2022-02-26 20:31:57 +01:00
# generate ca and tls certs for elasticsearch cluster
2022-05-04 16:27:46 +02:00
start a `bash` in an elasticsearch image, such as `docker.elastic.co/elasticsearch/elasticsearch:8.2.0` : `docker run -ti docker.elastic.co/elasticsearch/elasticsearch:8.2.0 bash`
2022-02-26 20:31:57 +01:00
generate a ca and node certs:
```bash
./bin/elasticsearch-certutil ca
./bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12
```
2022-05-04 16:27:46 +02:00
write these files in Consul at `secrets/telemetry/elasticsearch/elastic-certificates.p12` and `secrets/telemetry/elasticsearch/elastic-stack-ca.p12`
# start nomad services
2022-02-26 20:31:57 +01:00
```bash
2022-05-04 16:27:46 +02:00
nomad run telemetry-system.hcl
nomad run telemetry.hcl
2022-02-26 20:31:57 +01:00
```
2022-02-26 18:56:16 +01:00
# create elasticsearch passwords
2022-05-04 16:27:46 +02:00
in an elasticsearch container that was launched by Nomad:
2022-02-26 18:56:16 +01:00
```bash
2022-05-04 16:27:46 +02:00
./bin/elasticsearch-reset-password -u elastic
./bin/elasticsearch-reset-password -u kibana
2022-02-26 18:56:16 +01:00
```
save passwords in consul, at:
- `secrets/telemetry/elastic_passwords/kibana_system` for user `kibana_system`
- `secrets/telemetry/elastic_passwords/elastic` for user `elastic`
check kibana works, login to kibana with user `elastic`
2022-05-04 16:27:46 +02:00
grafana and apm-server will use the elastic user (the admin) to write data to elasticsearch