# no permissions for \[cluster:monitor/main\]

**URL:** <https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377>\
**Category:** Search Guard\
**Created:** [March 18, 2019, 3:21pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377 "2019-03-18T15:21:01Z")\
**Posts on this page:** 1\
**Showing post:** 18

<div class="post-metadata">

**Author:** ![viveksinghggits](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/viveksinghggits/32/538_2.png) [@viveksinghggits](https://forum.search-guard.com/u/viveksinghggits)\
**Post date:** [June 28, 2019, 6:49pm UTC](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377/18 "2019-06-28T18:49:38Z")

</div>

so, I am using elastic’s official elastic search image to run elastcsearch version `6.7.2` and installing search guard plugin version `com.floragunn:search-guard-6:6.7.2-25.1` in the `Dockerfile`. Now the very same thing works when I tried it all with elasticsearch version `7.0.1` but getting below error If I run that docker image which runs the version `6.7.2`  
Dockerfile can be found at

> **[GitHub - viveksinghggits/dockerfiles: Dockerfiles for the official Elastic...](https://github.com/viveksinghggits/dockerfiles)**
>
> Dockerfiles for the official Elastic Stack images and secured through basic authentication. - GitHub - viveksinghggits/dockerfiles: Dockerfiles for the official Elastic Stack images and secured thr...

```auto
{
"error": {
"root_cause": [
{
"type": "security_exception",
"reason": "no permissions for [cluster:monitor/main] and User [name=admin, roles=[], requestedTenant=null]"
}
],
"type": "security_exception",
"reason": "no permissions for [cluster:monitor/main] and User [name=admin, roles=[], requestedTenant=null]"
},
"status": 403
}

```

I tried to change the `sg_roles_mapping.yml` with mentioned values but agadmin failed with below error  
`sg_roles_mapping.yml`

```auto
sg_user:
  users:
    - admin:
    readall: true

```

`sgadmin.sh` error

```auto
Will update 'sg/rolesmapping' with ../sgconfig/sg_roles_mapping.yml 
   FAIL: Configuration for 'rolesmapping' failed because of com.fasterxml.jackson.dataformat.yaml.snakeyaml.error.MarkedYAMLException: while parsing a block collection
 in 'reader', line 37, column 5:
        - admin:
        ^
expected <block end>, but found Key
 in 'reader', line 38, column 5:
        readall: true  
        ^

```

It looks like an issue with the format in which I am making the the entry , but I was not able to resolve that.  
Once more thing, do I actually need to do this, because I dont get any error if try to do the same thing and install it on my ubuntu machine and not in docker.  
Any help is appreciated.

---

_[View the full topic](https://forum.search-guard.com/t/no-permissions-for-cluster-monitor-main/1377)._
