# Add subdomain to kibana instance

**URL:** <https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [April 10, 2019, 2:03pm UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235 "2019-04-10T14:03:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tehho](https://avatars.discourse-cdn.com/v4/letter/t/c89c15/32.png) [@tehho](https://discuss.elastic.co/u/tehho)\
**Post date:** [April 10, 2019, 2:03pm UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235/1 "2019-04-10T14:03:50Z")

</div>

Hi.

We would like to add a diffrent subdomain to our kibana instances for human readable urls.  
How do we do this?  
Example: [backup-test.example.com](http://backup-test.example.com)

When we have a CNAME from [backup-test.example.com](http://backup-test.example.com) pointed to [GUID.example.com](http://GUID.example.com) and [GUID.example.com](http://GUID.example.com) pointed to the ece proxy loadbalancer ip this works. But not when we have [backup-test.example.com](http://backup-test.example.com) pointed directly to the ip.

To handle easy setup we want to be able to create CNAME [clustername.example.com](http://clustername.example.com) pointed to [eceproxy.example.com](http://eceproxy.example.com) and handle the clustername in the kibana config in ece.

We have setup xpack.security.public using below settings:  
xpack.security.public:  
protocol: https  
hostname: [backup-test.example.com](http://backup-test.example.com)  
port: 443

Are there some dns lookups in ece that translates the host to a cname if not found?

Best regards  
Andreas Antonsson  
Collectorbank

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 10, 2019, 3:43pm UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235/2 "2019-04-10T15:43:11Z")

</div>

If you cannot prefix the cluster id at the start of the URL, then you need an `nginx` or similar in the middle that can inject the header `X-Found-Cluster: <GUID>`, otherwise the ECE proxy does not know where to send the traffic.

Alex

---

<div class="post-metadata">

**Author:** ![tehho](https://avatars.discourse-cdn.com/v4/letter/t/c89c15/32.png) [@tehho](https://discuss.elastic.co/u/tehho)\
**Post date:** [April 11, 2019, 6:23am UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235/3 "2019-04-11T06:23:33Z")

</div>

But then why does it work when we have a CNAME to the GUID hostname.  
The CNAME does not get added to any headers by default.

This also breaks if you place another CNAME in between.  
Ex: CNAME Backup-test -\> CNAME Test -\> GUID Does not work

Can we have a feature request to add a function to add a specific hostname to a cluster in ECE.  
Sort of you are also hostname: INSERT\_GOOD\_NAME\_HERE  
There are some annotations that point to xpack.security.public being the solution but the above setup does not work with our nginx.  
The nginx is configured to pass all 443 to 9200 on the eceproxys.

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 11, 2019, 1:14pm UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235/4 "2019-04-11T13:14:31Z")

</div>

> But then why does it work when we have a CNAME to the GUID hostname

@tehho There's a bunch of places (headers, `Host:` header, URL) where we search for a `GUID`

I haven't specifically looked to see where `cname` gets embedded in the HTTP request, but if it works then it must be one of the above 🙂

> Can we have a feature request to add a function to add a specific hostname to a cluster in ECE.

We have such a feature on our roadmap - it's often requested! It's been blocked by a larger change to the proxy architecture. That's mostly done so it should get moving again soon.

> There are some annotations that point to xpack.security.public

Not sure what this does, but there's a pretty standard nginx config to do what you state, something along the lines of:

```auto
upstream es_backend {
     server GUID.ip.es.io:9243;
}

server {
  listen 127.0.0.1:9000;

  location / {
    proxy_pass https://es_backend/;
    proxy_ssl_protocols TLSv1.2;
    proxy_ssl_session_reuse on;
    proxy_ssl_verify off;
    proxy_set_header X-Found-Cluster GUID;
    proxy_http_version 1.1;
    proxy_set_header Authorization "Basic AUTHENCODED==";
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2019, 1:14pm UTC](https://discuss.elastic.co/t/add-subdomain-to-kibana-instance/176235/5 "2019-04-25T13:14:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
