# Expose API to loopback address in a cluster

**URL:** <https://discuss.elastic.co/t/expose-api-to-loopback-address-in-a-cluster/186364>\
**Category:** Elasticsearch\
**Created:** [June 19, 2019, 2:58am UTC](https://discuss.elastic.co/t/expose-api-to-loopback-address-in-a-cluster/186364 "2019-06-19T02:58:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rossbrigoli](https://avatars.discourse-cdn.com/v4/letter/r/ebca7d/32.png) [@rossbrigoli](https://discuss.elastic.co/u/rossbrigoli)\
**Post date:** [June 19, 2019, 2:58am UTC](https://discuss.elastic.co/t/expose-api-to-loopback-address-in-a-cluster/186364/1 "2019-06-19T02:58:39Z")

</div>

Hello,

Has this been solved?

> [@Network.publish\_host does not seem to do what it says it does](https://discuss.elastic.co/t/network-publish-host-does-not-seem-to-do-what-it-says-it-does/17055):
>
> I'm trying to bind the API to 127.0.0.1 and use the apache reverse proxy settings with kibana to talk to ES. This works as I expected. However, I need to bind the inter-cluster communication to a real IP address, supposedly with network.publish\_host, but this does not work. Both bind to 127.0.0.1 Running from the latest deb package, on ubuntu 12.04 from /etc/elasticsearch/elasticsearch.yaml network.bind\_host: 127.0.0.1 network.publish\_host: my.redacted.ip.address netstat -an | grep 93…

I wanted to implement the same thing but it doesn't seem to work. I wanted to expose the API to localhost only, but i want to the use the real IP for clustering/discovery. The reason is that we do not have remote API calls, all ES API calls always originate from the same server. We do not want to expose the API outside of the server for security reasons.

I configured the nodes like:

network.publish\_host: \<\>  
network.bind\_host: localhost

The problem is they all bind to localhost resulting in nodes not being able to see each other.

Best Regards,  
Ross

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 24, 2019, 12:53am UTC](https://discuss.elastic.co/t/expose-api-to-loopback-address-in-a-cluster/186364/2 "2019-06-24T00:53:03Z")

</div>

You seem to be misunderstanding what these settings do.

The `bind_host` is where we bind and the `publish` host is what address we tell people we're bound to. That is, if you asked a node "what is your address", then it will tell you the `publish_host`, even if it didn't actually bind to that interface.

That means, for example, you can bind to an IP address, but publish it as a DNS name. Or you can bind to all interfaces, but explicitly state which address should be used when publishing.

> [@rossbrigoli](#):
>
> The problem is they all bind to localhost resulting in nodes not being able to see each other.

Which, per the explanation above is exactly what should happen.

What you're after is to have a different bind (and publish) address for the `http` port, versus the `transport` port.

For that, you want to set `http.host` (or `http.bind_host` and `http.publish_host`)

> **[HTTP | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-http.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2019, 1:07am UTC](https://discuss.elastic.co/t/expose-api-to-loopback-address-in-a-cluster/186364/3 "2019-07-22T01:07:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
