# Restricting access via an intermediate layer

**URL:** <https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100>\
**Category:** Elasticsearch\
**Created:** [March 22, 2012, 8:29pm UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100 "2012-03-22T20:29:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dragan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dragan/32/2943_2.png) [@dragan](https://discuss.elastic.co/u/dragan)\
**Post date:** [March 22, 2012, 8:29pm UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100/1 "2012-03-22T20:29:47Z")

</div>

Hi,

I am working on restricting access to my elasticsearch cluster and I'd  
love some feedback on it.

All outside requests should go through an authenticated server that  
passes them (unauthenticated) to elasticsearch. The ES machines only  
accept requests from this server and from each other, all other  
requests are denied.

I am trying to figure out what I'm going to do with the head plugin. I  
can expose an api function that passes the status request to  
elasticsearch, but it would be nice to be able to check up on the  
index through /\_plugin/head/

My questions are the following:

1. I can open port X (X would be a different port from the one on  
which ES is running) and only allow authenticated access on it. I am  
assuming I can host head on port X, since all I need is to access  
/plugins/head/\_site/index.html  
Is that correct?

2. Is this a good way to protect my cluster?

Thank you

---

<div class="post-metadata">

**Author:** ![Thomas\_Peuss](https://avatars.discourse-cdn.com/v4/letter/t/22d042/32.png) [@Thomas\_Peuss](https://discuss.elastic.co/u/Thomas_Peuss)\
**Post date:** [March 23, 2012, 9:18am UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100/2 "2012-03-23T09:18:36Z")

</div>

Hi Dragan!

Am Donnerstag, 22. März 2012 21:29:47 UTC+1 schrieb Dragan:

> passes them (unauthenticated) to elasticsearch. The ES machines only  
> accept requests from this server and from each other, all other  
> requests are denied.

You can tell ES to only bind to localhost (ES defaults to binding to all  
interfaces on the host). So ES is only accessible on the local machine. Put  
for example an Apache httpd on the machine and configure it as reverse  
proxy against the local ES instance. You can configure authentication quite  
detailed in httpd.  
This does not work if you want to use the Java client which uses a binary  
protocol against the ES instance. This would need changes to ES itself.

CU  
Thomas

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [March 23, 2012, 1:56pm UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100/3 "2012-03-23T13:56:39Z")

</div>

Head is HTML5 application, which means head code doesn't run inside  
elasticsearch. Instead you load it into your browser, and then your browser  
is executing all necessary queries against elasticsearch. In other words,  
to use head you need to provide access from your browser to all requests  
that head is using. Head itself doesn't have to be protected since just  
accessing head doesn't give you anything that is not already available on  
github.

If you fell comfortable with configuring jetty, you might want to take a  
look at jetty plugin for elasticsearch  
([GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)). It will allow you to setup  
authentication on the elasticsearch nodes without an intermediate layer.

On Thursday, March 22, 2012 4:29:47 PM UTC-4, Dragan wrote:

> Hi,
> 
> I am working on restricting access to my elasticsearch cluster and I'd  
> love some feedback on it.
> 
> All outside requests should go through an authenticated server that  
> passes them (unauthenticated) to elasticsearch. The ES machines only  
> accept requests from this server and from each other, all other  
> requests are denied.
> 
> I am trying to figure out what I'm going to do with the head plugin. I  
> can expose an api function that passes the status request to  
> elasticsearch, but it would be nice to be able to check up on the  
> index through /\_plugin/head/
> 
> My questions are the following:
> 
> 1. I can open port X (X would be a different port from the one on  
> which ES is running) and only allow authenticated access on it. I am  
> assuming I can host head on port X, since all I need is to access  
> /plugins/head/\_site/index.html  
> Is that correct?
> 
> 2. Is this a good way to protect my cluster?
> 
> Thank you

On Thursday, March 22, 2012 4:29:47 PM UTC-4, Dragan wrote:

