# Kibana with nginx ingress on minikube

**URL:** <https://discuss.elastic.co/t/kibana-with-nginx-ingress-on-minikube/160303>\
**Category:** Kibana\
**Created:** [December 11, 2018, 6:54am UTC](https://discuss.elastic.co/t/kibana-with-nginx-ingress-on-minikube/160303 "2018-12-11T06:54:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sud7](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@sud7](https://discuss.elastic.co/u/sud7)\
**Post date:** [December 11, 2018, 6:54am UTC](https://discuss.elastic.co/t/kibana-with-nginx-ingress-on-minikube/160303/1 "2018-12-11T06:54:07Z")

</div>

Hi, I am trying to test my ELK stack configuration on minikube, Kibana is "exposed" using a ngnix ingress (http only). My ELK stack version is 6.2.4 with searchguard.

I went through various posts here as well as on stackoverflow and i think i have the config right but i am stuck on "login page loop", i.e even after logging in, the page redirects to login page.

**kibana.yml**

```
server.port: 5601
server.host: "0.0.0.0"
server.basePath: "/logs"
server.name: "kibana"
elasticsearch.url: '${ELASTICSEARCH_URL}'
elasticsearch.username: "kibana"
elasticsearch.password: "password"

```

**ingress config**

```
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: kibana-http-ingress
  namespace: backstage
  labels:
    app: kibana
    chart: kibana-6.2.4
    release: kibana
    heritage: Tiller
  annotations:
    kubernetes.io/ingress.class: "nginx"
    nginx.ingress.kubernetes.io/rewrite-target: /
    nginx.ingress.kubernetes.io/configuration-snippet: |
       rewrite ^/logs/(.*)$ /$1 break;
spec:
  rules:
  - host: my-local-devops.com
    http:
      paths:
      - path: /logs
        backend:
          serviceName: kibana
          servicePort: 5601

```

**nginx.conf in the controller (autogenerated)**

```
location ~* ^/logs\/?(?<baseuri>.*) {
			
			set $namespace "backstage";
			set $ingress_name "kibana-http-ingress";
			set $service_name "kibana";
			set $service_port "5601";
			set $location_path "/logs";
			
			rewrite_by_lua_block {
				
				balancer.rewrite()
				
			}
			
			log_by_lua_block {
				
				balancer.log()
				
				monitor.call()
			}
			
			port_in_redirect off;
			
			set $proxy_upstream_name "backstage-kibana-5601";
			
			client_max_body_size "1m";
			
			proxy_set_header Host $best_http_host;
			
			# Pass the extracted client certificate to the backend
			
			# Allow websocket connections
			proxy_set_header Upgrade $http_upgrade;
			
			proxy_set_header Connection $connection_upgrade;
			
			proxy_set_header X-Request-ID $req_id;
			proxy_set_header X-Real-IP $the_real_ip;
			
			proxy_set_header X-Forwarded-For $the_real_ip;
			
			proxy_set_header X-Forwarded-Host $best_http_host;
			proxy_set_header X-Forwarded-Port $pass_port;
			proxy_set_header X-Forwarded-Proto $pass_access_scheme;
			
			proxy_set_header X-Original-URI $request_uri;
			
			proxy_set_header X-Scheme $pass_access_scheme;
			
			# Pass the original X-Forwarded-For
			proxy_set_header X-Original-Forwarded-For $http_x_forwarded_for;
			
			# mitigate HTTPoxy Vulnerability
			# https://www.nginx.com/blog/mitigating-the-httpoxy-vulnerability-with-nginx/
			proxy_set_header Proxy "";
			
			# Custom headers to proxied server
			
			proxy_connect_timeout 5s;
			proxy_send_timeout 60s;
			proxy_read_timeout 60s;
			
			proxy_buffering "off";
			proxy_buffer_size "4k";
			proxy_buffers 4 "4k";
			proxy_request_buffering "on";
			
			proxy_http_version 1.1;
			
			proxy_cookie_domain off;
			proxy_cookie_path off;
			
			# In case of errors try the next upstream server before returning an error
			proxy_next_upstream error timeout;
			proxy_next_upstream_tries 3;
			
			rewrite ^/logs/(.*)$ /$1 break;
			
			rewrite (?i)/logs/(.*) /$1 break;
			rewrite (?i)/logs$ / break;
			proxy_pass http://upstream_balancer;
			
			proxy_redirect off;
			
		}

```

I see no errors in either kibana or nginx controller logs.  
We also have a kubernetes setup on one of our local servers and we are facing the same issue.

---

<div class="post-metadata">

**Author:** ![sud7](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@sud7](https://discuss.elastic.co/u/sud7)\
**Post date:** [December 14, 2018, 1:08pm UTC](https://discuss.elastic.co/t/kibana-with-nginx-ingress-on-minikube/160303/2 "2018-12-14T13:08:38Z")

</div>

Found the issue, the issue was with search guard. On our QA we have an https ingress for which we enabled the searchguard.cookie.secure . When we used http ingress in our test this caused a login loop

`searchguard.cookie.secure: true`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2019, 1:16pm UTC](https://discuss.elastic.co/t/kibana-with-nginx-ingress-on-minikube/160303/3 "2019-01-11T13:16:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
