# Does elastic have a healthcheck endpoint that does not require username and password

**URL:** <https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [January 30, 2020, 1:25am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090 "2020-01-30T01:25:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pingz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pingz/32/58555_2.png) [@pingz](https://discuss.elastic.co/u/pingz)\
**Post date:** [January 30, 2020, 1:25am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/1 "2020-01-30T01:25:44Z")

</div>

Problem description: AWS ALB health check does not take in username and password. For elastic search container to attach to ALB and pass its health check, I have to enable the anonymous user in elastic and assign it the superuser role.  
xpack.security.authc:  
anonymous:  
username: anonymous  
roles: superuser  
authz\_exception: false

The problem is that anonymous user role is also inherited by other created users later, so the user role does not work. Any user created, although they are assigned with specific role, they all seem to have superuser role permission. I would like to disable the anonymous user, but also would like to know if there is a way to perform a health check without providing username and password to health check endpoint

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [January 30, 2020, 9:23am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/2 "2020-01-30T09:23:15Z")

</div>

@pingz I think you can [create your own role](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/security-api-put-role.html) with restricted [privileges](https://www.elastic.co/guide/en/elasticsearch/reference/6.6/security-privileges.html#privileges-list-cluster), and not use the `superuser` role for anonymous access.

Currently there isn't any separate dedicated healthcheck endpoint with different restrictions. [https://github.com/elastic/elasticsearch/issues/50187](https://github.com/elastic/elasticsearch/issues/50187) is open to handle health checks differently in Elasticsearch.

Looking at AWS ALB documentation, it looks like the LoadBalancer has its own healthcheck logic, that can be [configured when used through an Ingress resource](https://kubernetes-sigs.github.io/aws-alb-ingress-controller/guide/ingress/annotation/). I would have expected the healthcheck to be bound to the Pod readiness but apparently that's not the case. I don't see any way to add authentication to the healthcheck.  
A workaround could be to setup your own sidecar container in the Elasticsearch podTemplate, that would listen to an unauthenticated HTTP port to perform authenticated Elasticsearch calls.  
You can also use a different Ingress implementation.[ingress-nginx](https://kubernetes.github.io/ingress-nginx/) is a popular one.

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [January 30, 2020, 9:35am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/3 "2020-01-30T09:35:10Z")

</div>

@michael.morello rightly pointed out to me that you can also [customize the ALB success-code annotation](https://kubernetes-sigs.github.io/aws-alb-ingress-controller/guide/ingress/annotation/#success-codes) to consider an HTTP 401 status code means the Pod is ready. Far from perfect of course.

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [January 30, 2020, 4:13pm UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/4 "2020-01-30T16:13:21Z")

</div>

I created [https://github.com/elastic/cloud-on-k8s/issues/2488](https://github.com/elastic/cloud-on-k8s/issues/2488) to improve our documentation around this.

---

<div class="post-metadata">

**Author:** ![pingz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pingz/32/58555_2.png) [@pingz](https://discuss.elastic.co/u/pingz)\
**Post date:** [January 30, 2020, 6:33pm UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/5 "2020-01-30T18:33:11Z")

</div>

Hi Sebgl:

Thanks for your reply. Yes, I am considering using 401 status code as a workaround for elastic. For Kibana I used /login rest api, will need to check its code from 200 to something else as well.

---

<div class="post-metadata">

**Author:** ![Hugo\_Martin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hugo_martin/32/90763_2.png) [@Hugo\_Martin](https://discuss.elastic.co/u/Hugo_Martin)\
**Post date:** [June 30, 2021, 11:48am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/6 "2021-06-30T11:48:17Z")

</div>

Hi !  
You can point your LB endpoint to `/login`, it returns a 200 without any authorization. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:42am UTC](https://discuss.elastic.co/t/does-elastic-have-a-healthcheck-endpoint-that-does-not-require-username-and-password/217090/7 "2022-11-04T07:42:44Z")

</div>


