# Simple JWT authentication example with Docker

**URL:** <https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [February 7, 2024, 4:59pm UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786 "2024-02-07T16:59:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lasra\_Bilaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lasra_bilaj/32/127247_2.png) [@Lasra\_Bilaj](https://discuss.elastic.co/u/Lasra_Bilaj)\
**Post date:** [February 7, 2024, 4:59pm UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/1 "2024-02-07T16:59:04Z")

</div>

I want to find a simple example of JWT based authentication for Elasticsearch with docker.

I am using the the docker-compose.yml file provided by Elastic here at:

> **[Install Elasticsearch with Docker | Elasticsearch Guide \[7.17\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/docker.html#docker-compose-file)**

Is there a resource where I can set that up with the minimal settings required, I can use ruby based JWT to create the tokens.

---

<div class="post-metadata">

**Author:** ![Sergi\_Massaneda\_Dona](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergi_massaneda_dona/32/107149_2.png) [@Sergi\_Massaneda\_Dona](https://discuss.elastic.co/u/Sergi_Massaneda_Dona)\
**Post date:** [February 8, 2024, 10:22am UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/2 "2024-02-08T10:22:11Z")

</div>

Hello, thanks for reaching out,  
I updated the tags since the `Elastic Security` references the "Elastic Security Solution" questions, this is an `Elasticsearch` question. I'll forward it to the correct team.

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [February 8, 2024, 3:49pm UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/3 "2024-02-08T15:49:25Z")

</div>

Hi,

First of all JWT authn is not available in version 7.17.  
I recommend you go with version 8.12.  
Secondly, docker/docker compose configuration is only tangential to (JWT) authn realm configuration (i.e. if you get to a JWT configuration that works for a single node cluster, launched under the env your most familar with, it should efortlessly translate to the docker compose setup).

Here are the docs explaining JWT configuration: [JWT authentication | Elasticsearch Guide [8.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/jwt-auth-realm.html#jwt-realm-configuration)  
JWT realm configuration is very versatile. You can also take inspiration from integration tests we use on our CI: [elasticsearch/x-pack/qa/oidc-op-tests/src/javaRestTest/java/org/elasticsearch/xpack/security/authc/oidc/C2IdOpTestCase.java at fca3fc82beda930e75d147331dce4dbfdc546e61 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/blob/fca3fc82beda930e75d147331dce4dbfdc546e61/x-pack/qa/oidc-op-tests/src/javaRestTest/java/org/elasticsearch/xpack/security/authc/oidc/C2IdOpTestCase.java#L82)

---

<div class="post-metadata">

**Author:** ![Lasra\_Bilaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lasra_bilaj/32/127247_2.png) [@Lasra\_Bilaj](https://discuss.elastic.co/u/Lasra_Bilaj)\
**Post date:** [March 4, 2024, 10:07am UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/4 "2024-03-04T10:07:25Z")

</div>

Hi Albert thanks for the tip. I did indeed try with 8.11.4 with a simple elasticsearch instance and without docker. I used the information provided by the documentation but had no success.

I get the following error when starting up elasticsearch:

```auto

fatal exception while booting Elasticsearchjava.lang.IllegalStateException: security initialization failed
	at org.elasticsearch.security@8.11.4/org.elasticsearch.xpack.security.Security.createComponents(Security.java:656)
	at org.elasticsearch.server@8.11.4/org.elasticsearch.node.Node.lambda$new$17(Node.java:759)
	at org.elasticsearch.server@8.11.4/org.elasticsearch.plugins.PluginsService.lambda$flatMap$1(PluginsService.java:263)
	at java.base/java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:273)
	at java.base/java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:197)

```

Im sure im missing something, thats why I was looking for a resource where I could following a step by step guide to add JWT to elasticsearch

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [March 5, 2024, 2:01pm UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/5 "2024-03-05T14:01:34Z")

</div>

Hi Lasra,

The snipped doesn't contain enough information to help with diagnosing.  
Can you paste the full stack trace? In any case, the immediate problem doesn't look JWT-related (given the truncated stack trace you've shared).

---

<div class="post-metadata">

**Author:** ![Lasra\_Bilaj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lasra_bilaj/32/127247_2.png) [@Lasra\_Bilaj](https://discuss.elastic.co/u/Lasra_Bilaj)\
**Post date:** [March 6, 2024, 8:19am UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/6 "2024-03-06T08:19:23Z")

</div>

Hi Albert, thanks for the help but turns out that the endpoint to use JWT authentication with DLS for Connectors was supposed to be the enterprisesearch endpoint and not the elasticsearch endpoint.

I assumed since API key authentication with DLS for connectors works with elasticsearch, it was supposed to be the same for JWT. My problem is now solved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2024, 8:19am UTC](https://discuss.elastic.co/t/simple-jwt-authentication-example-with-docker/352786/7 "2024-04-03T08:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
