Apr 18 – 22, 2016
DESY Zeuthen
Authorization extension for the secure use of ElasticSearch and Kibana

Apr 21, 2016, 2:00 PM
Seminar room 3 (DESY Zeuthen)

DESY Zeuthen

Platanenallee 6, 15738 Zeuthen (near Berlin), Germany
Wataru Takase (KEK)


Although ElasticSearch and Kibana bring great monitoring platform, they lack access control feature by default. This means any user who can access to Kibana can retrieve any information from ElasticSearch. In CERN cloud service, a homemade ElasticSearch plugin has been deployed to restricts data access based on cloud user. It enables each user to have a separated dashboard for cloud usage. Based on the solution, we integrated Kerberos authentication to Kibana and ElasticSearch. Our solution enables user/role based ElasticSearch access control and Kibana dashboards separation. The integration and deployment was completed in CC-IN2P3.
