Kibana
Protect access to Kibana dashboards and administration as an upstream web application.
Overview
Kibana is the web interface and application platform for Elastic data. It normally listens on port 5601. A Kibana route protects the interface and API, but it does not protect the Elasticsearch endpoint itself.
Kibana can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Kibana. Kibana remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose only the Kibana endpoint. Preserve forwarded scheme and host values. Test saved objects, dashboards, API calls, and any external links.
Example
Analysts reach a private Kibana instance through Pomerium. Kibana and Elasticsearch keep Elastic users, spaces, roles, index permissions, and data controls.
Considerations
- Configure server.publicBaseUrl and any base path for the Pomerium origin.
- This route does not protect Elasticsearch directly. Keep Elastic security and credentials active.
