# Elastic and Kibana 8.1.0 via Docker Compose

**URL:** https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907
**Category:** Elastic Search
**Tags:** docker
**Created:** [March 17, 2022, 1:12am UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907 "2022-03-17T01:12:49Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![st11x](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st11x/32/103141_2.png) [@st11x](https://discuss.elastic.co/u/st11x)
#### Post date: [March 17, 2022, 1:12am UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/1 "2022-03-17T01:12:50Z")

</div>

With 8.1.0, security is enabled by default and a SSL certificate is generated for localhost. I have this docker compose file.

```auto
elastic:
    image: elasticsearch:8.1.0
    ports:
      - 9200:9200
      - 9300:9300

    environment:
      - "ES_JAVA_OPTS=-Xms512m -Xmx512m"
      - discovery.type=single-node

  kibana:
    image: kibana:8.1.0
    ports:
      - 5601:5601

    depends_on:
      - elastic

```

When I set up Kibana, I cannot use [http://elastic](http://elastic) nor [https://elastic](https://elastic) through manual configuration, **http** is not available and **elastic** is not in the certificate.

If I configure with the Elastic token, then it sets it to a IP address to an 172.x Docker address. That is not desired.

Is there a way to make it work with the elastic host without any manual tweaking post install?

thanks  
Matt

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 17, 2022, 3:45am UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/2 "2022-03-17T03:45:29Z")

</div>

Welcome!

Have a look at the provided examples. I think this could help: [Install Elasticsearch with Docker | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-compose-file)

However, if you are using curl, you will need to use `--insecure` option because of the self-signed certificates.

---

<div class="post-metadata">

### Author: ![st11x](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st11x/32/103141_2.png) [@st11x](https://discuss.elastic.co/u/st11x)
#### Post date: [March 17, 2022, 3:20pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/3 "2022-03-17T15:20:34Z")

</div>

@dadoonet Thanks for the reference.

I was thinking there might be a less manual tweaking option this being Docker. There's quite a lot of code in the sample Docker compose file alone.

In previous versions, before security was enforced, the setup was much simpler. Hopefully this can get easier in future versions.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 17, 2022, 7:15pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/4 "2022-03-17T19:15:28Z")

</div>

Well I guess it can be easier if you have generated your own certificates first.

But not an expert. And at least it's documented here 😁

---

<div class="post-metadata">

### Author: ![Justin\_Cranford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_cranford/32/85302_2.png) [@Justin\_Cranford](https://discuss.elastic.co/u/Justin_Cranford)
#### Post date: [March 17, 2022, 10:15pm UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/5 "2022-03-17T22:15:39Z")

</div>

Have a closer look at the example `docker-compose.yml`. Everything is fully automated. The only thing you are probably missing is extracting a copy of `/usr/share/elasticsearch/config/certs/ca.crt`. If you export and use ca.crt, you should be able to run these commands from your host machine.

- `curl -s --cacert /tmp/ca.crt https://localhost:9200/` for es01
- `curl -s --cacert /tmp/ca.crt https://localhost:5601/` for kibana01

Overview:

Container `startup`: Creates volume `/usr/share/elasticsearch/config/certs`. Runs `bin/elasticsearch-certutil` to generate certs/ca.zip. Runs it `again` with a config of SANs to generate certs/certs.zip. Each server cert gets SANs like `localhost`, `127.0.0.1`, and one of `es01/es02/es03/kibana01`. Cert files are stored in the `certs` volume, and get mounted by subsequent containers. You should be able to use Docker Compose volume commands to extract a copy of ca.crt to your host machine too.

Containers `es01`, `es02`, `es03`, `kibana01`: Mounts `/usr/share/elasticsearch/config/certs`. Starts Elasticsearch/Kibana with ca.crt and one of the server certs. Health checks do full trust checking and hostname verification, such as `curl -s --cacert config/certs/ca/ca.crt https://localhost:9200`. Server cert SANs were populated with `localhost` by the `setup` container.

Get a copy of `/usr/share/elasticsearch/config/certs/ca.crt` from the `certs` volume. Use it in your host machine. Use it in curl for trust checking. Docker Compose port mapping via localhost allows hostname checking to pass too.

If you are using a HTTPS browser, import ca.crt temporarily into your browser's truststore. If your browser complains about localhost certs (ex: Chrome), you may need to click through that warning, or configure your browser to allow `localhost` SANs.

---

<div class="post-metadata">

### Author: ![st11x](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st11x/32/103141_2.png) [@st11x](https://discuss.elastic.co/u/st11x)
#### Post date: [March 19, 2022, 1:45am UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/6 "2022-03-19T01:45:05Z")

</div>

Thanks for the explanation.

I was thinking it was more “out of the box”. Perhaps like passing an environment variable of hostnames and it does the rest. Maybe a shared named volume between them to distribute the certs. Helps for someone new to it like me.

Once you have a bit more experience, scripting it outside of docker-compose like what @dadoonet suggested is a good option.

Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:34am UTC](https://discuss.elastic.co/t/elastic-and-kibana-8-1-0-via-docker-compose/299907/7 "2022-11-04T08:34:41Z")

</div>


