# Enterprise Search (App Search) - doesn't expose with custom 443 port in Kubernetes

**URL:** <https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [May 19, 2021, 7:35pm UTC](https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441 "2021-05-19T19:35:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![111476](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111476/32/88982_2.png) [@111476](https://discuss.elastic.co/u/111476)\
**Post date:** [May 19, 2021, 7:35pm UTC](https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441/1 "2021-05-19T19:35:00Z")

</div>

Hi guys! Spent 2 days digging and trying to debug things, but now I'm stuck.

I deployed Kibana, ES, and App Search (Enterprise Search) to my Kubernetes cluster via this [guide](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-deploy-eck.html)

Everything works great within the cluster with default configs.

Making a step further I exposed my **Kibana** to the world using Ingress and DNS:

- Kibana **Pod** (port 5601) -\> Kibana **Service** (5601:5601) -\> **Ingress** ([https://kibana.MYSITE.com](https://kibana.MYSITE.com) on default 80 or 443)  
And it works **GREAT**.

Next thing I want to do is expose my **App Search (Enterprise Search)** the same way.  
So I changed the config to serve App Search on port **443**.

```auto
    cat <<EOF | kubectl apply -f -
    apiVersion: enterprisesearch.k8s.elastic.co/v1
    kind: EnterpriseSearch
    metadata:
      name: enterprise-search-quickstart
    spec:
      version: 7.12.1
      count: 1
      elasticsearchRef:
        name: quickstart
      config:
        ent_search.listen_port: 443
        ent_search.external_url: https://appsearch.MYSITE.com:443
        ent_search.ssl.redirect_http_from_port: 80
    EOF

```

...but for some reason this setup doesn't work.  
As I can see, **Service** which is created is still serving on port 3002 (default port of App Search).  
From the Pod logs I can see that the server starts.  
I also tried adding `ent_search.ssl.enabled: false` config, but still no luck.

Feeling kinda desperate trying to make this thing work 😥  
What I'm trying to reach is that App Search (Enterprise Search) is both available inside the cluster via cluster.local DNS **and** via Ingress+DNS to external clients.  
Please, help

---

<div class="post-metadata">

**Author:** ![111476](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111476/32/88982_2.png) [@111476](https://discuss.elastic.co/u/111476)\
**Post date:** [May 21, 2021, 2:12pm UTC](https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441/2 "2021-05-21T14:12:41Z")

</div>

Found the solution for **dev** now:

```auto
cat <<EOF | kubectl apply -f -
apiVersion: enterprisesearch.k8s.elastic.co/v1
kind: EnterpriseSearch
metadata:
  name: enterprise-search-quickstart
spec:
  version: 7.12.1
  count: 1
  elasticsearchRef:
    name: quickstart
  http:
    tls:
      selfSignedCertificate:
        disabled: true       
  config:
    ent_search.external_url: https://appsearch.MYSITE.com
    ent_search.ssl.redirect_http_from_port: 80
EOF

```

So probably the solution for **production** is in the realm of having your own SSL certificate in config. 🤔

---

<div class="post-metadata">

**Author:** ![ross.bell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ross.bell/32/77559_2.png) [@ross.bell](https://discuss.elastic.co/u/ross.bell)\
**Post date:** [May 24, 2021, 6:32pm UTC](https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441/3 "2021-05-24T18:32:18Z")

</div>

Hey @111476,

Just wanted to confirm you've seen this documentation for configuring SSL/TLS in Enterprise Search (not specific to K8s): [Configure SSL/TLS | Elastic Enterprise Search Documentation [master] | Elastic](https://www.elastic.co/guide/en/enterprise-search/master/configure-ssl-tls.html).

Ross

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2021, 6:32pm UTC](https://discuss.elastic.co/t/enterprise-search-app-search-doesnt-expose-with-custom-443-port-in-kubernetes/273441/4 "2021-06-21T18:32:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
