# Bash Scripting ElasticSearch and Kibana Passwords

**URL:** <https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [October 23, 2022, 7:12pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285 "2022-10-23T19:12:43Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ihms](https://avatars.discourse-cdn.com/v4/letter/i/3ec8ea/32.png) [@Ihms](https://discuss.elastic.co/u/Ihms)\
**Post date:** [October 23, 2022, 7:12pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/1 "2022-10-23T19:12:43Z")

</div>

I have a bash script that automates the installation and configuration of Elastic, Kibana, Logstash, and filebeat.

I am currently trying to secure my Kibana. I have enabled xpack in my `elastic.yml`: `xpack.security.enabled: true`.

And have included `bin/elasticsearch-setup-passwords auto` to the script, but this would still require the user to manually copy the password into the `kibana.yml` file. Is there any way to specifically set what I want my password to be in the script and just put whatever I have set in my `kibana.yml` file so everything is still automated?

---

<div class="post-metadata">

**Author:** ![A\_Mightiev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_mightiev/32/62186_2.png) [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Post date:** [October 23, 2022, 8:12pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/2 "2022-10-23T20:12:28Z")

</div>

you can use `bin/elasticsearch-keystore` instead  
more on the documentation here:  
[elasticsearch-keystore](https://www.elastic.co/guide/en/elasticsearch/reference/current/elasticsearch-keystore.html)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 23, 2022, 9:10pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/3 "2022-10-23T21:10:11Z")

</div>

Frist thing would be to start using `elasticsearch-reset-password`, the `elasticsearch-setup-passwords` is deprecated in version 8, the new tool is [elasticsearch-reset-password](https://www.elastic.co/guide/en/elasticsearch/reference/current/reset-password.html).

Then you would need to run it in the interactive mode and try to combine it with the expect tool in your bash script, this way you may be able to provide a custom password.

It would be best to not use a username and password in Kibana, but use a service account, there is also a [CLI tool](https://www.elastic.co/guide/en/elasticsearch/reference/current/service-tokens-command.html#service-tokens-command). to create the service account.

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [October 24, 2022, 10:52am UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/4 "2022-10-24T10:52:20Z")

</div>

But still you have to copy passwords from output and put them into keystore.

---

<div class="post-metadata">

**Author:** ![Ihms](https://avatars.discourse-cdn.com/v4/letter/i/3ec8ea/32.png) [@Ihms](https://discuss.elastic.co/u/Ihms)\
**Post date:** [October 24, 2022, 10:43pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/5 "2022-10-24T22:43:23Z")

</div>

Thanks, I will consider the service account. Can I decide to create a user in my script by having a line such as:

`bin/elasticsearch-users useradd jacknich -p theshining -r admin`

If I make this user an admin, Would they be able to access the Kibana dashboard without any restrictions? Also, would I still need to add the below lines in `kibana.yml`?

```auto
elastic.username: jacknich
elastic.password: theshining

```

---

<div class="post-metadata">

**Author:** ![cheshirecat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheshirecat/32/109532_2.png) [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Post date:** [October 25, 2022, 11:33am UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/6 "2022-10-25T11:33:33Z")

</div>

> [@Ihms](#):
>
> Also, would I still need to add the below lines in `kibana.yml`?

Those lines are for system user that connects Kibana to Elasticsearch.  
If you would like to create a new admin user you do not have to change those values.

---

<div class="post-metadata">

**Author:** ![A\_Mightiev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_mightiev/32/62186_2.png) [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Post date:** [October 25, 2022, 6:09pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/7 "2022-10-25T18:09:36Z")

</div>

Here's another idea. when you run manually the elasticsearch-keystore or the reset password it will generate an encrypted keystore file stored in your system, maybe you can store them in a vault together with the encryption key so when you deploy them automatically you also deploy the keystore and the encryption key.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2022, 2:53am UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/8 "2022-11-22T02:53:45Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2022, 11:35pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/9 "2022-12-19T23:35:56Z")

</div>



---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2023, 11:36pm UTC](https://discuss.elastic.co/t/bash-scripting-elasticsearch-and-kibana-passwords/317285/10 "2023-01-16T23:36:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
