Repository navigation
Starting the elastic-agent docker container fails resolving ELASTICSEARCH_API_KEY variable even when it is provided #9328
Description
Activity
- addedbugSomething isn't workingSomething isn't workingTeam:Elastic-Agent-Control-PlaneLabel for the Agent Control Plane teamLabel for the Agent Control Plane team
on Aug 12, 2025 Pinging @elastic/elastic-agent-control-plane (Team:Elastic-Agent-Control-Plane)
@ycombinator was able to determine that the change in this commit b59d51a#diff-efef2d2536ab052feff95a0b0565325806b28e733bb9f2abc319b646194d4de5 caused the error.
looking into determining why and the proper fix
The issue here is that the variables are not defined exactly the same as
go-ucfgreferences them.go-ucfgallowed${env.ELASTICSEARCH_API_KEY:}but the AST variable substitution requires${env.ELASTICSEARCH_API_KEY:''}. The missing''at the end is the issue.This was an over sight on my part. I think allowing the AST to work with
${env.ELASTICSEARCH_API_KEY:}is the better solution as this would be non-breaking and doesn't require others to update there existing configuration. Which was the original goal of the b59d51aThe issue here is that the variables are not defined exactly the same as go-ucfg references them. go-ucfg allowed ${env.ELASTICSEARCH_API_KEY:} but the AST variable substitution requires ${env.ELASTICSEARCH_API_KEY:''}. The missing '' at the end is the issue.
Can we quickly add the missing
''to? This would fix this immediately in a low effort way immediately with the default container configuration.elastic-agent/_meta/config/elastic-agent.docker.yml.tmpl
Lines 7 to 10 in e69dd4c
hosts: '${ELASTICSEARCH_HOSTS:http://elasticsearch:9200}' username: '${ELASTICSEARCH_USERNAME:}' password: '${ELASTICSEARCH_PASSWORD:}' api_key: '${ELASTICSEARCH_API_KEY:}' I think allowing the AST to work with ${env.ELASTICSEARCH_API_KEY:} is the better solution as this would be non-breaking and doesn't require others to update there existing configuration. Which was the original goal of the b59d51a
This makes sense as long as it is straight forward and doesn't have any other trade offs. 9.1.0 was released on July 29th so this hasn't been out in the wild for that long, we may see other reports of this later (though nobody internally has noticed it for 6 months).
@cmacknz My comment was a little off. Once I dug more it was actually that it is using
:and not|.Reacted by Craig MacKenzie- linked a pull request that will close this issueAdd support for variable parser to handle `:` as default constant . #9451
on Aug 19, 2025
Allowing users to set the API key via an environment variable was introduced in #5536 which was first available in 9.0.0.
Any 9.0.0 and above container will fail to start with a
failed: no matching vars: ${env.ELASTICSEARCH_API_KEY:}error even when the environment variable is provided.The 8.19.0 container will fail to start with a similar error, but this time related to the ELASTICSEARCH_HOSTS variable as the ELASTICSEARCH_API_KEY variable does not exist in that branch: