# Expose Kibana behind a subpath using GCE ingress

**URL:** <https://discuss.elastic.co/t/expose-kibana-behind-a-subpath-using-gce-ingress/267987>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [March 22, 2021, 3:55pm UTC](https://discuss.elastic.co/t/expose-kibana-behind-a-subpath-using-gce-ingress/267987 "2021-03-22T15:55:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![lmes3oud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmes3oud/32/85735_2.png) [@lmes3oud](https://discuss.elastic.co/u/lmes3oud)\
**Post date:** [March 22, 2021, 3:55pm UTC](https://discuss.elastic.co/t/expose-kibana-behind-a-subpath-using-gce-ingress/267987/1 "2021-03-22T15:55:40Z")

</div>

Trying to expose kibana behind GCE Ingress under a subpath. Say you want to expose Kibana under the subpath `/kibana` . You first need to configure Kibana to be aware of this by setting `server.basePath` , `server.rewriteBasePath` and `server.publicBaseUrl` . Then you need to update the readiness probe so that it uses the new path to `/login` . Below is a working code. Much thanks to @[charith-elastic](https://discuss.elastic.co/u/charith-elastic)

```auto
---
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: hulk
  labels:
    app: hulk
spec:
  version: 7.11.2
  count: 1
  config:
    server:
      basePath: "/kibana"
      rewriteBasePath: true
      publicBaseUrl: "https://elastic.stack/kibana"
  http:
    service:
      metadata:
        labels:
          app: hulk
        annotations:
          # Enable TLS between GCLB and the application
          cloud.google.com/app-protocols: '{"https":"HTTPS"}'
          service.alpha.kubernetes.io/app-protocols: '{"https":"HTTPS"}'
          # Comment out the following line if you are not using a VPC-native cluster
          cloud.google.com/neg: '{"ingress": true}'
  elasticsearchRef:
    name: hulk
  podTemplate:
    spec:
      containers:
        - name: kibana
          readinessProbe:
            # Override the readiness probe as GCLB reuses it for its own healthchecks
            httpGet:
              scheme: HTTPS
              path: "/kibana/login"
              port: 5601

```

```auto
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: hulk
  labels:
    app: hulk
  annotations:
    # Issue certificates for TLS hosts automatically
    cert-manager.io/cluster-issuer: "selfsigning-issuer"
    # Disable HTTP traffic
    kubernetes.io/ingress.allow-http: "false"
spec:
  tls:
    - hosts: ["elastic.stack"]
      secretName: hulk-kibana-cert
  rules:
    - host: "elastic.stack"
      http:
        paths:
          - path: "/kibana/*"
            pathType: Exact
            backend:
              service:
                name: hulk-kb-http
                port:
                  name: https

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 3:56pm UTC](https://discuss.elastic.co/t/expose-kibana-behind-a-subpath-using-gce-ingress/267987/2 "2021-04-19T15:56:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
