# Revers proxy setup for opensearch-dashboard

**URL:** <https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137>\
**Category:** OpenDistro\
**Tags:** discuss\
**Created:** [April 5, 2022, 10:55am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137 "2022-04-05T10:55:31Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 5, 2022, 10:55am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/1 "2022-04-05T10:55:31Z")

</div>

Hello Team,

I am using docker container to run the opensearch and opensearch-dashboard.

I wanted to setup revers proxy using vhost in Ubuntu 20.4 server.

I would like to know do we have any documentation related to this?

We just wanted to know the \*\*DocumentRoot" directory path so that we can mentioned it in the vhost configuration for proxy setup.

Thanks.

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 6, 2022, 9:37pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/2 "2022-04-06T21:37:52Z")

</div>

Hi @sabil -

I think since Nginx is a web server, you’ll still have to provide it a DocumentRoot inside of a `server{}` directive. Since you have no code to serve up and are only acting as a proxy, I believe the document root can be arbitrary as long as you’re including the `proxy_pass` directive.

I haven’t done this in a while, but I believe there’s some magic you can perform by using the nginx\_http\_proxy module as well - you can read all about it at

[https://nginx.org/en/docs/http/ngx\_http\_proxy\_module.html#proxy\_redirect](https://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_redirect)

If you find a solution that works for you, I’d love if you came back to share it with everyone! I’d love to see it!

Nate

---

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 7, 2022, 10:27am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/3 "2022-04-07T10:27:54Z")

</div>

Hello @nateynate,

Thank you for your suggestion.

The thing is that we are using apache currently in our environment. By any chance do you have any idea about apache configuration for revers proxy for opensearch…

Thank you in advance! 🙂

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 7, 2022, 4:23pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/4 "2022-04-07T16:23:55Z")

</div>

Not sure off the top of my head, but a quick web search reveals the documentation for Apache’s REverse Proxy Guide at [Reverse Proxy Guide - Apache HTTP Server Version 2.4](https://httpd.apache.org/docs/2.4/howto/reverse_proxy.html)

The gist of it is this piece that would go in your `httpd.conf` under your virutalhost directives.

> `ProxyPass "/" "http://www.example.com/"`  
> `ProxyPassReverse "/" "http://www.example.com/"`

This would make Apache redirect any requests starting with `/` to your backend. The `ProxyPassReverse` makes it so that the `Location` headers are re-written to point at the reverse proxy instead of what’s on the backend (in the case of a 302 or 301 redirect).

That should get you started, however I very much suggest referring to the Reverse Proxy guide and experimenting a little bit.

Nate

---

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 8, 2022, 5:47am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/5 "2022-04-08T05:47:56Z")

</div>

@nateynate Thank you so much for your help and support…

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 8, 2022, 5:51pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/6 "2022-04-08T17:51:08Z")

</div>

I’m glad I can be of help! If you end up building your solution, bring your config back here for the rest of us to learn from!

Nate

---

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 9, 2022, 10:31am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/7 "2022-04-09T10:31:41Z")

</div>

@nateynate Yes sure. So far the solution is not working…

However, I will defiantly post it here for others if the working solution is with me.

Thanks.

---

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 10, 2022, 12:45pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/8 "2022-04-10T12:45:11Z")

</div>

Hello @nateynate,

I am able to made some progress on reverse proxy setup for Opensearch dashboard.

The challenge/issue I am facing is when I give port 5601 in proxypass and proxypassrevers the URL is not working at all… When I try to change the port from 5601 to 9200 (opensearch-node) I am getting an output (Opensearch information) on the web browser using proxy URL

Do you have any idea about the **DocumentRoot** for opensearch-dashbaord? Or is there any setting or configure we can give for a opensearch-dashbaord to get it work.

Thanks.  
Sabil.

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 11, 2022, 5:32pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/9 "2022-04-11T17:32:02Z")

</div>

Welcome back @sabil! Do you mind pasting the appropriate sections of `httpd.conf` defining your proxypass settings?

