-
Notifications
You must be signed in to change notification settings - Fork 14
/
Copy pathopensearch-dashboards.yml
31 lines (26 loc) · 1.51 KB
/
opensearch-dashboards.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
server.name: os_dashboards
server.host: "0.0.0.0"
opensearch.hosts: [https://os01:9200, https://os02:9200, https://os03:9200]
opensearch.username: kibanaserver
opensearch.password: kibanaserver
# Encrypt traffic between the browser and OpenSearch-Dashboards
server.ssl.enabled: true
server.ssl.certificate: /usr/share/opensearch-dashboards/config/certificates/os-dashboards/os-dashboards.pem
server.ssl.key: /usr/share/opensearch-dashboards/config/certificates/os-dashboards/os-dashboards.key
# Encrypt traffic between OpenSearch-Dashboards and Opensearch
opensearch.ssl.certificateAuthorities:
[/usr/share/opensearch-dashboards/config/certificates/ca/ca.pem]
opensearch.ssl.verificationMode: full
opensearch.requestHeadersWhitelist: ["securitytenant", "Authorization"]
opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.enable_global: true
opensearch_security.multitenancy.tenants.enable_private: true
opensearch_security.multitenancy.tenants.preferred: ["Private", "Global"]
opensearch_security.multitenancy.enable_filter: false
opensearch_security.auth.type: openid
opensearch_security.openid.connect_url: https://172.17.0.1:8443/auth/realms/master/.well-known/openid-configuration
opensearch_security.openid.base_redirect_url: https://172.17.0.1:5601
opensearch_security.openid.client_id: dashboards
opensearch_security.openid.client_secret: secret
opensearch_security.openid.root_ca: /usr/share/opensearch-dashboards/config/certificates/ca/ca.pem
opensearch_security.openid.verify_hostnames: "false"