Updated: 28 September 2026 · Applies to: Elastic Stack 9.x on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9

CentOS 7 is end of life. Current Kibana versions (9.x) have their own login and can use TLS, so Nginx is used mainly to publish Kibana on a normal HTTPS address. These steps work on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9. See "How to install and Secure Elasticsearch and Kibana on CentOS 7?" for installing Kibana.

Publish Kibana through Nginx with HTTPS

In /etc/kibana/kibana.yml set server.publicBaseUrl: "https://kibana.example.com" and restart Kibana. Then create an Nginx server block:

server {
    listen 80;
    server_name kibana.example.com;
    location / {
        proxy_pass http://127.0.0.1:5601;
        proxy_http_version 1.1;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Reload Nginx and add a certificate with certbot --nginx -d kibana.example.com. Kibana has its own login, so a separate Nginx password is optional; restricting the site to your IPs (allow / deny) adds another layer. On AlmaLinux/Rocky also run setsebool -P httpd_can_network_connect 1.

Optional: an extra password prompt

apt install apache2-utils          # httpd-tools on AlmaLinux/Rocky
htpasswd -c /etc/nginx/.kibana-users admin

Add auth_basic "Kibana"; and auth_basic_user_file /etc/nginx/.kibana-users; to the location block and reload Nginx. Users then log in twice (Nginx, then Kibana).

Ucartz services for this topic

Was this answer helpful? 1 Users Found This Useful (2 Votes)