借助Search Guard认证的Kibana如何通过REST API连接?
Alright, let's break down how to connect to your Search Guard-protected Kibana instance via the REST API—there are a few reliable methods depending on your use case:
1. Basic Authentication (Most Common)
Search Guard typically enables HTTP Basic Auth by default for Kibana's API endpoints. This is the simplest approach for scripted or tool-based access.
To use it, include your Search Guard username and password in the request:
- Using
curlwith direct credentials:curl -u "your-username:your-password" https://<kibana-host>:<kibana-port>/api/status - Alternatively, manually encode your credentials as Base64 and add the
Authorizationheader:
First, encodeusername:password(e.g., runecho -n "admin:admin" | base64in your terminal), then use:curl -H "Authorization: Basic <base64-encoded-string>" https://<kibana-host>:5601/api/status
Notes for HTTPS: If your Kibana uses HTTPS (recommended for production), either ignore certificate validation for testing with -k, or specify your CA certificate for secure connections:
curl -u "admin:admin" --cacert /path/to/root-ca.pem https://<kibana-host>:5601/api/status
2. Search Guard API Keys
For a more secure, revocable alternative to static username/password pairs, use Search Guard's API key authentication:
Step 1: Create an API Key
First, generate an API key using a privileged user (like an admin):
curl -u "admin:admin" -X POST https://<kibana-host>:5601/_searchguard/api/v1/auth/keys/create \ -H "Content-Type: application/json" \ -d '{ "username": "your-rest-user", "expiry": "30d", "metadata": { "description": "API key for automated REST access" } }'
The response will include an access_key and secret_key—save these securely, as they won't be displayed again.
Step 2: Use the API Key for Authentication
Treat the access_key as the username and secret_key as the password in a Basic Auth request:
curl -u "<access_key>:<secret_key>" https://<kibana-host>:5601/api/status
3. Session-Based Authentication (For Stateful Clients)
If you need to mimic a user's browser session (e.g., for longer-lived access without re-sending credentials), you can use session cookies:
Step 1: Log in to get a session cookie
curl -c cookies.txt -X POST https://<kibana-host>:5601/_searchguard/login \ -H "Content-Type: application/json" \ -d '{ "username": "your-user", "password": "your-password" }'
The -c cookies.txt flag saves the session cookie to a file for reuse across subsequent requests.
Step 2: Use the cookie for subsequent requests
curl -b cookies.txt https://<kibana-host>:5601/api/status
Keep in mind that sessions have an expiration time, so you'll need to re-authenticate periodically when the cookie expires.
Critical Considerations
- Permissions: Ensure your user has the necessary Search Guard roles to access Kibana's API endpoints. At minimum, assign a role that includes
kibana_useror custom permissions for paths like/api/*. - Auth Configuration: Check your
kibana.ymlto confirm thatsearchguard.auth.typeincludesbasicorapiKey(these are enabled by default, but if you've configured SAML/OIDC, make sure you haven't disabled these methods). - Security Best Practices: Always use HTTPS in production to avoid transmitting credentials in plaintext. Rotate API keys regularly, and avoid hardcoding credentials in scripts.
内容的提问来源于stack exchange,提问作者Mgasmi

