Install plugins with init containers on Elastic Cloud on Kubernetes

Use an init container to run elasticsearch-plugin install before the main Elasticsearch container starts. Each new node repeats the download, so the pods need network access to reach the plugin source.

The following example installs the ICU analysis plugin:

spec:
  nodeSets:
  - name: default
    count: 3
    podTemplate:
      spec:
        initContainers:
        - name: install-plugins
          command:
          - sh
          - -c
          - |
            bin/elasticsearch-plugin remove --purge analysis-icu
            bin/elasticsearch-plugin install --batch analysis-icu
		

For more information on how init containers behave in Kubernetes, refer to the Kubernetes init containers documentation.

Tip

You can also build the plugins into your own Elasticsearch image, as described in Create custom images. To compare that approach with init containers, refer to Add plugins and custom configuration files in Elastic Cloud on Kubernetes.

Unless you override them, the init container inherits:

  • The image of the main Elasticsearch container, if one is not explicitly set.
  • The volume mounts from the main container, unless a volume mount with the same name and mount path is already defined on the init container.
  • The Pod name and IP address environment variables.

When using Istio, an init container typically has no network access, because the Envoy sidecar that provides connectivity has not started yet. The plugin download then fails. You have three options:

  • Allow the outbound ports that the init container needs, so that its traffic bypasses the sidecar. For a manifest that installs a plugin this way, refer to Using init containers with Istio CNI.
  • Use a custom container image that already includes the plugins, so that nothing is downloaded at startup.
  • Run the plugin install in the Elasticsearch container's startup command, as shown in the following section.

If allowing the ports and using a custom image are both impractical, you can run the plugin install in the Elasticsearch container’s startup command before Elasticsearch starts. You may need to update that command if the entrypoint in the Elasticsearch image changes, which can cause failures during upgrades. The following is an example.

spec:
  nodeSets:
  - name: default
    count: 3
    podTemplate:
      spec:
        containers:
        - name: elasticsearch
          command:
          - /usr/bin/env
          - bash
          - -c
          - |
            #!/usr/bin/env bash
            set -e
            bin/elasticsearch-plugin remove --purge repository-s3 || true
            bin/elasticsearch-plugin install --batch repository-s3
            /bin/tini -- /usr/local/bin/docker-entrypoint.sh