> Hi,
> 
> I am working on restricting access to my elasticsearch cluster and I'd  
> love some feedback on it.
> 
> All outside requests should go through an authenticated server that  
> passes them (unauthenticated) to elasticsearch. The ES machines only  
> accept requests from this server and from each other, all other  
> requests are denied.
> 
> I am trying to figure out what I'm going to do with the head plugin. I  
> can expose an api function that passes the status request to  
> elasticsearch, but it would be nice to be able to check up on the  
> index through /\_plugin/head/
> 
> My questions are the following:
> 
> 1. I can open port X (X would be a different port from the one on  
> which ES is running) and only allow authenticated access on it. I am  
> assuming I can host head on port X, since all I need is to access  
> /plugins/head/\_site/index.html  
> Is that correct?
> 
> 2. Is this a good way to protect my cluster?
> 
> Thank you

---

<div class="post-metadata">

**Author:** ![dragan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dragan/32/2943_2.png) [@dragan](https://discuss.elastic.co/u/dragan)\
**Post date:** [March 26, 2012, 2:07pm UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100/4 "2012-03-26T14:07:49Z")

</div>

Thank you guys

On Fri, Mar 23, 2012 at 9:56 AM, Igor Motov [imotov@gmail.com](mailto:imotov@gmail.com) wrote:

> Head is HTML5 application, which means head code doesn't run inside  
> elasticsearch. Instead you load it into your browser, and then your browser  
> is executing all necessary queries against elasticsearch. In other words, to  
> use head you need to provide access from your browser to all requests that  
> head is using. Head itself doesn't have to be protected since just accessing  
> head doesn't give you anything that is not already available on github.
> 
> If you fell comfortable with configuring jetty, you might want to take a  
> look at jetty plugin for elasticsearch  
> ([GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)). It will allow you to setup  
> authentication on the elasticsearch nodes without an intermediate layer.
> 
> On Thursday, March 22, 2012 4:29:47 PM UTC-4, Dragan wrote:
> 
> > Hi,
> > 
> > I am working on restricting access to my elasticsearch cluster and I'd  
> > love some feedback on it.
> > 
> > All outside requests should go through an authenticated server that  
> > passes them (unauthenticated) to elasticsearch. The ES machines only  
> > accept requests from this server and from each other, all other  
> > requests are denied.
> > 
> > I am trying to figure out what I'm going to do with the head plugin. I  
> > can expose an api function that passes the status request to  
> > elasticsearch, but it would be nice to be able to check up on the  
> > index through /\_plugin/head/
> > 
> > My questions are the following:
> > 
> > 1. I can open port X (X would be a different port from the one on  
> > which ES is running) and only allow authenticated access on it. I am  
> > assuming I can host head on port X, since all I need is to access  
> > /plugins/head/\_site/index.html  
> > Is that correct?
> > 
> > 2. Is this a good way to protect my cluster?
> > 
> > Thank you
> 
> On Thursday, March 22, 2012 4:29:47 PM UTC-4, Dragan wrote:
> 
> > Hi,
> > 
> > I am working on restricting access to my elasticsearch cluster and I'd  
> > love some feedback on it.
> > 
> > All outside requests should go through an authenticated server that  
> > passes them (unauthenticated) to elasticsearch. The ES machines only  
> > accept requests from this server and from each other, all other  
> > requests are denied.
> > 
> > I am trying to figure out what I'm going to do with the head plugin. I  
> > can expose an api function that passes the status request to  
> > elasticsearch, but it would be nice to be able to check up on the  
> > index through /\_plugin/head/
> > 
> > My questions are the following:
> > 
> > 1. I can open port X (X would be a different port from the one on  
> > which ES is running) and only allow authenticated access on it. I am  
> > assuming I can host head on port X, since all I need is to access  
> > /plugins/head/\_site/index.html  
> > Is that correct?
> > 
> > 2. Is this a good way to protect my cluster?
> > 
> > Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:34am UTC](https://discuss.elastic.co/t/restricting-access-via-an-intermediate-layer/7100/5 "2017-07-06T03:34:47Z")

</div>


