Troubleshooting

Fixes for the most common connection, certificate, Keychain and Gatekeeper problems.

“kabanos can’t be opened”

Current builds aren’t notarized yet. Open System Settings → Privacy & Security, scroll to Security and click Open Anyway next to the kabanos message. See Getting started.

The Keychain keeps asking for my password

When macOS asks whether kabanos may use kabanos Safe Storage, click Always Allow. If you click Allow (once), you’ll be asked again next launch. Replacing the app with a new version may ask once more.

Connection errors

MessageWhat to check
Authentication failed (401)The username and password or API key. For API keys, paste id:key or the encoded value.
Authenticated but not allowed to read cluster info (403)The user needs the monitor cluster privilege (or at least access to GET /).
Connection refusedIs the cluster running at that host and port? Is a VPN or SSH tunnel needed?
Host not foundA typo in the host, or a private DNS name only resolvable on a VPN.
Request timed outA firewall, a slow cluster, or a timeout that’s too short — raise Request timeout under Advanced.
The server did not answer with JSONThe URL points at something else — Kibana (port 5601) instead of Elasticsearch (9200), or a login page.
TLS errorSee below.

Self-signed or private certificates

  • Choose the cluster’s Custom CA certificate (http_ca.crt in an Elasticsearch 8 installation), or
  • paste the SHA-256 fingerprint Elasticsearch 8 printed on first start (under Advanced), or
  • for a throwaway local cluster only, untick Verify TLS certificate.

AWS SigV4 errors

kabanos uses your normal AWS setup. Check that aws sts get-caller-identity works in Terminal with the same profile; for SSO, run aws sso login first. Make sure Region and Service (es or aoss) match the endpoint.

“Unknown variable {{x}}”

The request uses a placeholder that isn’t defined. In the workspace, pick an environment that defines it (Env). In a routine, add it to the routine’s Variables, or make sure the step that captures it ran first.

A write was blocked or asked for confirmation

That’s the connection’s safety settings at work: Read-only mode blocks writes, Production asks first. Change them on the Connections screen. See Privacy & safety.

Previews in the Aggregations tab are slow

Turn on Fast (sampled) for large indices, or turn off Live preview and press Run when you’re ready. See Aggregation pipelines.

Still stuck?

Open an issue on GitHub with the error message and your Elasticsearch or OpenSearch version — never include passwords or API keys.