# Kubernetes: how to run HA kibana behind service? - Login fails if using more than one instance

**URL:** https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [August 6, 2019, 9:04am UTC](https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967 "2019-08-06T09:04:49Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [August 6, 2019, 9:04am UTC](https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967/1 "2019-08-06T09:04:49Z")

</div>

Hi,

I am running elastic stack with enabled security module (TLS + authentication) in kubernetes.  
My Infrastructure inside kubernetes looks like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e1685b16cb6a22a7534cf15de593f353f03619b.png)

I have one issue and one question:

**Issue:**  
If running only one kibana pod, Login is running fine, I can work with kibana. But If I run 2 pods behind the kibana service, I the Login window comes back after entering credentials. I am caught in a loop.

So what do I need to to if I want to use multiple kibana instances behind a service / loadbalancer?  
I think I read somewhere of a parameter / key / cookie stuff which should be configured identically on all kibana instances which are behind a loadbalancer. But I am not too sure about it and I cannot find this information again.

**Question:**  
Is that picture shown best practice for running kibana + elasticsearch in kubernetes or is it still better to run kibana against it's own coordinating only node as described in production recommendations?

Thanks a lot,  
Andreas

PS: I did not set any session affinity yet.

---

<div class="post-metadata">

### Author: ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)
#### Post date: [August 6, 2019, 9:09am UTC](https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967/2 "2019-08-06T09:09:55Z")

</div>

> [@asp](#):
>
> So what do I need to to if I want to use multiple kibana instances behind a service / loadbalancer?  
> I think I read somewhere of a parameter / key / cookie stuff which should be configured identically on all kibana instances which are behind a loadbalancer. But I am not too sure about it and I cannot find this information again.

You need to set `xpack.security.encryptionKey` to be the same in all of your Kibana instances as by default this will be auto-generated with a different value every time Kibana starts. See [Security settings in Kibana | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/security-settings-kb.html#security-ui-settings)

---

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [August 6, 2019, 9:24am UTC](https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967/3 "2019-08-06T09:24:09Z")

</div>

great, that was the link I lost 😉

I just added `xpack.security.encryptionKey` to keystore and it works again. Many thanks.

Can anyone please also answer the Best practice question above?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 3, 2019, 9:24am UTC](https://discuss.elastic.co/t/kubernetes-how-to-run-ha-kibana-behind-service-login-fails-if-using-more-than-one-instance/193967/4 "2019-09-03T09:24:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
