# Disable enrolment-token requirement on initial startup of Elasticsearch and Kibana

**URL:** <https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [March 9, 2023, 9:41pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399 "2023-03-09T21:41:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Johnston](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_johnston/32/117427_2.png) [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Post date:** [March 9, 2023, 9:41pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/1 "2023-03-09T21:41:50Z")

</div>

Hello. I'm running Elasticsearch and Kibana via docker containers, whose images I'm building from the Dockerfiles from this repository: [GitHub - elastic/dockerfiles: Dockerfiles for the official Elastic Stack images](https://github.com/elastic/dockerfiles). On initial startup, Elasticsearch logs an enrolment token and password to be used to login to the Kibana UI.

I'm wondering if it's possible to configure either the `elasticsearch.yml` file or the `kibana.yml` file, or both, in such a way that the need to enter an enrolment token is no longer required. Also, is there a way to preconfigure the password needed for authentication?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 10, 2023, 12:36am UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/2 "2023-03-10T00:36:10Z")

</div>

Have you looked at [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-compose-file)

---

<div class="post-metadata">

**Author:** ![Matt\_Johnston](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_johnston/32/117427_2.png) [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Post date:** [March 10, 2023, 2:21pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/3 "2023-03-10T14:21:21Z")

</div>

Hi Stephen. Thanks for the link! I had not seen it. I followed the instructions and was able to start Elasticsearch and Kibana while bypassing the requirement for the enrolment token. That is what I was looking for.

However, I guess I'm trying to understand exactly which parts of the code are responsible for disabling the enrolment token. If you have any clues or other links that would help to understand, it would be greatly appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 10, 2023, 2:50pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/4 "2023-03-10T14:50:12Z")

</div>

Hi @Matt_Johnston

I will Take another look when I get a chance, but I'm pretty sure it's just the fact that the needed settings are set before Kibana starts.

```auto
      - ELASTICSEARCH_HOSTS=https://es01:9200
      - ELASTICSEARCH_USERNAME=kibana_system
      - ELASTICSEARCH_PASSWORD=${KIBANA_PASSWORD}
      - ELASTICSEARCH_SSL_CERTIFICATEAUTHORITIES=config/certs/ca/ca.crt

```

Pretty sure this is easy to test. You can simply download a copy of Kibana, put some values for those in the Kibana.yml or set ENV and for those doesn't really matter if it connects or not and pretty sure it'll start up without asking for the token.

---

<div class="post-metadata">

**Author:** ![Matt\_Johnston](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_johnston/32/117427_2.png) [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Post date:** [March 10, 2023, 4:04pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/5 "2023-03-10T16:04:38Z")

</div>

Hi Stephen. Sure enough, when I comment out these three lines

```auto
# - ELASTICSEARCH_HOSTS=https://es01:9200
# - ELASTICSEARCH_USERNAME=kibana_system
# - ELASTICSEARCH_PASSWORD=${KIBANA_PASSWORD}

```

and then run the containers again, Kibana asks for the enrolment token. Thanks a bunch!

---

<div class="post-metadata">

**Author:** ![Matt\_Johnston](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_johnston/32/117427_2.png) [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Post date:** [March 10, 2023, 5:42pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/6 "2023-03-10T17:42:09Z")

</div>

So, I've been trying out a few different things and had another question. I decided to see if I could run separate kibana and elasticsearch containers from the Github repository I linked to above and configure them in a way that the enrolment token was not necessary. I wanted to see if I could mimic what the `docker-compose.yml` file does based on what I understand are the key parts of why the enrolment token doesn't show up when I run the contains through Docker Compose.

In the `kibana.yml` file I added these two lines:

```auto
elasticsearch.username: kibana_system
elasticsearch.password: kibana

```

similar to what the `docker-compose.yml` file has as environment variables for the `kibana` container. However, when I run the elasticsearch and kibana containers and try to access kibana in the browser, I get a message in the top left corner of the browser saying that the "Kibana server is not ready yet." Any idea what's going on here?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 10, 2023, 6:08pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/7 "2023-03-10T18:08:02Z")

</div>

Most likely there is a network issue.. the containers don't know about each other suspect you need to read a bit about docker networking and host network vs docker networks...

Some reading here..

> [@Filebeat Docker - Elasticsearch Host Issue](https://discuss.elastic.co/t/filebeat-docker-elasticsearch-host-issue/320083/2):
>
> Hi @mwsprotte Welcome to the community! Docker Networking Issue not Elastic... Another explanation Might be worth reading... if you are new to docker try using host.docker.internal docker run \ --net=elastic docker.elastic.co/beats/filebeat:7.17.4 \ setup -E setup.kibana.host=host.docker.internal:5601 \ -E output.elasticsearch.hosts=["https://host.docker.internal:9200"]

Please start new threads with the appropriate Subject if you have more questions..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2023, 6:08pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399/8 "2023-04-07T18:08:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
