.3`.  
But now the issue that I have is I think I can not provide the password as environment variable while running docker image if elastic search is being run as docker image. Because that functionality is available after search `guard version 25` as mentioned here in this thread.

> [@How to pass pass username and password as env variable when search-gaurd is securing the ES cluster that is running as docker image](https://forum.search-guard.com/t/how-to-pass-pass-username-and-password-as-env-variable-when-search-gaurd-is-securing-the-es-cluster-that-is-running-as-docker-image/1507/2):
>
> If you are running SG version 25.0 or above, you can use environment variables in the Search Guard configuration files. For example, if the password hash for your admin user is stored in an environment variable called ADMIN\_PWD\_HASH you can use it like: admin: hash: ${env.ADMIN\_PWD\_HASH} If your cleartext password is stored in an environment variable called ADMIN\_PWD, SG can automatically convert it to a hash when replacing the variables, like: admin: hash: ${envbc.ADMIN\_PWD}

Is there a way to achieve the same in this version of search-guard or its not possible to do in versions below that 25.

So, here is the problem now if i run elastic search version less than 6.6, respective search guard version would be less than 25 and providing the password while running docker images wont be possible and if I run elastic search version 6.6 or 6.7 and respective search guard plugin I get issue that is mentioned here

> [@no permissions for \[cluster:monitor/main\]](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/18):
>
> so, I am using elastic’s official elastic search image to run elastcsearch version 6.7.2 and installing search guard plugin version com.floragunn:search-guard-6:6.7.2-25.1 in the Dockerfile. Now the very same thing works when I tried it all with elasticsearch version 7.0.1 but getting below error If I run that docker image which runs the version 6.7.2 Dockerfile can be found at { "error": { "root\_cause": [{ "type": "security\_exception", "reason": "no permissions for [cluster:monitor/main] …

[Previous page](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377.md?page=1)
