You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ELK Stack 7.4 OSS版如何为用户配置Dashboard只读访问权限?

ELK 7.4 OSS: Workarounds for Dashboard Read-Only Access (No Xpack RBAC)

Hey there, since you're working with the OSS version of ELK 7.4 (which doesn't have Xpack's role-based access control), here are practical, tested ways to grant users read-only access to your specific dashboard:


1. Lock Down Elasticsearch Index Permissions First

Your dashboard pulls data from Elasticsearch indices, so start by ensuring the target user can only read those specific indices (no write/delete access). Here's how to set this up with Elasticsearch's file-based realm:

  • Add a dedicated read-only user in config/users:
    dashboard_viewer:your_secure_password
    
  • Create a read-only role in config/roles.yml (replace your_dashboard_indices* with your actual index patterns):
    dashboard_reader_role:
      cluster: ["monitor"]  # Minimal cluster access
      indices:
        - names: ["your_dashboard_indices*"]
          privileges: ["read", "view_index_metadata"]
    
  • Link the user to the role in config/users_roles:
    dashboard_reader_role: dashboard_viewer
    

Restart Elasticsearch to apply these changes. This ensures the user can't modify the underlying data powering your dashboard.

2. Restrict Kibana Functionality via Nginx Reverse Proxy

Since OSS Kibana doesn't let you hide modules natively, use an Nginx reverse proxy to block access to all Kibana paths except the dashboard section. This prevents users from creating/editing visualizations, indices, or other dashboards.

Here's a sample Nginx config:

server {
    listen 80;
    server_name your-kibana-domain.com;

    # Allow access only to dashboard-related paths and required static assets
    location ~ ^/(app/dashboard|bundles|translations|plugins|api/status) {
        proxy_pass http://localhost:5601;  # Point to your Kibana instance
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }

    # Block all other requests (return 403 or redirect to your dashboard)
    location / {
        # Option 1: Forbid access
        return 403;
        # Option 2: Redirect directly to your specific dashboard
        # return 302 /app/dashboard#/view/your-dashboard-UUID;
    }
}

Restart Nginx, and have users access Kibana through this Nginx endpoint. They'll only be able to view the dashboard and nothing else.

3. Quick Fix: Static Dashboard Sharing (For Public/Unsecured Access)

If you don't need user authentication (e.g., sharing with internal teams you trust), you can generate a direct share link for your dashboard:

  1. Open your dashboard in Kibana.
  2. Click the Share button (top-right corner).
  3. Copy the generated URL.
  4. Ensure your Elasticsearch indices are accessible to anonymous users (adjust your role config to include the anonymous user if needed).

Note: This is less secure than the first two methods, so only use it for non-sensitive dashboards.


Final Recommendation

For most production scenarios, combine Elasticsearch index-level read-only permissions with Nginx path restriction—this balances security and usability perfectly.

内容的提问来源于stack exchange,提问作者rehan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:08:46