# Cannot set xpack.security.secureCookies from environment (through docker-compose.yml)

**URL:** https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150
**Category:** Kibana
**Created:** [May 18, 2020, 4:13pm UTC](https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150 "2020-05-18T16:13:42Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![braddre](https://avatars.discourse-cdn.com/v4/letter/b/a5b964/32.png) [@braddre](https://discuss.elastic.co/u/braddre)
#### Post date: [May 18, 2020, 4:13pm UTC](https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150/1 "2020-05-18T16:13:43Z")

</div>

For Elastic stack 7.6.0, should xpack.security.secureCookies be read from the kibana environment when it starts? I did this test:

added xpack.security.secureCookies=true to kibana.yml  
built and deployed docker image  
tested with browser -- browser complains if connection lacks TLS

Then I tried setting secureCookies in environment through docker-compose.yml  
Here are the lines from from docker-compose.yml

```
version: "3.7"
services:
  kibana:
    image: lpsd-kibana:${APP_VERSION}
    environment:
      - KIBANA_PASSWORD=${KIBANA_PASSWORD}
      - xpack.security.secureCookies=true

```

Updated kibana.yml to remove secureCookies:

```
bash-4.2$ cat kibana.yml
server.name: kibana
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://elasticsearch:9200"]
xpack.monitoring.ui.container.elasticsearch.enabled: true
elasticsearch.username: "kibana"
elasticsearch.password: ${KIBANA_PASSWORD}
status.allowAnonymous: true
xpack.security.session.idleTimeout: 900s
#xpack.security.secureCookies: true

```

Verified that container environment has secureCookies setting:

```
bash-4.2$ env
ELASTIC_CONTAINER=true
PATH=/usr/share/kibana/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
xpack.security.secureCookies=true
PWD=/usr/share/kibana/config
KIBANA_PASSWORD=abc
HOME=/usr/share/kibana

```

But, browser had no problem display the site without TLS, leading me to conclude secureCookies is not enabled.

Is my test correct, and should secureCookies setting be read from the environment?

---

<div class="post-metadata">

### Author: ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)
#### Post date: [May 19, 2020, 4:56pm UTC](https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150/2 "2020-05-19T16:56:21Z")

</div>

As you can see in the [docs](https://www.elastic.co/guide/en/kibana/current/docker.html#environment-variable-config), the name of the config should be converted to all uppercase and underscore instead of dots. Could you try `XPACK_SECURITY_SECURECOOKIES` instead?

---

<div class="post-metadata">

### Author: ![braddre](https://avatars.discourse-cdn.com/v4/letter/b/a5b964/32.png) [@braddre](https://discuss.elastic.co/u/braddre)
#### Post date: [May 28, 2020, 4:11pm UTC](https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150/3 "2020-05-28T16:11:57Z")

</div>

yes, that did it. Thanks! I do remember reading that settings in environment need to be converted as you describe. But, I also find that sometimes unconverted works, so it's easy to forget

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 25, 2020, 4:12pm UTC](https://discuss.elastic.co/t/cannot-set-xpack-security-securecookies-from-environment-through-docker-compose-yml/233150/4 "2020-06-25T16:12:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
