如何在开源版Kibana中锁定仪表盘以防止修改?
Hey Sam, great question—since you're working with the open-source Kibana build (no X-Pack subscription needed), there are a couple of practical workarounds to lock your dashboards so users can interact with filters but can't modify the original setup. Here's what I recommend:
1. Create a Read-Only Clone of Your Dashboard
This is the most straightforward and flexible method, letting you keep an editable original while sharing a locked version with users:
- First, save your fully configured dashboard as your "master" copy (keep this one private for your own edits).
- Clone the master dashboard to create a new copy for users.
- Open Kibana's Dev Tools and run this command to fetch the cloned dashboard's saved object (replace
<dashboard-id>with the ID of your cloned dashboard—you can find this in the dashboard URL):GET .kibana/_doc/dashboard/<dashboard-id> - In the response, locate the
attributessection and change theeditablefield fromtruetofalse. - Save the modified object back using this PUT command (use the same
<dashboard-id>):PUT .kibana/_doc/dashboard/<dashboard-id> { // Paste the modified JSON content here, with "editable": false }
Now when users open this cloned dashboard, they’ll see all your visualizations, be able to apply filters, but won’t have access to edit buttons or options to modify the dashboard structure.
2. Use View-Only Share Links
If you don’t want to mess with saved objects directly, Kibana’s built-in sharing feature can help:
- Open your dashboard, click the Share button in the top-right corner.
- Select "Share dashboard" and look for the View only toggle (available in most recent open-source versions). Enable it, then generate the share link.
- Users who open this link will land in a view-only mode where editing controls are hidden. They can still use filters, zoom into visualizations, and interact with the data—just not change the dashboard itself.
Note: This relies on Kibana’s session controls, so make sure users don’t have admin access that lets them switch back to edit mode.
3. Restrict API Access via Reverse Proxy
For a more hardline approach (if you want to block all editing across your Kibana instance for non-admin users), use a reverse proxy like Nginx to block write requests to Kibana’s saved objects API:
- Set up Nginx in front of your Kibana instance.
- Add rules to block
POST,PUT, andDELETErequests to the.kibanaindex API endpoints (e.g.,/api/saved_objects/dashboard/*). - Keep a separate, direct access path to Kibana (bypassing the proxy) for your own editing work.
This ensures no users can modify any saved objects, including dashboards, while still letting them view and interact with the data.
Each method has its pros—cloning gives you the most control, share links are quick to set up, and the proxy method is the most secure for large teams. Pick the one that fits your workflow best!
内容的提问来源于stack exchange,提问作者Sam

