# Disable login kibana 8.2

**URL:** <https://discuss.elastic.co/t/disable-login-kibana-8-2/304599>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** elastic-stack-security\
**Created:** [May 12, 2022, 3:19pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599 "2022-05-12T15:19:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![crimson\_riot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crimson_riot/32/100766_2.png) [@crimson\_riot](https://discuss.elastic.co/u/crimson_riot)\
**Post date:** [May 12, 2022, 3:19pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/1 "2022-05-12T15:19:37Z")

</div>

We are using eck operator and oauth2-proxy for single sign on. And we want to disable the kibana login page so that after successful sign in, oauth2 directly will take the user to dashboard. But how should we do that? when we do `xpack.security.disabled: false` on Elasticsearch.yml, It gives error:

```auto
{"timestamp": "2022-05-12T15:15:24+00:00", "message": "readiness probe failed", "curl_rc": "35"}

```

Elasticsearch.yml:

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: es_cluster
spec:
  version: 8.2.0
  nodeSets:
    - name: default
      count: 1
      config:
        xpack.security.enabled: false
      podTemplate:
        spec:
          containers:
            - name: elasticsearch
              env:
                - name: ES_JAVA_OPTS
                  value: 1
              resources:
                requests:
                  memory: 1
                  cpu: 2
                limits:
                  memory: 128
        volumeClaimTemplates:
          - metadata:
              name: elasticsearch-data
            spec:
              accessModes:
                - ReadWriteOnce
              resources:
                requests:
                  storage: 70
              storageClassName: gp2

```

kibana.yml:

```auto
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: kibana
spec:
  version: 8.2.0
  http:
    service:
      spec:
        type: LoadBalancer
        ports:
        - name: https
          port: 443
          targetPort: 3000
      metadata:
        annotations:
          # Note that the backend talks over HTTP.
          service.beta.kubernetes.io/aws-load-balancer-backend-protocol: http
          # TODO: Fill in with the ARN of your certificate.
          service.beta.kubernetes.io/aws-load-balancer-ssl-cert: 
          # Only run SSL on the port named "https" below.
          service.beta.kubernetes.io/aws-load-balancer-ssl-ports: "https"
    tls:
      selfSignedCertificate:
        disabled: true
  count: 1
  elasticsearchRef:
    name: kube-es
  podTemplate:
    spec:
      containers:
      - name: kibana
        resources:
          requests:
            memory: 1Gi
            cpu: 0.5
          limits:
            memory: 2.5Gi
            cpu: 2
      - name: kibana-proxy
        image: 'quay.io/oauth2-proxy/oauth2-proxy:latest'
        imagePullPolicy: IfNotPresent
        args:
          - --cookie-secret=
          - --client-id=
          - --client-secret=
          - --upstream=http://localhost:5601
          - --email-domain=
          - --footer=-
          - --http-address=http://:3000
          - --redirect-url=
        ports:
          - containerPort: 3000
            name: http
            protocol: TCP
        resources:
          limits:
            memory: 500Mi
          requests:
            cpu: 0.5
            memory: 256Mi

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 13, 2022, 10:45am UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/2 "2022-05-13T10:45:54Z")

</div>

Why use an oauth proxy when Kibana can do oauth natively?

---

<div class="post-metadata">

**Author:** ![crimson\_riot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crimson_riot/32/100766_2.png) [@crimson\_riot](https://discuss.elastic.co/u/crimson_riot)\
**Post date:** [May 13, 2022, 11:03am UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/3 "2022-05-13T11:03:00Z")

</div>

Yes, this was the way it was setup previously in our company so we thought we could just replicate it on kubernetes. But we can use the native one also. But just curious, how can we disable the login on kibana ?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 13, 2022, 12:46pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/4 "2022-05-13T12:46:10Z")

</div>

With eck, idk if that's possible.

---

<div class="post-metadata">

**Author:** ![crimson\_riot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crimson_riot/32/100766_2.png) [@crimson\_riot](https://discuss.elastic.co/u/crimson_riot)\
**Post date:** [May 13, 2022, 5:13pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/5 "2022-05-13T17:13:37Z")

</div>

Even when i try to do oauth natively, It asks for `xpack.security.authc.realms.oidc.oidc1.rp.client_secret` which needs to be stored in keystore as per documentation. But how would I be able to enter my `client_secret` in keystore using just yaml files?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 14, 2022, 2:19pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/6 "2022-05-14T14:19:59Z")

</div>

U can create a k8s secret with the value and then add it to the config. See [Secure settings | Elastic Cloud on Kubernetes [2.2] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-es-secure-settings.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2022, 2:20pm UTC](https://discuss.elastic.co/t/disable-login-kibana-8-2/304599/7 "2022-06-11T14:20:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
