# ECK and AD authentication for KIbana

**URL:** <https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** elastic-stack-security\
**Created:** [March 27, 2020, 5:23pm UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447 "2020-03-27T17:23:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigdamhero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigdamhero/32/34478_2.png) [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Post date:** [March 27, 2020, 5:23pm UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/1 "2020-03-27T17:23:27Z")

</div>

Anyone got this working? I am not familiar enough to guess what the config that needs to be added to the containers should look like and where to put it. Any samples would be very welcome thank you.

---

<div class="post-metadata">

**Author:** ![Anya\_Sabo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anya_sabo/32/49903_2.png) [@Anya\_Sabo](https://discuss.elastic.co/u/Anya_Sabo)\
**Post date:** [March 27, 2020, 7:44pm UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/2 "2020-03-27T19:44:42Z")

</div>

@bigdamhero have you seen the docs here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html) ?

You'd place that configuration in the `config` section of the spec as described here:  
[https://www.elastic.co/guide/en/cloud-on-k8s/1.0/k8s-node-configuration.html](https://www.elastic.co/guide/en/cloud-on-k8s/1.0/k8s-node-configuration.html)

---

<div class="post-metadata">

**Author:** ![tsbayne](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@tsbayne](https://discuss.elastic.co/u/tsbayne)\
**Post date:** [April 30, 2020, 6:29pm UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/3 "2020-04-30T18:29:36Z")

</div>

Thank you for this. That did point me in the right direction. If I could expand on the original question, what about the role mapping file? I'm not sure how to incorporate that into the ECK deployment.

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [May 7, 2020, 9:42am UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/4 "2020-05-07T09:42:18Z")

</div>

Since ECK 1.1.0, you can create custom roles using the file-based role management by referencing Kubernetes secrets containing the roles specification: [https://www.elastic.co/guide/en/cloud-on-k8s/1.1/k8s-users-and-roles.html#k8s\_creating\_custom\_roles](https://www.elastic.co/guide/en/cloud-on-k8s/1.1/k8s-users-and-roles.html#k8s_creating_custom_roles).

---

<div class="post-metadata">

**Author:** ![tsbayne](https://avatars.discourse-cdn.com/v4/letter/t/3d9bf3/32.png) [@tsbayne](https://discuss.elastic.co/u/tsbayne)\
**Post date:** [May 7, 2020, 10:39am UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/5 "2020-05-07T10:39:35Z")

</div>

Of all the many documents I've read from elastic the last few weeks while learning this stuff, I've never seen that page. Looks pretty straightforward. Thank you for your guidance! I'll give it a shot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:51am UTC](https://discuss.elastic.co/t/eck-and-ad-authentication-for-kibana/225447/6 "2022-11-04T07:51:08Z")

</div>


