# Kubernetes ingress for elasticsearch not working after enabling security

**URL:** <https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 1, 2021, 9:54am UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814 "2021-02-01T09:54:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![anoopkv](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Post date:** [February 1, 2021, 9:54am UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/1 "2021-02-01T09:54:36Z")

</div>

I am using [Official helm chart](https://github.com/elastic/helm-charts/tree/master/elasticsearch/examples/security) to install ELK stack on my on-premise VMWare hanzu k8s cluster.

An Ingress controller to the cluster is already created by k8s admin using [Contour](https://projectcontour.io/docs/main/github)

Following [this](https://www.pimwiddershoven.nl/entry/deploy-a-secure-instance-of-elasticsearch-on-kubernetes) instruction of creating self-signed certificate using elasticsearch-certutil. After all the setup and pods running when I try to connect to elastic search using the dns - getting this error

```
upstream connect error or disconnect/reset before headers

```

I am however able to access the same when security is disabled. Really appreciate any pointers

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 2, 2021, 4:53pm UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/2 "2021-02-02T16:53:50Z")

</div>

Hi @anoopkv , this part of the forums is mostly for the elastic security solutions such as beats agents and SIEM.

You might have better luck finding answers to the regular Elastic forums here:

> **[Elastic Stack](https://discuss.elastic.co/c/elastic-stack/81)**
>
> Elasticsearch, Kibana, Beats, and Logstash - also known as the ELK Stack. Reliably and securely take data from any source, in any format, then search, analyze, and visualize it in real time.
> 
> Please post your your topic under the relevant product category - Elasticsearch, Kibana, Beats, Logstash.

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [February 3, 2021, 9:44am UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/4 "2021-02-03T09:44:15Z")

</div>

Hello @anoopkv,

You might be interested by [Elastic Cloud on Kubernetes (ECK)](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-overview.html) that automates the deployment, provisioning, management, and orchestration of Elasticsearch, Kibana, APM Server, Enterprise Search, and Beats on Kubernetes based on the operator pattern.

In particular, ECK manages the [TLS certificates](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-tls-certificates.html) for you and also has a [Helm chart](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-install-helm.html).

---

<div class="post-metadata">

**Author:** ![anoopkv](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Post date:** [February 4, 2021, 1:52pm UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/5 "2021-02-04T13:52:56Z")

</div>

okay. Thanks for the reply

---

<div class="post-metadata">

**Author:** ![anoopkv](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Post date:** [February 4, 2021, 1:53pm UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/6 "2021-02-04T13:53:49Z")

</div>

We dont want to go with ECk solution, but thanks for the suggestions

---

<div class="post-metadata">

**Author:** ![anoopkv](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Post date:** [March 3, 2021, 6:26am UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/7 "2021-03-03T06:26:17Z")

</div>

Thought of posting the solution that worked. Switched to nginx ingress controller, which has gave the option to do ssl passthrough to the elastic stack.

```
ingress:

  enabled: true

  annotations:

    ingress.kubernetes.io/ssl-passthrough: "true"

    kubernetes.io/ingress.class: nginx

    nginx.ingress.kubernetes.io/backend-protocol: HTTPS

    nginx.ingress.kubernetes.io/secure-backends: "true"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:23am UTC](https://discuss.elastic.co/t/kubernetes-ingress-for-elasticsearch-not-working-after-enabling-security/262814/8 "2022-11-04T08:23:01Z")

</div>


