# Kibana not accessible via Kubernetes Ingress

**URL:** <https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162>\
**Category:** Kibana\
**Created:** [December 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162 "2023-12-12T14:49:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![patrick-94](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick-94/32/129787_2.png) [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Post date:** [December 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/1 "2023-12-12T14:49:01Z")

</div>

Hey,  
i have the following Problem which I copy and paste it from Github, anyone here who can help me out with this?

This is the Original Post to Github: [Kibana not accessible via Ingress · Issue #172630 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/172630#issuecomment-1851883490)

**Kibana version:**  
Kibana-8.10.4 (Bitnami Helm Chart)

**Elasticsearch version:**  
Elastisearch 8.11.1 (Bitnami Helm Chart)

**Server OS version:**  
Debian-12.2 Bookworm / Kubernetes-1.27.7

**Browser version:**  
Safari-17.1.2 / Chrome-119.0.6045.199

**Browser OS version:**

MacOS Sonoma 14.1.2

**Original install method (e.g. download page, yum, from source, etc.):**

Helm Chart (Bitnami)

> <https://github.com/bitnami/charts/tree/main/bitnami/kibana>
>
> //github.com/bitnami/charts/tree/main/bitnami/kibana

> <https://github.com/bitnami/charts/tree/main/bitnami/elasticsearch>
>
> //github.com/bitnami/charts/tree/main/bitnami/elasticsearch

**Describe the bug:**

When I try to login to Kibana and I enter my credentials and click on login it loads and send me Back to the login screen (Loop), when I open UP the Developer Tools inside my Browser I get the following error:

```console
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-P5polb1UreUSOe5V/Pv7tc+yeZuJXiOi/3fqhGsU7BE='), or a nonce ('nonce-...') is required to enable inline execution.

```

**Steps to reproduce:**

1. helm install --namespace elasticsearch elasticsearch bitnami/kibana -f values.yaml
2. I use the following Values.yaml file for my Deployment:

```yaml
kibana:
  replicaCount: 3
  extraConfiguration:
    "server.publicBaseUrl": "https://kibana-dashboard.domain.tld"
    "xpack.security.sameSiteCookies": None
    "telemetry.allowChangingOptInStatus": false
    "telemetry.optIn": false
  persistence:
    enabled: true
    storageClass: "rook-cephfs"
    accessModes:
      - ReadWriteMany
    size: 10Gi
  ingress:
    enabled: true
    hostname: kibana-dashboard.domain.tld
    annotations:
      cert-manager.io/cluster-issuer: default-clusterissuer
      cert-manager.io/private-key-algorithm: "RSA"
      cert-manager.io/private-key-size: "4096"
      kubernetes.io/tls-acme: "true"
      nginx.ingress.kubernetes.io/proxy-ssl-verify: "false"
      nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    tls: true
    selfSigned: false
    ingressClassName: "nginx"
  containerSecurityContext:
    enabled: true
    runAsUser: 1001
    runAsNonRoot: true
    privileged: false
    readOnlyRootFilesystem: false
    allowPrivilegeEscalation: false
    capabilities:
      drop: ["ALL"]
    seccompProfile:
      type: "RuntimeDefault"
  metrics:
    enabled: true
    containerSecurityContext:
      enabled: true
      runAsUser: 1001
      runAsNonRoot: true
      privileged: false
      readOnlyRootFilesystem: false
      allowPrivilegeEscalation: false
      capabilities:
        drop: ["ALL"]
      seccompProfile:
        type: "RuntimeDefault"
    serviceMonitor:
      enabled: false
  tls:
    enabled: true
    autoGenerated: true
  elasticsearch:
    hosts:
      - '{{ include "elasticsearch.service.name" . }}'
    port: '{{ include "elasticsearch.service.ports.restAPI" . }}'
    security:
      auth:
        enabled: true
        kibanaPassword: "PASSWORD"
        createSystemUser: true
        elasticsearchPasswordSecret: "elasticsearch"
      tls:
        enabled: true
        existingSecret: "elasticsearch-coordinating-crt"
        usePemCerts: true
```

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 27, 2023, 10:55pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/2 "2023-12-27T22:55:10Z")

</div>

I have a feeling this is due to the fact that you have the `sameSiteCookies` set to None, which requires xpack.security.secureCookies to be set to True. (default is false)

> **[Security settings in Kibana | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html#security-session-and-cookie-settings)**

---

<div class="post-metadata">

**Author:** ![patrick-94](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick-94/32/129787_2.png) [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Post date:** [December 28, 2023, 6:26am UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/3 "2023-12-28T06:26:15Z")

</div>

Thank‘s, i will try it out!

---

<div class="post-metadata">

**Author:** ![patrick-94](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick-94/32/129787_2.png) [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Post date:** [January 2, 2024, 10:15am UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/4 "2024-01-02T10:15:44Z")

</div>

Same error with the following settings:

```yaml
kibana:
  replicaCount: 3
  extraConfiguration:
    "server.publicBaseUrl": "https://kibana.platform-staging.domain.net"
    "xpack.security.sameSiteCookies": None
    "xpack.security.secureCookies": true
    "telemetry.allowChangingOptInStatus": false
    "telemetry.optIn": false

```

---

<div class="post-metadata">

**Author:** ![patrick-94](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick-94/32/129787_2.png) [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Post date:** [January 2, 2024, 3:18pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/5 "2024-01-02T15:18:04Z")

</div>

This are the errors inside the Webdeveloper Console.

 ![Bildschirmfoto 2024-01-02 um 16.17.09](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f47a8ccd84ba6486f9b2b55382c3164f13aced4b.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2024, 3:19pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162/6 "2024-01-30T15:19:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
