# Kibana Endpoint not Passing through Haproxy Using Shortened URL

**URL:** <https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [January 2, 2020, 3:59pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597 "2020-01-02T15:59:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![balogan](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@balogan](https://discuss.elastic.co/u/balogan)\
**Post date:** [January 2, 2020, 3:59pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/1 "2020-01-02T15:59:04Z")

</div>

ECE 2.4.3  
Haproxy 1.8  
Kibana/Elasticsearch 7.5.4

I can get to Kibana using the endpoint prepended to the domain name like this:  
[https://708](https://708)....vcp-ecelab-log.mon.vzwops.com

But we want a more user friendly url like this:  
[https://vcp-ecelab-log.mon.vzwops.com/kibana](https://vcp-ecelab-log.mon.vzwops.com/kibana)

Here's the result:  
{"ok":false,"message":"Unknown deployment."}

Haproxy setup:  
Frontend:  
use\_backend be\_ecelab\_log if { hdr(host) -i [vcp-ecelab-log.mon.vzwops.com](http://vcp-ecelab-log.mon.vzwops.com) } { path\_beg -i /kibana } or { path\_beg -i /kibana/ }

Backend:  
backend be\_ecelab\_log  
mode http  
balance source

server ecelab-log-1 708.....eceproxylab-1-southlake.mon.vzwops.com:9200 check verify none  
server ecelab-log-2 708.....eceproxylab-2-southlake.mon.vzwops.com:9200 check verify none  
server ecelab-log-3 708.....eceproxylab-3-southlake.mon.vzwops.com:9200 check verify none

I've tried different combinations of the following on the frontend with no luck:  
#acl ece\_kibana path\_beg -i /kibana  
#redirect location 708.....eceproxylab-1-southlake.mon.vzwops.com append-slash code 301 if ece\_kibana  
#acl ece\_kibana { hdr(host) -i [vcp-ecelab-log.mon.vzwops.com](http://vcp-ecelab-log.mon.vzwops.com) } { path\_beg -i /kibana } or { path\_beg -i /kibana/ }  
#http-request set-var(req.kibana\_endpoint) req.hdr(host),lower,regsub(.vcp-ecelab-log.mon.vzwops.com$,) if { hdr(host) -i [vcp-ecelab-log.mon.vzwops.com](http://vcp-ecelab-log.mon.vzwops.com) } { path\_beg -i /kibana }  
#http-request set-path /%[var(req.rewrite\_kibendpoint)]%[path] if { var(req.rewrite\_kibendpoint) -m found }  
#http-request set-header Host [vcp-ecelab-log.mon.vzwops.com](http://vcp-ecelab-log.mon.vzwops.com) if { var(req.rewrite\_kibendpoint) -m found }  
#http-request redirect location 708.....eceproxylab-1-southlake.mon.vzwops.com if ece\_kibana  
#http-request redirect code 301 location http://%[url,regsub(^/,/708....,)].%[hdr(host)] if ece\_kibana  
#use\_backend be\_ecelab\_log ece\_kibana  
#redirect prefix 708.....eceproxylab-1-southlake.mon.vzwops.com code 301 if { hdr(host) -i [vcp-ecelab-log.mon.vzwops.com](http://vcp-ecelab-log.mon.vzwops.com) }

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 2, 2020, 6:38pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/2 "2020-01-02T18:38:42Z")

</div>

Hi @balogan

We're working on built-in support for "vanity URLs" aka "cluster aliases" aka "user friendly URLs" at the moment (no ETA though), in the meantime, you should get `haproxy` to inject the header `X-Found-Cluster: 708...4e` (full id, not the rest of the URL, I shortened for security)

eg

```auto
http-request add-header X-Found-Cluster “708...4e”

```

---

<div class="post-metadata">

**Author:** ![balogan](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@balogan](https://discuss.elastic.co/u/balogan)\
**Post date:** [January 2, 2020, 7:29pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/3 "2020-01-02T19:29:49Z")

</div>

> [@Alex\_Piggott](#):
>
> http-request add-header X-Found-Cluster “708...4e”

Thanks for the quick response.

I made the change and can access through curl on the load balancers, but I'm getting a 503 with a web browser.

\< HTTP/1.1 302 Found  
\< Cache-Control: no-cache  
\< Content-Length: 0  
\< Date: Thu, 02 Jan 2020 19:23:50 GMT  
\< Kbn-Name: kibana  
\< Kbn-Xpack-Sig: dc7415cd93ad168f271f0f17ac21d92e  
\< Location: /login?next=%2Fkibana  
\< X-Cloud-Request-Id: dc4b53ee-80b2-4d35-8397-44dc50bc2740  
\< X-Found-Handling-Cluster: 708b4ffd5e6f4e8a923f02f0a1f4894e  
\< X-Found-Handling-Instance: instance-0000000005  
\< X-Found-Handling-Server: 10.56.56.29  
\<

- Connection #0 to host [vcp-analytics-ecelab.mon.vzwops.com](http://vcp-analytics-ecelab.mon.vzwops.com) left intact

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5e9c043ef1e1c268c12e8209b7f635c76b6654d.png)

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 2, 2020, 9:57pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/4 "2020-01-02T21:57:51Z")

</div>

My _guess_ would be that one of the rules in your haproxy is misfiring

Can you get haproxy to log what it's doing exactly (and specifically what it is converting the "input" URL to?)

Or probably if you look in one of the log files in `/mnt/data/:id/services/proxy/logs/` it will give some more info

(If you go to the network debugger for the browser and "copy as curl", and then try that curl, I would guess you'll reproduce the error)

---

<div class="post-metadata">

**Author:** ![balogan](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@balogan](https://discuss.elastic.co/u/balogan)\
**Post date:** [January 3, 2020, 3:29pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/5 "2020-01-03T15:29:42Z")

</div>

I got it to work by removing /kibana from the haproxy rules. I could see the initial get going through in the browser network debugger, but the login response is where it failed.

We'll see if my manager is happy removing /kibana. He's on PTO today.

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [January 6, 2020, 7:26pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/6 "2020-01-06T19:26:51Z")

</div>

HAProxy is good and all but below is how i do it with nginx.

```
upstream ece_proxies {
        zone ece_proxies 64K;
        server 10.1.1.100:9243;
        server 10.1.1.101:9243;
        server 10.1.1.102:9243;
}
#Testing Instance
    server {
            listen 9200 ssl;
            listen 443 ssl; # 'ssl' parameter tells NGINX to decrypt the traffic
            server_name myhouse-es.domain.net;
            ssl_certificate /etc/letsencrypt/live/domain.net/fullchain.pem; # The certificate file
            ssl_certificate_key /etc/letsencrypt/live/domain.net/privkey.pem; # The private key file

        location / {
                proxy_pass https://ece_proxies;
                proxy_http_version 1.1;
                proxy_set_header Host e71625acb09b4befbb40bf03cb3e0d86.domain.net;
                proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
                proxy_set_header Connection "";
        }
}

```

The above terminated a Lets Encrypted wildcard cert and hands the connections off to the ECE proxies correctly and without and issues.

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 6, 2020, 7:40pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/7 "2020-01-06T19:40:43Z")

</div>

(Setting `Host` with the full cluster id as a prefix is the alternative to setting `X-Found-Cluster`, which to use is just a matter of preference)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2020, 7:40pm UTC](https://discuss.elastic.co/t/kibana-endpoint-not-passing-through-haproxy-using-shortened-url/213597/8 "2020-01-20T19:40:57Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
