Connections
URL format, every authentication option, TLS, SSH tunnels, proxies, production and read-only connections, import and export.
Every cluster you work with is a saved connection. Connections live in folders in the sidebar of the Connections screen, open as tabs in the title bar, and can be connected side by side.
The connection URL
Paste one URL per cluster into Connection URL (or click Paste from clipboard):
https://user:password@host:9200/optional/path-prefix
- Only
httpandhttpsare accepted. A barehost:9200becomeshttps://host:9200. - Percent-encoded characters in the username or password (
%40for@,%3Afor:) are decoded. - Credentials are removed from the URL and stored in the macOS Keychain. The query string and
#fragmentare dropped. - The breakdown under the field shows the Scheme, Host (including a path prefix), Port and User that will be used. The password is masked as
••••••••when the field isn’t focused.
If you leave Name empty, a name is suggested from the host (Localhost, the first part of the hostname, or the Elastic Cloud deployment name).
Authentication
Pick one of the options in Authentication:
| Option | When to use it |
|---|---|
| From URL | Username and password are inside the URL (or the cluster has no security). |
| Basic | Enter Username and Password separately. |
| API key | Paste either id:key or the base64 encoded value Elasticsearch returns. |
| Cloud ID | Elastic Cloud. Paste the Cloud ID; the decoded endpoint is shown as → https://…. Use an API key, or a username and password instead. |
| AWS SigV4 | Amazon OpenSearch Service (es) or OpenSearch Serverless (aoss). |
| None | Clusters without security. |
Stored secrets are never shown again: the field says Stored in Keychain — leave blank to keep.
AWS SigV4
Set Region (e.g. eu-west-1), Service — OpenSearch Service (es) or OpenSearch Serverless (aoss) — and optionally an AWS profile. Pasting an …<region>.es.amazonaws.com or …aoss.amazonaws.com URL fills these in for you.
kabanos never stores AWS credentials. It uses the standard AWS credential chain: environment variables, ~/.aws profiles, SSO and instance roles. If signing fails, configure ~/.aws or run aws sso login.
TLS
- Verify TLS certificate is on by default. Turn it off only for throwaway local clusters.
- Custom CA certificate — choose a
.pem,.crtor.cerfile for clusters signed by a private CA. - CA / certificate SHA-256 fingerprint (under Advanced) — pin the certificate instead of trusting a CA. Paste the fingerprint Elasticsearch 8 prints on first start; colons and a
sha256 Fingerprint=prefix are fine. The connection is trusted when any certificate in the chain matches. Pinning can’t be combined with an HTTP proxy.
SSH tunnel
For clusters only reachable from a bastion host, open Advanced and enable Connect through an SSH tunnel:
- SSH host, Port (22) and SSH user.
- Authenticate with a Private key (default
~/.ssh/id_ed25519, plus an optional passphrase), the SSH agent (SSH_AUTH_SOCK), or a Password.
TLS is still verified against the cluster’s own hostname. The tunnel reconnects automatically if it drops.
HTTP(S) proxy
Set HTTP(S) proxy under Advanced, e.g. http://proxy.corp:3128. You can use either a proxy or an SSH tunnel on a connection, not both.
Other advanced options
- Request timeout — 1 to 3600 seconds (default 30).
- Accept gzip-compressed responses — on by default; gzip, deflate and brotli responses are decompressed.
- Default headers — one
Key: valueper line, sent with every request.
Production and read-only
Two switches protect important clusters:
- Production — the tab gets a warning stripe and every request that isn’t a read asks for confirmation in a native dialog before it is sent. It is switched on automatically for connections in the Production folder or with the red color tag (you can override it).
- Read-only mode — everything except reads (
GET,HEAD,_search,_count, …) is blocked outright. The tab shows anRObadge.
Both are enforced in the app’s main process, so they apply everywhere: the workspace, the index view, routines and the explorer. See Privacy & safety for exactly what counts as a read.
Testing and engine detection
Test connection sends GET / and reports, for example, Connected · Elasticsearch 8.15.3 · 42 ms, followed by the cluster name, health, node count and the number of indices, aliases and index templates. Errors are explained in plain words — wrong credentials (401), missing privileges (403), refused connections, unknown hosts, timeouts and TLS problems.
kabanos detects the engine automatically (you can force it with Engine):
| Badge | Meaning |
|---|---|
ES 8.15 | Elasticsearch |
ES Serverless | Elastic Cloud Serverless |
OS 2.19 | OpenSearch |
OS (compat 7.10) | Amazon OpenSearch Service in Elasticsearch-compatibility mode |
AOSS | OpenSearch Serverless |
Organising connections
- Folder — free text; Production, Staging and Local sort first in the sidebar.
- Color tag — amber, red, teal, blue or green; shown on the tab.
- Favorites — star a connection to pin it to the top of the sidebar.
- Filter connections — searches names, hosts and folders.
Open tabs are restored the next time you launch kabanos. The menu-bar icon also lists your connections — click one to open it.
Import and export
The Export… button at the bottom of the sidebar writes kabanos-connections.json with every connection’s settings — without any passwords, API keys or SSH secrets. Share it with your team; after Import…, each person adds their own credentials.