# Exposing Kibana behind GKE ingress (UNHEALTHY state)

**URL:** <https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [March 18, 2021, 2:44pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684 "2021-03-18T14:44:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lmes3oud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmes3oud/32/85735_2.png) [@lmes3oud](https://discuss.elastic.co/u/lmes3oud)\
**Post date:** [March 18, 2021, 2:44pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/1 "2021-03-18T14:44:09Z")

</div>

Hi everyone, I'm trying to expose `Kibana` behind of a `GCE ingress`, but the ingress reporting the kibana service as` UNHEALTHY` while it is healthy and ready. Just note that the healthcheck created by the Ingress is still using the default value `HTTP` on `/` using the `nodeport`. Changing the value in GCP console to `HTTPS` on `/login` and `Port: 5601` doesn't change anything and the service still reported Unhealthy.  
I'm using `ECK 1.3.1` and below are my configs. I'm I missing anything? Thank you in advance.

```
apiVersion: elasticsearch.k8s.elastic.co/v1beta1
kind: Elasticsearch
metadata:
  name: d3m0
spec:
  version: 7.10.1
  nodeSets:
  - name: default
    count: 1
    config:
      node.store.allow_mmap: false
---
apiVersion: kibana.k8s.elastic.co/v1beta1
kind: Kibana
metadata:
  name: d3m0
spec:
  version: 7.10.1
  count: 1
  elasticsearchRef:
    name: d3m0
  podTemplate:
    metadata:
      labels:
        kibana: node
    spec:
      containers:
      - name: kibana
        resources:
          limits:
            memory: 1Gi
            cpu: 1
        readinessProbe:
          httpGet:
            scheme: HTTPS
            path: "/login"
            port: 5601
  http:
    service:
      spec:
        type: NodePort

---
apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
  name: kibana-ingress
    spec:
      backend:
          serviceName: d3m0-kb-http
          servicePort: 5601
```

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [March 18, 2021, 3:13pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/2 "2021-03-18T15:13:31Z")

</div>

You probably need to enable TLS between GCLB and Kibana by adding the `service.alpha.kubernetes.io/app-protocols` annotation to the pod. There is an example of this at:

> **[elastic/cloud-on-k8s](https://github.com/elastic/cloud-on-k8s/tree/master/config/recipes/gclb)**
>
> master/config/recipes/gclb

---

<div class="post-metadata">

**Author:** ![lmes3oud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmes3oud/32/85735_2.png) [@lmes3oud](https://discuss.elastic.co/u/lmes3oud)\
**Post date:** [March 18, 2021, 4:22pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/3 "2021-03-18T16:22:19Z")

</div>

Hi @charith-elastic, thank you for the quick reply. Straight to the point 👍 !  
That annotation was missing In kibana service definition.

Can you please point any tutorial or example on how to expose kibana service using a subpath in the Ingress. I'm currently having 404 error. Thank you in advance.

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [March 22, 2021, 3:19pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/4 "2021-03-22T15:19:45Z")

</div>

I couldn't find a tutorial so I tried it out myself.

Say you want to expose Kibana under the subpath `/kibana`. You first need to configure Kibana to be aware of this by setting `server.basePath`, `server.rewriteBasePath` and `server.publicBaseUrl`. Then you need to update the readiness probe so that it uses the new path to `/login`.

```auto
---
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: hulk
  labels:
    app: hulk
spec:
  version: 7.11.2
  count: 1
  config:
    server:
      basePath: "/kibana"
      rewriteBasePath: true
      publicBaseUrl: "https://elastic.stack/kibana"
  http:
    service:
      metadata:
        labels:
          app: hulk
        annotations:
          # Enable TLS between GCLB and the application
          cloud.google.com/app-protocols: '{"https":"HTTPS"}'
          service.alpha.kubernetes.io/app-protocols: '{"https":"HTTPS"}'
          # Comment out the following line if you are not using a VPC-native cluster
          cloud.google.com/neg: '{"ingress": true}'
  elasticsearchRef:
    name: hulk
  podTemplate:
    spec:
      containers:
        - name: kibana
          readinessProbe:
            # Override the readiness probe as GCLB reuses it for its own healthchecks
            httpGet:
              scheme: HTTPS
              path: "/kibana/login"
              port: 5601

```

```auto
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: hulk
  labels:
    app: hulk
  annotations:
    # Issue certificates for TLS hosts automatically
    cert-manager.io/cluster-issuer: "selfsigning-issuer"
    # Disable HTTP traffic
    kubernetes.io/ingress.allow-http: "false"
spec:
  tls:
    - hosts: ["elastic.stack"]
      secretName: hulk-kibana-cert
  rules:
    - host: "elastic.stack"
      http:
        paths:
          - path: "/kibana/*"
            pathType: Exact
            backend:
              service:
                name: hulk-kb-http
                port:
                  name: https

```

---

<div class="post-metadata">

**Author:** ![lmes3oud](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmes3oud/32/85735_2.png) [@lmes3oud](https://discuss.elastic.co/u/lmes3oud)\
**Post date:** [March 22, 2021, 3:49pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/5 "2021-03-22T15:49:22Z")

</div>

Hi @charith-elastic, thank you very much, this is really helpful.  
I will create a [topic](https://discuss.elastic.co/t/expose-kibana-behind-a-subpath-using-gce-ingress/267987) about it and accept the solutions for more visibility.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 3:50pm UTC](https://discuss.elastic.co/t/exposing-kibana-behind-gke-ingress-unhealthy-state/267684/6 "2021-04-19T15:50:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
