# How to access Kibana with x-pack security disabled?

**URL:** <https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [June 28, 2022, 10:54am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347 "2022-06-28T10:54:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dendog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dendog/32/101382_2.png) [@dendog](https://discuss.elastic.co/u/dendog)\
**Post date:** [June 28, 2022, 10:54am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/1 "2022-06-28T10:54:55Z")

</div>

Hi!

I starting es and kibana in a docker compose file, I have set `xpack.security.enabled=false`, but when accessing the kibana UI I am still asked for an enrollment token, which from my understanding would not be generated when switching off security.

Is there a setting I need to pass to kibana to avoid needing any security?

This is all for local development only, and I am using version 8.2.3

Thanks!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 28, 2022, 11:07am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/2 "2022-06-28T11:07:17Z")

</div>

It should be _pretty_ easy to work with security enabled, as everything would work out of the box with minimal effort. [Install Elasticsearch with Docker | Elasticsearch Guide [8.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker) will get you all the way there and this way you are already ready to take this to production when ready or not worry if your instance gets exposed to the internet ! All that with the only additional effort of logging in to Kibana once in a while 🙂

If you _really_ want to disable security, you need to share your docker compose file so that we can make suggestions as to what is wrong and what can be fixed.

---

<div class="post-metadata">

**Author:** ![dendog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dendog/32/101382_2.png) [@dendog](https://discuss.elastic.co/u/dendog)\
**Post date:** [June 28, 2022, 12:44pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/3 "2022-06-28T12:44:24Z")

</div>

Hey thanks for the reply, I am using docker compose and the guide for using compose is quite involved - requires storing certs etc.

For production I will be using elastic cloud, so seems overkill to set up security for local dev.

Here is my compose file:

```auto
version: "3.9"

services:
  app:
    build: .
    working_dir: /code/app
    command: uvicorn main:app --host 0.0.0.0 --reload
    environment:
      DEBUG: 1
    volumes:
      - ./app:/code/app
    ports:
      - 8000:8000
    restart: on-failure
    networks:
      - elastic

  elastic:
    image: elasticsearch:8.2.3
    container_name: elastic
    environment:
      - discovery.type=single-node
      - ES_JAVA_OPTS=-Xms1g -Xmx1g
      - xpack.security.enabled=false
    volumes:
      - es_data:/usr/share/elasticsearch/data
    ports:
      - 127.0.0.1:9200:9200
    networks:
      - elastic

  kibana:
    image: kibana:8.2.3
    environment:
      - xpack.security.enabled=false
    ports:
      - target: 5601
        published: 5601
    depends_on:
      - elasticsearch
    networks:
      - elastic      

volumes:
  es_data:
    driver: local

networks:
  elastic:
    name: elastic
    driver: bridge

```

Thanks!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 28, 2022, 1:52pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/4 "2022-06-28T13:52:28Z")

</div>

Kibana environment variables need to be in capital letters ( [Install Kibana with Docker | Kibana Guide [8.2] | Elastic](https://www.elastic.co/guide/en/kibana/current/docker.html#environment-variable-config) )

```auto
environment:
      - XPACK_SECURITY_ENABLED=false

```

---

<div class="post-metadata">

**Author:** ![dendog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dendog/32/101382_2.png) [@dendog](https://discuss.elastic.co/u/dendog)\
**Post date:** [June 30, 2022, 10:05am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/5 "2022-06-30T10:05:31Z")

</div>

Thanks! But setting this still asks for an enrollment token when accessing Kibana:

```auto
  kibana:
    image: kibana:8.2.3
    environment:
      - XPACK_SECURITY_ENABLED=false
    ports:
      - target: 5601
        published: 5601
    depends_on:
      - elastic
    networks:
      - elastic  

```

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [June 30, 2022, 10:10am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/6 "2022-06-30T10:10:48Z")

</div>

See this reply [Kibana asking for Enrollment Token when xpack.security.enabled: false in Elasticsearch - #2 by ikakavas](https://discuss.elastic.co/t/kibana-asking-for-enrollment-token-when-xpack-security-enabled-false-in-elasticsearch/302118/2)

---

<div class="post-metadata">

**Author:** ![dendog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dendog/32/101382_2.png) [@dendog](https://discuss.elastic.co/u/dendog)\
**Post date:** [June 30, 2022, 10:32am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/7 "2022-06-30T10:32:02Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2022, 10:32am UTC](https://discuss.elastic.co/t/how-to-access-kibana-with-x-pack-security-disabled/308347/8 "2022-07-28T10:32:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
