# How to access Ziti Controller via Console

**URL:** <https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741>\
**Category:** Ziti Overlay\
**Created:** [June 19, 2024, 9:56am UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741 "2024-06-19T09:56:07Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 19, 2024, 9:56am UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/1 "2024-06-19T09:56:07Z")

</div>

I deployed the controller using k3d in ec2 machine following the blog ,  
[Deploy OpenZiti in Kubernetes with Ease Using k3d](https://blog.openziti.io/deploy-openziti-in-kubernetes-with-ease-using-k3d) ,

```helm
--namespace "ziti" --create-namespace \
--set clientApi.advertisedHost="ec2-<my_ip>.eu-north-1.compute.amazonaws.com" \
--set clientApi.advertisedPort=1280 \
--set clientApi.service.type=LoadBalancer \
--set ctrlPlane.advertisedHost="ec2-<my_ip>.eu-north-1.compute.amazonaws.com" \
--set ctrlPlane.advertisedPort=6262 \
--set ctrlPlane.service.type=LoadBalancer \
--set trust-manager.app.trust.namespace=ziti \
--set trust-manager.enabled=true \
--set cert-manager.enabled=true

```

Then I deployed ZAC as helm chart as a nodePort service , I was not able to access console on browser it complained that it should be secure so since localhost is secure  
I did ssh-tunneling into the ec2 machine along with port-forward and now i can open console on browser .

So what should be my controller name and url

I tried the variants with

`ec2-<ip>.eu-north-1.compute.amazonaws.com:1280`  
as both name and URL and also tried the same with port 6262 , also tried with controller name ziti-controller keeping the urls

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [June 19, 2024, 12:54pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/2 "2024-06-19T12:54:39Z")

</div>

That appears to be the correct URL based on the advertised address and port you showed here. Can you connect to the controller and inspect the certificate and confirm the DNS SANS field contains this address?

This doesn't mean much to me:

> was not able to access console on browser it complained that it should be secure

Without knowing how you're deploying things, this might be perfectly fine. If you're using a self signed certificate that's entirely expected

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 19, 2024, 1:39pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/3 "2024-06-19T13:39:53Z")

</div>

There is no certificate here , I installed it from here [Install the Console in Kubernetes | OpenZiti](https://openziti.io/docs/guides/deployments/kubernetes/kubernetes-console)  
without additional configuring

 ![Screenshot 2024-06-19 at 7.05.23 PM](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/9/90a509984bffd2245b248cb3de59d5e7aa91bb23.png)

---

<div class="post-metadata">

**Author:** ![rgalletto](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rgalletto/32/1508_2.png) [@rgalletto](https://openziti.discourse.group/u/rgalletto)\
**Post date:** [June 19, 2024, 5:10pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/4 "2024-06-19T17:10:02Z")

</div>

@sadath-12 how were you deploying ZAC? Did you run using the following steps?

`npm install`  
`ng build ziti-console-lib`  
`ng build ziti-console-node`  
`node server`

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 19, 2024, 5:44pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/5 "2024-06-19T17:44:16Z")

</div>

No @rgalletto but I deployed via helm

```auto
helm install \
  --namespace ziti-console --create-namespace --generate-name \
  openziti/ziti-console \
    --set service.type=LoadBalancer \
    --set service.advertisedPort=80

```

then edited to the NodePort

---

<div class="post-metadata">

**Author:** ![rgalletto](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rgalletto/32/1508_2.png) [@rgalletto](https://openziti.discourse.group/u/rgalletto)\
**Post date:** [June 19, 2024, 6:39pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/6 "2024-06-19T18:39:50Z")

</div>

Ahh ok I see. So if you are self hosting and accessing ZAC locally via HTTPS the "untrusted certificate" error is expected unless you use a self signed cert that is trusted by your systems trust store.

There are a few different setup guides out there that explain how to do this, but the one i typically would follow is explained here by LetsEncrypt:

> **[Certificates for localhost - Let's Encrypt](https://letsencrypt.org/docs/certificates-for-localhost/)**
>
> Sometimes people want to get a certificate for the hostname “localhost”, either for use in local development, or for distribution with a native application that needs to communicate with a web application. Let’s Encrypt can’t...

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [June 19, 2024, 6:50pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/7 "2024-06-19T18:50:24Z")

</div>

I've never installed ziti console in kubernetes but when in docker or directly starting the node server, if you set these environment variables and supply valid cert/key

```auto
# The in-container path for the key file to use for TLS.
ENV ZAC_SERVER_KEY=
# The in-container path for the cert bundle file to use for TLS.
ENV ZAC_SERVER_CERT_CHAIN=
# the HTTPS port ZAC uses
ENV PORTTLS=

```

That should enable TLS in your ziti console

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 24, 2024, 1:04pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/8 "2024-06-24T13:04:14Z")

</div>

In Kubernetes, the best way to configure a TLS server certificate for the standalone ZAC Node.js server is with Cert Manager (CM) ([section link](https://openziti.io/docs/guides/deployments/kubernetes/kubernetes-console/#tls-with-cert-manager)) and an Ingress Controller with the ClusterIP service type instead of the NodePort service type you're currently using.

