### How do I configure security (authentication, authorization)?

Zipkin UI can be secured by running it behind an authenticating proxy like [Apache HTTPD](, [Nginx]( or similar. Make sure to also consult the [notes](#apache-http-as-a-zipkin-reverse-proxy) on running apache http as a reverse proxy for the UI, as it can be a bit tricky.

Note that by default, a Zipkin server runs both the UI ('/zipkin') and the span collector ('/api') endpoint. Your configuration to secure the UI should only target the UI endpoint in order to not prevent clients from ingesting span data.