---

<div class="post-metadata">

**Author:** ![rick98](https://avatars.discourse-cdn.com/v4/letter/r/a183cd/32.png) [@rick98](https://forum.opensearch.org/u/rick98)\
**Post date:** [April 12, 2022, 6:12pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/10 "2022-04-12T18:12:41Z")

</div>

This is what we have working with Apache (bearing in mind these are docker containers so Apache is listening on external 80/443, but communicating to the dashboard on the docker network on 5601)

There’s some additional bits on proxying to another non-dashboard URI and some authentication stuff, but left those out for brevity.

```auto
<VirtualHost *:80>
    ServerName localhost
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI}
</VirtualHost>

<VirtualHost _default_:443>

# General setup for the virtual host
DocumentRoot "/usr/local/apache2/htdocs"
ServerName localhost
ServerAdmin you@localhost

ProxyPass "/" "http://opensearch-dashboards:5601/"
ProxyPassReverse "/" "http://opensearch-dashboards:5601/"

```

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 12, 2022, 8:57pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/11 "2022-04-12T20:57:10Z")

</div>

A couple of things seem off to me here, but without more specifics about what is going wrong, I’m afraid I’ll have to throw out a few more guesses.

Firstly, you’re redirecting https requests back to http in your proxypass directive. You probably want to replace `http` with `https` in your rewrite target. You may also need to add the directive

```
SSLProxyEngine on

```

to be included in your configuration. Can you describe a bit more about what’s not working and we’ll go from there?

P.S. There might be some known-to-be-working examples by searching google for working proxypass configuration examples. There might be some eccentricity of the configuration that I’m missing.

---

<div class="post-metadata">

**Author:** ![rick98](https://avatars.discourse-cdn.com/v4/letter/r/a183cd/32.png) [@rick98](https://forum.opensearch.org/u/rick98)\
**Post date:** [April 12, 2022, 9:37pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/12 "2022-04-12T21:37:09Z")

</div>

Actually, my config works - it’s a bit incomplete - was just showing a small extract since @sabil had asked for a working example.

If their dashboard is running SSL, then they’ll need to configure such - as I noted, we’re using docker containers, so the dashboard instance is not exposed to any external interfaces, only the docker internal network, while Apache is exposed and running TLS.

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 12, 2022, 11:05pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/13 "2022-04-12T23:05:12Z")

</div>

Thanks @rick98 - I had mistakenly assumed that OP responded and not someone new trying to help. That’s my bad. 🙂

---

<div class="post-metadata">

**Author:** ![sabil](https://avatars.discourse-cdn.com/v4/letter/s/f05b48/32.png) [@sabil](https://forum.opensearch.org/u/sabil)\
**Post date:** [April 13, 2022, 4:59am UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/14 "2022-04-13T04:59:16Z")

</div>

Hello @nateynate and @rick98,

Thank you so much for your suggestion and assistance.

I have a solution which is working fine now. 🙂

My scenario is little different, we have an application which is running on “/” in reverse proxy and I wanted to run additional application which is “opensearch-dashboard” using apache reverse proxy on another path.  
In this scenario I wanted to change the entry point/base URL of opensearch-dashboard to “/opnesearch-dashboard” instead of “/”. To achieve this I have added couple of environment variable to docker-compose.yml file as follows.

```auto
- "SERVER_BASEPATH=/opensearch-dashboard"
- "SERVER_REWRITEBASEPATH=true"

```

Following is the configuration of .conf file.

```auto
<Location /opensearch-dashboard>
ProxyPass http://127.0.0.1:5601/opensearch-dashboard
ProxyPassReverse http://127.0.0.1:5601/opensearch-dashboard
</Location>

```

Hope I am able to explain properly. If not feel free to ask question and I am happy to answer here.

Thank you once again  
Sabil.

---

<div class="post-metadata">

**Author:** ![nateynate](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/nateynate/32/4913_2.png) [@nateynate](https://forum.opensearch.org/u/nateynate)\
**Post date:** [April 14, 2022, 10:13pm UTC](https://forum.opensearch.org/t/revers-proxy-setup-for-opensearch-dashboard/9137/15 "2022-04-14T22:13:12Z")

</div>

Thanks @sabil ! I didn’t know about the `SERVER_BASEPATH` options!
