# Possible to have a health check url without authentication

**URL:** <https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 25, 2021, 1:35pm UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564 "2021-07-25T13:35:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![f1outsourcing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f1outsourcing/32/92096_2.png) [@f1outsourcing](https://discuss.elastic.co/u/f1outsourcing)\
**Post date:** [July 25, 2021, 1:35pm UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564/1 "2021-07-25T13:35:13Z")

</div>

My container monitoring environment does not allow me to specify username and password for the health check url option.

Is it possible to disable this for a specific url or 127.0.0.1 still having the xpack.security.enabled: true

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 25, 2021, 11:05pm UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564/2 "2021-07-25T23:05:11Z")

</div>

Welcome to our community! 😃

You can try [Enabling anonymous access | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.13/anonymous-access.html)

---

<div class="post-metadata">

**Author:** ![f1outsourcing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f1outsourcing/32/92096_2.png) [@f1outsourcing](https://discuss.elastic.co/u/f1outsourcing)\
**Post date:** [July 26, 2021, 9:07am UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564/3 "2021-07-26T09:07:30Z")

</div>

And then create a role for access to only this endpoint?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 26, 2021, 10:04pm UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564/4 "2021-07-26T22:04:50Z")

</div>

Yep.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2021, 10:05pm UTC](https://discuss.elastic.co/t/possible-to-have-a-health-check-url-without-authentication/279564/5 "2021-08-23T22:05:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
