# Elk stack docker with traefik

**URL:** <https://discuss.elastic.co/t/elk-stack-docker-with-traefik/271872>\
**Category:** Elastic Security\
**Created:** [May 1, 2021, 2:55pm UTC](https://discuss.elastic.co/t/elk-stack-docker-with-traefik/271872 "2021-05-01T14:55:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![siara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siara/32/80562_2.png) [@siara](https://discuss.elastic.co/u/siara)\
**Post date:** [May 1, 2021, 2:55pm UTC](https://discuss.elastic.co/t/elk-stack-docker-with-traefik/271872/1 "2021-05-01T14:55:37Z")

</div>

Hi

I have elk stack in docker with tls from documentation [Running the Elastic Stack on Docker | Getting Started [7.12] | Elastic](https://www.elastic.co/guide/en/elastic-stack-get-started/current/get-started-docker.html)

I try run this on server with traefik. I add traefik network for kibana container and add labels:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/617b8e9f5add204c2f1cfabd8205e34916d3b4da.png)

And I have 502 Bad Gateway on this adres. Stack wihout tls is working with this labels.  
any ideas why is this happening?

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [May 1, 2021, 10:03pm UTC](https://discuss.elastic.co/t/elk-stack-docker-with-traefik/271872/2 "2021-05-01T22:03:51Z")

</div>

I'm not familiar with Traefik and Docker, but I do use Traefik with Kubernetes. One thing you might want to try is making sure you set the scheme that Kibana uses, as I believe by default, even if you are using an https entrypoint, Traefik will still try to send the connection to an http backend.

Here is a Kubernetes example (it's not a 1-to-1 match, but should help)

```auto
---
apiVersion: traefik.containo.us/v1alpha1
kind: IngressRoute
metadata:
  name: kibana-https-ingress
spec:
  entryPoints:
    - websecure
  routes:
    - kind: Rule
      match: KIBANA_MATCH_RULE
      services:
        - kind: Service
          name: KIBANA_SERVICE_NAME
          port: 5601
          passHostHeader: true
          scheme: https #<----- Scheme set here to https (as Kibana is setup to uses https instead of http)
          serversTransport: kibana-server-transport
  tls:
    secretName: kibana-cert
    options:
      name: kibana-tls-options
      namespace: KIBANA_NAMESPACE

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2021, 10:03pm UTC](https://discuss.elastic.co/t/elk-stack-docker-with-traefik/271872/3 "2021-05-29T22:03:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
