# Kibana is not able to authenticate elastic search in my k8s deployment

**URL:** <https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708>\
**Category:** Kibana\
**Tags:** docker, kibana-plugin-development\
**Created:** [March 28, 2023, 11:16am UTC](https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708 "2023-03-28T11:16:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tauqeerahmad104](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@tauqeerahmad104](https://discuss.elastic.co/u/tauqeerahmad104)\
**Post date:** [March 28, 2023, 11:16am UTC](https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708/1 "2023-03-28T11:16:25Z")

</div>

I have to deploy Elasticsearch and kibana on my k8s cluster. The pods were running successfully and worked fine. Then I try adding a username and password for kibana and Elasticsearch. Now Elasticsearch is running smoothly and I can access the API with a username and password. However, the kubana is not able to authenticate the Elasticsearch server. I see `Preformatted text`this error.  
`["warning","process"],"pid":7,"message":"Error [ProductNotSupportedSecurityError]: The client is unable to verify that the server is Elasticsearch due to security privileges on the server side. Some functionality may not be compatible if the server is running an unsupported product.\n`

My codes are as follows. For elasticsearch-stateful.yaml

```auto
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: es-cluster
#namespace: logging
spec:
  serviceName: elasticsearch
  replicas: 3
  selector:
    matchLabels:
      app: elasticsearch
  template:
    metadata:
      labels:
        app: elasticsearch
    spec:
      containers:
      - name: elasticsearch
        image: docker.elastic.co/elasticsearch/elasticsearch:7.16.1
        resources:
            limits:
              cpu: 1000m
            requests:
              cpu: 100m
        ports:
        - containerPort: 9200
          name: rest
          protocol: TCP
        - containerPort: 9300
          name: inter-node
          protocol: TCP
        volumeMounts:
        - name: data
          mountPath: /usr/share/elasticsearch/data
        env:
          - name: cluster.name
            value: k8s-logs
          - name: node.name
            valueFrom:
              fieldRef:
                fieldPath: metadata.name
          - name: discovery.seed_hosts
            value: "es-cluster-0.elasticsearch,es-cluster-1.elasticsearch,es-cluster-2.elasticsearch"
          - name: cluster.initial_master_nodes
            value: "es-cluster-0,es-cluster-1,es-cluster-2"
          - name: ES_JAVA_OPTS
            value: "-Xms512m -Xmx512m"
          - name: ELASTIC_USERNAME
            valueFrom:
              secretKeyRef:
                name: elasticsearch-credentials
                key: username
          - name: ELASTIC_PASSWORD
            valueFrom:
              secretKeyRef:
                name: elasticsearch-credentials
                key: password
          - name: xpack.security.enabled
            value: "true"
      initContainers:
      - name: fix-permissions
        image: busybox
        command: ["sh", "-c", "chown -R 1000:1000 /usr/share/elasticsearch/data"]
        securityContext:
          privileged: true
        volumeMounts:
        - name: data
          mountPath: /usr/share/elasticsearch/data
      - name: increase-vm-max-map
        image: busybox
        command: ["sysctl", "-w", "vm.max_map_count=262144"]
        securityContext:
          privileged: true
      - name: increase-fd-ulimit
        image: busybox
        command: ["sh", "-c", "ulimit -n 65536"]
        securityContext:
          privileged: true
  volumeClaimTemplates:
  - metadata:
      name: data
      labels:
        app: elasticsearch
    spec:
      accessModes: ["ReadWriteOnce"]
      storageClassName: "openebs-hostpath"
      resources:
        requests:
          storage: 3Gi

```

My kibana file is as follow

```auto
apiVersion: apps/v1
kind: Deployment
#namespace: logging
metadata:
  name: kibana
  labels:
    app: kibana
spec:
  replicas: 1
  selector:
    matchLabels:
      app: kibana
  template:
    metadata:
      labels:
        app: kibana
    spec:
      containers:
      - name: kibana
        image: docker.elastic.co/kibana/kibana:7.16.1
        resources:
          limits:
            cpu: 1000m
          requests:
            cpu: 100m
        env:
          - name: ELASTICSEARCH_URL
            value: http://elastic:admin@elasticsearch:9200
          - name: ELASTIC_USERNAME
            value: elastic
          - name: ELASTIC_PASSWORD
            value: admin
          #- name: ELASTICSEARCH_SSL_VERIFICATIONMODE
            #value: none
          #- name: ELASTIC_USERNAME
            #valueFrom:
              #secretKeyRef:
                #name: elasticsearch-credentials
                #key: username
          #- name: ELASTIC_PASSWORD
            #valueFrom:
              #secretKeyRef:
                #name: elasticsearch-credentials
                #key: password
          - name: xpack.security.enabled
            value: "true"
        ports:
        - containerPort: 5601

```

When I exec into the Kibana pod and curl the Elastic service with username and password I can see the API.  
I am not sure why it sees this error. can you please help me out? Regards,  
Tauqeer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2023, 11:17am UTC](https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708/2 "2023-04-25T11:17:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