This feature will deprecate the standalone ZAC Node.js server for Kubernetes deployments: [add console service option to controller chart · Issue #222 · openziti/helm-charts · GitHub](https://github.com/openziti/helm-charts/issues/222)

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 24, 2024, 3:41pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/9 "2024-06-24T15:41:35Z")

</div>

I think we should have insecure option as well to use , for dev purposes

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 24, 2024, 4:20pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/10 "2024-06-24T16:20:56Z")

</div>

I see what you mean. When I install the `ziti-console` chart to deploy the standalone ZAC Node.js server without an Ingress Controller, the web browser displays an empty white screen and the Javascript console complains about an SSL error, citing a CORS violation.

As a workaround, you can deploy the standalone ZAC chart and access it via the CORS-allowed "localhost" address without TLS by forwarding a local port with `kubectl`.

```bash
kubectl -n ziti port-forward deployments/ziti-console 1408:1408

```

Then, visit [http://localhost:1408/login](http://localhost:1408/login)

One of the nice things about the forthcoming controller chart feature I mentioned is that it will use Ziti's built-in TLS by default.

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 24, 2024, 4:38pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/11 "2024-06-24T16:38:15Z")

</div>

thanks @qrkourier you sense me nicely .  
I am aware localhost is considered as secure , but this cluster is in aws not in my local .  
So instead I tried to ssh-tunnel into my laptop and opened zac and it works after that the issue is it is not connecting to the controller and the steps i tried to login is

controller name: ec2-.eu-north-1.compute.amazonaws.com:1280  
url: ec2-.eu-north-1.compute.amazonaws.com:1280

controller name: ec2-.eu-north-1.compute.amazonaws.com:6262  
url: ec2-.eu-north-1.compute.amazonaws.com:6262

controller name: ziti-controller  
url: ec2-.eu-north-1.compute.amazonaws.com:1280

controller name: ziti-controller  
url: ec2-.eu-north-1.compute.amazonaws.com:1280

login fails in all the above cases

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 24, 2024, 4:46pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/12 "2024-06-24T16:46:55Z")

</div>

I'm happy to hear you worked around the empty white console page by forwarding a local port with SSH to access the NodePort without TLS. You can also do this with `kubectl` instead of SSH, but you must use the container port, not the advertised port of the cluster service if forwarding to the deployment with `kubectl`.

Now you're having trouble with logging in as "admin," correct?

When you deploy the standalone ZAC server, you have the option to configure the URL of the Ziti controller, e.g., `--set "settings.edgeControllers[0].url=https://ec2-.eu-north-1.compute.amazonaws.com:1280"`.

Alternatively, you can manually add a controller by visiting the console and adding the URL.

I assume you are using the correct password for user "admin."

What is the precise symptom of the failure? Is an error message displayed? Is there a interesting Javascript console message? Is there an HTTP response from the server when you submit the form? Does the console's pod log show anything helpful?

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 24, 2024, 4:57pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/13 "2024-06-24T16:57:18Z")

</div>

At first ZAC asked me controller name and url and it says , login failed cant connect to controller.  
I'm sure controller is working as I can login via ziti cli

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 24, 2024, 5:05pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/14 "2024-06-24T17:05:25Z")

</div>

There must be a problem with the URL to the controller's client API or the connection to that URL. Did you try it with a prefix `https://`?

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 24, 2024, 7:01pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/15 "2024-06-24T19:01:50Z")

</div>

with https I get ` "error": "Invalid Edge Controller"`  
with http I get `{"error":"Edge Controller not Online","errorObj":{}}`

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 24, 2024, 8:39pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/16 "2024-06-24T20:39:16Z")

</div>

I have another option for you. I've just released v1.0.10 of the ziti-controller chart. It provides the console on the `/zac/` path in the management API, so you no longer need a separate ziti-console deployment.

You can ensure the new version is installed by adding this to your `helm upgrade` command: `--version 1.0.10`.

After upgrading the ziti-controller chart, you can visit the console at `https://{controller address}:{controller port}/zac/`.

---

<div class="post-metadata">

**Author:** ![sadath-12](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/sadath-12/32/2043_2.png) [@sadath-12](https://openziti.discourse.group/u/sadath-12)\
**Post date:** [June 25, 2024, 5:20am UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/17 "2024-06-25T05:20:42Z")

</div>

but the ziti controller is also running on http for testing purpose . Why cant we have http for zac for testing purpose ?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 25, 2024, 12:07pm UTC](https://openziti.discourse.group/t/how-to-access-ziti-controller-via-console/2741/18 "2024-06-25T12:07:21Z")

</div>

I'm not aware of a way to configure any of Ziti controller's servers with a non-TLS web listener. This is by design and does not impede testing. For example, you can operate a Ziti controller with a single web listener (a `web` configuration object where RESTful APIs may be bound) and it will use the controller's default server certificate for all APIs, e.g., `edge-client`, `edge-management`.

The console's static files are present in to the `ziti-controller` container image in `/ziti-console`, and the new Helm chart configures the controller to serve the single page application (SPA) on the same web listener as the `edge-management` binding with URL path `/zac/`.
