A lightweight authentication middleware for Kibana that enables Single Sign-On (SSO) using oauth2-proxy — a free and simple alternative to the native SSO available only in Kibana's Platinum and Enterprise tiers.
This project is ideal for teams using the free version of Kibana who want to enforce user-based access control via SSO, without giving up Kibana’s native RBAC.
Tested with Elasticsearch and Kibana version 9.0.0
- SSO authentication using oauth2-proxy.
- Seamless integration with Kibana.
- Automatic user provisioning in Elasticsearch.
- Temporary random passwords generated on each login.
- Uses Kibana’s built-in RBAC and user management.
- No paid Elastic licenses required.
- The user authenticates via
oauth2-proxy, which sets thex-forwarded-emailheader. - This middleware intercepts requests to Kibana.
- If the user has a valid Kibana session cookie (
sid), the request proceeds. - If not:
- Extracts the email from
x-forwarded-email - Validates the email domain.
- Checks if the user exists in Elasticsearch:
- If not: creates a new user with the
viewerrole. - If yes: updates the user’s password.
- If not: creates a new user with the
- Logs in to Kibana using the generated password.
- Redirects the user with a valid Kibana session cookie.
- Extracts the email from
- Node.js >= 24.
- Elasticsearch and Kibana 9.0.0 (or compatible).
- A properly configured oauth2-proxy that sets the
x-forwarded-emailheader.
| Variable | Description | Required |
|---|---|---|
KIBANA_TARGET |
URL of your Kibana instance (e.g. https://kibana.example.com) |
Yes |
ELASTIC_TARGET |
URL of your Elasticsearch instance (e.g. https://elastic.example.com) |
Yes |
ELASTIC_USER |
Elasticsearch user with permission to manage users | Yes |
ELASTIC_PASS |
Password for the Elasticsearch user | Yes |
ALLOWED_EMAIL_DOMAINS |
Comma-separated list of allowed email domains (e.g. example.com) |
Yes |
ELASTIC_TIMEOUT_MS |
Timeout for Elasticsearch requests in milliseconds (default: 10000) |
No |
PORT |
Port for the middleware to run on (default: 3000) |
No |
KIBANA_TARGET=https://kibana.example.com
ELASTIC_TARGET=https://elastic.example.com
ELASTIC_USER=elastic
ELASTIC_PASS=your-secure-password
ALLOWED_EMAIL_DOMAINS=example.com
ELASTIC_TIMEOUT_MS=5000
PORT=3000
⚠️ Important: Do not commit your.envfile to version control. It may contain sensitive information.
To test the middleware locally without running oauth2-proxy, use a browser extension like ModHeader to inject the header: x-forwarded-email: your-email@example.com
git clone https://github.com/your-org/kibana-auth-middleware.git
cd kibana-auth-middleware
cd src
npm install
cp .env.example .env # Fill in your environment details
npm startdocker pull alexsanderp/kibana-auth-middleware:latest
docker run -p 3000:3000 --env-file .env alexsanderp/kibana-auth-middleware:latestThis project uses Jest for unit and integration tests.
📁 Note: All test commands must be run inside the
src/directory.
cd src
# Run all tests
npm test
# Generate a coverage report
npm run test:coverage- Passwords generated are temporary and unique to each session.
- Users are created with the least privilege (
viewerrole). - Only emails from allowed domains can authenticate.
Contributions are welcome! Please open issues or submit pull requests for new features, bug fixes, or improvements. See CONTRIBUTING.md for guidelines.
This project is licensed under the MIT License.
For questions or feedback, feel free to open an issue on GitHub.