This is my first outing with nginx. I am using it as a workaround for a quirk of AWS ElasticSearch Kibana dashbaords, namely that I need to use an iframe and Cognito authentication does not work in iframes.
My problem is that, while I have a hard coded one off solution, trying to create a generalized solution is proving difficult.
I need my nginx server to be able to serve as proxy for one of several (properly configured) elasticsearch kibana dashboards the user can choose from.
I currently have the following kibana.conf file. When I pass the elasticsearch kibana dashboard url with my server ip address (ex. http://XX.XXX.XXX.XX/{elasticsearch kibana dash url}.us-east-1.es.amazonaws.com/_plugin/kibana/), the first location can pull the dash url from the request uri and set the proxy_pass to the correct address.
However, on the second location, which is required because the Kibana dashboard process requires a flurry of further calls, those are all requests such as http://XX.XXX.XXX.XX/_plugin/kibana/app/kibana. The way it is currently, with the kibana dashboard url hardcoded in proxy_pass, it works beautifully. But I have no idea how to pass the dashboard url dynamically the way I did with the first call.
Any insight would be greatly appreciated. Thank you!
server {
listen 80;
server_name XX.XXX.XXX.XX;
# error logging
error_log /var/log/nginx/kibana_error.log info;
location ~ ^/(?<kibana_dash_url>.+)/_plugin/kibana/$ {
proxy_http_version 1.1;
proxy_set_header X-Real-IP XX.XXX.XXX.XX;
proxy_set_header Connection "Keep-Alive";
proxy_set_header Proxy-Connection "Keep-Alive";
proxy_set_header Authorization "";
proxy_pass https://$kibana_dash_url/_plugin/kibana/;
proxy_redirect https://$kibana_dash_url/_plugin/kibana/ http://XX.XXX.XXX.XX/kibana/;
}
location ~ (/app/kibana|/app/timelion|/bundles|/built_assets|/translations|/es_admin|/plugins|/api|/ui|/elasticsearch) {
proxy_pass https://<hardcoded elasticsearch url here>.us-east-1.es.amazonaws.com;
# proxy_pass https://<no idea how to get dynamic elasticsearch url here>.us-east-1.es.amazonaws.com;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header Authorization "";
}
}