# Multi node helm chart service account issue

**URL:** <https://forum.opensearch.org/t/multi-node-helm-chart-service-account-issue/16926>\
**Category:** OpenSearch\
**Created:** [December 4, 2023, 8:05am UTC](https://forum.opensearch.org/t/multi-node-helm-chart-service-account-issue/16926 "2023-12-04T08:05:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![arun\_udaiyar](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@arun\_udaiyar](https://forum.opensearch.org/u/arun_udaiyar)\
**Post date:** [December 4, 2023, 8:05am UTC](https://forum.opensearch.org/t/multi-node-helm-chart-service-account-issue/16926/1 "2023-12-04T08:05:29Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
OS: 2.10  
OD: 2.10

**Describe the issue** :  
I deployed the opensearch as multi node cluster with 3 master and 2 data nodes, by following the below url instruction

> **[Setup OpenSearch multi-node cluster on Kubernetes using Helm Charts](https://opensearch.org/blog/setup-multinode-cluster-kubernetes/)**
>
> Setup OpenSearch multi-node cluster on Kubernetes using Helm Charts.

the cluster is up and running.

> kubectl get po -n opensearch  
> NAME READY STATUS RESTARTS AGE  
> opensearch-cluster-data-0 1/1 Running 0 138m  
> opensearch-cluster-data-1 1/1 Running 0 138m  
> opensearch-cluster-master-0 1/1 Running 0 140m  
> opensearch-cluster-master-1 1/1 Running 0 140m  
> opensearch-cluster-master-2 1/1 Running 0 140m  
> opensearch-dashboard-dcd7ffbd6-lfvlf 1/1 Running 0 131m

but the actual issue is the service account which used to authenticate with gcs bucket is not working.

it throws 403 permission error.

if i go with usual cluster setup the SA works fine.  
**Configuration** :

> rbac:  
> create: true  
> serviceAccountAnnotations: {“[iam.gke.io/gcp-service-account](http://iam.gke.io/gcp-service-account)”: “[opensearch-prod@project-id.iam.gserviceaccount.com](mailto:opensearch-prod@project-id.iam.gserviceaccount.com)”}  
> serviceAccountName: “opensearch-dashboards”

i tried different approach like.

- enabled rbac only for master node
- enabled rbac only for data node
- enabled rbac for both master and data node.

**Relevant Logs or Screenshots** :

but still i face the permission error. did anyonce came across this issue.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [December 4, 2023, 8:45pm UTC](https://forum.opensearch.org/t/multi-node-helm-chart-service-account-issue/16926/2 "2023-12-04T20:45:55Z")

</div>

@arun_udaiyar I never worked with user workload identity. However, have you tried to configure it this way?

```auto
rbac:
  create: true
  serviceAccountAnnotations: 
      iam.gke.io/gcp-service-account: opensearch-prod@project-id.iam.gserviceaccount.com
  serviceAccountName: opensearch-dashboards

```
