I have a requirement of sharing just Kibana dashboard in view only access mode with customers.
This is the first time I am working with Elasticsearch and Kibana. And this is my first Stackoverflow question. So, kindly bear with me.
Our team is using AWS Elasticsearch service with ES version 6.3, AWS does not provide access to ElasticSearch server and Kibana app server.
Kibana has native support for Read Only dashboard as mentioned here -
Kibana dashboard only mode.
Kibana 6.0 onwards there is support for read only dashboard feature. Also, there is X-pack plugin for Kibana versions not natively supporting this feature.
With AWS ES Service, I installed standalone Kibana on a separate EC2 instance to use its readonly native feature.
Download Kibana6.2.4
Using AWS docs, I have configured kibana.yml
Standalone Kibana looked exactly same as the one default with AWS ES, there is no options for user management.
I installed X-pack plugin with kibana6.2.4 using following command:
sudo ./bin/kibana-plugin install x-pack
I got following exceptions :
Authentication Exception :: {"path":"/_xpack","statusCode":401,"response":"{\"Message\":\"Your request: '/_xpack' is not allowed.\"}"}
If I use kibana6.3, it automatically starts throwing errors -
Authentication Exception :: {"path":"/_xpack","statusCode":401,"response":"{\"Message\":\"Your request: '/_xpack' is not allowed.\"}"}
If I disable x-pack security feature,
xpack.security.enabled: false
kibana server will go indefinitely into an optimization mode on my aws ec2 t2.micro instance, cpu consumption would go upto 100% and after sometime instance stops responding.
I found that some changes are required in elasticsearch.yml which resides on the ElasticSearch cluster instance which we don't have access to.
I raised a support ticket to AWS and they said, view only kibana dashboard is not possible as of now. I have requested them to make it a feature request which they accepted but there is no ETA given
Then, again I went further to find other solutions. I found that, a proxy setup can be used to restrict some ES REST API calls to make the kibana dashboard browsing experience as read only.
Here are some links which I used -
Nginx configuration for Kibana-ElasticSearch read-only/read-write access
Kibana readonly over internet
Elasticsearch readonly rest plugin
The rest plugin above requires access to ElasticSearch server which I don't have.
As another try, using links above, I setup an AWS EC2 t2.micro instance and configured nginx to serve as proxy to restrict backend ElasticSearch api calls to make Kibana read only.
Here is my configuration snippet in nginx.conf -
set $posting 11;
if ( $request_method !~ ^(GET|POST|OPTIONS|HEAD)$ ) { return 405; }
if ( $request_method = POST ) { set $posting 1; }
if ( $request_uri ~ ^/(.+)/(_search)(.*)$ ) { set $posting "${posting}1"; }
if ( $request_method ~ ^(GET|OPTIONS|HEAD)$ ) { set $posting 11; }
if ( $posting != 11 ) { return 403; }
# for elb health checks
location /status {
root /usr/share/nginx/html/ ;
}
location / {
proxy_set_header Host search-<ES_DOMAIN>-<CRYPTO_STRING>.ap-south-1.es.amazonaws.com;
proxy_set_header X-Real-IP <PUBLIC IP>;
proxy_http_version 1.1;
proxy_set_header Connection "Keep-Alive";
proxy_set_header Proxy-Connection "Keep-Alive";
proxy_set_header Authorization "";
proxy_pass https://search-<ES_DOMAIN>-<CRYPTO_STRING>.ap-south-1.es.amazonaws.com/;
proxy_redirect https://search-<ES_DOMAIN>-<CRYPTO_STRING>.ap-south-1.es.amazonaws.com/_plugin/kibana/ http://<PUBLIC IP>/kibana/;
}
With this nginx setting, Kibana's Discover/Timelion/Dev Tools/Management page links wont work for save/delete, which is good.
Discover page goes blank, which is the right thing as no body can send their own queries.
Visualize and Dashboard both work similarly, they show their item lists, which is fine, but after that both pages don't open any real graphs. I want even Visualize page should go blank but not the Dashboard page.
When I looked into firefox/chrome browser inspect/dev tools, both Visualize and Dashboard pages make calls using following apis -
"_plugin/kibana/api/saved_objects/_bulk_get",
"_msearch",
"_plugin/kibana/api/timelion/run"
I am not sure how to stop all UI elements to work except view only links in Dashboard, even Visualize page should be fully restricted.
I am trying to keep only Dashboard open for viewing its predefined graphs without any edit, save or delete options.
After some research with Stackoverflow, I got few answers which are either old or not relevant or even requires access to ES/Kibana server which I don't have.
These are the Stackoverflow links:-
Is custom kibana plugin installation in aws elasticsearch possible
Kibana read only dashboard
How to block selected kibana subpages using nginx
Kibana dashboard only mode
Another approach is given at this link, Applying read only permission to kibana dashboard
But this would lock the .kibana index and it would be a problem for other users using it.
Any help or pointers would be highly appreciated. I am not able to solve this for many days by myself.