Updated: 28 September 2026 · Applies to: Elastic Stack 9.x on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9
CentOS 7 is end of life. Current Kibana versions (9.x) have their own login and can use TLS, so Nginx is used mainly to publish Kibana on a normal HTTPS address. These steps work on Ubuntu 24.04, Debian 12, AlmaLinux 9 and Rocky Linux 9. See "How to install and Secure Elasticsearch and Kibana on CentOS 7?" for installing Kibana.
Publish Kibana through Nginx with HTTPS
In /etc/kibana/kibana.yml set server.publicBaseUrl: "https://kibana.example.com" and restart Kibana. Then create an Nginx server block:
server {
listen 80;
server_name kibana.example.com;
location / {
proxy_pass http://127.0.0.1:5601;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
Reload Nginx and add a certificate with certbot --nginx -d kibana.example.com. Kibana has its own login, so a separate Nginx password is optional; restricting the site to your IPs (allow / deny) adds another layer. On AlmaLinux/Rocky also run setsebool -P httpd_can_network_connect 1.
Optional: an extra password prompt
apt install apache2-utils # httpd-tools on AlmaLinux/Rocky htpasswd -c /etc/nginx/.kibana-users admin
Add auth_basic "Kibana"; and auth_basic_user_file /etc/nginx/.kibana-users; to the location block and reload Nginx. Users then log in twice (Nginx, then Kibana).
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
