# Enabling anonymous access (fileRealm) in kibana

**URL:** <https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [December 13, 2022, 8:30am UTC](https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101 "2022-12-13T08:30:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jane.hwang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jane.hwang/32/114600_2.png) [@jane.hwang](https://discuss.elastic.co/u/jane.hwang)\
**Post date:** [December 13, 2022, 8:30am UTC](https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101/1 "2022-12-13T08:30:46Z")

</div>

Hello,  
I'm a beginner in using elasticsearch and kibana with ECK.  
I have installed elasticsearch and kibana with ECK.

I have already make it possible to login elasticsearch using fileRealm.

elasticsearch.yaml

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: "test"
  namespace: default
spec:
  version: 8.4.2
  auth:
    fileRealm:
      - secretName: test-user-realm-secret

```

secret.yaml

```auto
kind: Secret
apiVersion: v1
metadata:
  name: test-user-realm-secret
  namespace: default
stringData:
  users: |-
    hello:ECRYPT_PASSWORD(BCRYPT)

```

I wanted to make it possible to acess anonymous user to kibana.  
It was possible to acess anonymous user with raw password using kibana yaml file.

kibana.yaml (with raw password)

```auto
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: test-kibana
  namespace: default
spec:
  version: 8.4.2
  count: 1
  podTemplate:
    metadata:
      labels:
        app: test-kibana
  elasticsearchRef:
    name: "test"
    namespace: default
  config:
    xpack.security.authc.providers:
      basic.basic1:
        order: 0
      anonymous.anonymous1:
        order: 1
        credentials:
          username: "hello"
          password: "password"

```

But I couldn't find the way to set encrypted password(Bcrypt) for anonymous user.  
Is there any way to access anonymous to access anonymous user with encrypted password(Bcrypt)?

For example, I want to put the password in yaml file like this. (bcrypt)

`password: "$2a$12$Mc/gFfMwC6ctkeLkqRbd8exhTAFJnJh4C9nurjsw7mR3fGXyfduDe"`

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [December 27, 2022, 2:35pm UTC](https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101/2 "2022-12-27T14:35:44Z")

</div>

Hi @jane.hwang welcome to the Elastic discussion forum.

I'm pretty sure you cannot specify the password for anonymous access other than as a raw string as the [documentation explains](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#anonymous-authentication).

Maybe you can inject the password using an environment variable that allows you to store the password elsewhere?

From the configuration docs:

> environment variables can be injected into configuration using `${MY_ENV_VAR}` syntax

So in your case it would mean to create a pretty ugly env var named:

```auto
XPACK_SECURITY_AUTHC_PROVIDERS_ANONYMOUS_ANONYMOUS1_CREDENTIALS_PASSWORD

```

Hope it helps.

---

<div class="post-metadata">

**Author:** ![jane.hwang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jane.hwang/32/114600_2.png) [@jane.hwang](https://discuss.elastic.co/u/jane.hwang)\
**Post date:** [January 3, 2023, 11:30pm UTC](https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101/3 "2023-01-03T23:30:59Z")

</div>

Hi,@jsanz

Thanks, just wanted to check if it is possible to enable anonymous access.

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2023, 11:31pm UTC](https://discuss.elastic.co/t/enabling-anonymous-access-filerealm-in-kibana/321101/4 "2023-01-31T23:31:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
