Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Granting kibana_system reserved role access to "all" privileges to .preview.alerts* index #80746

Merged
merged 1 commit into from
Nov 18, 2021

Conversation

dplumlee
Copy link
Contributor

Required for: elastic/kibana#116374

Summary

An extension of #76624. Adding for the new rule preview feature that utilizes alerts as data and a reserved index to write alerts. We are writing to a separate index than normal alerts so they won't show up with standard .alerts* queries, but still need the same permissions as "normal" alert indices

@dplumlee dplumlee added >enhancement :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC v8.0.0 Team:Security Meta label for security team external-contributor Pull request authored by a developer outside the Elasticsearch team labels Nov 15, 2021
@dplumlee dplumlee self-assigned this Nov 15, 2021
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

Copy link

@ecezalp ecezalp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member

@ywangd ywangd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@dplumlee dplumlee merged commit 2fe10e2 into master Nov 18, 2021
@dplumlee dplumlee deleted the alerts-as-data-rule-preview-index branch November 18, 2021 01:17
@dplumlee dplumlee added the auto-backport Automatically create backport pull requests when merged label Nov 18, 2021
ywangd pushed a commit to ywangd/elasticsearch that referenced this pull request Nov 18, 2021
@ywangd
Copy link
Member

ywangd commented Nov 18, 2021

8.0 Backport PR: #80861

@dplumlee Is it 8.0 only, i.e. Does it need to be backported to 7.16?

elasticsearchmachine pushed a commit that referenced this pull request Nov 19, 2021
…80746) (#80861)

Co-authored-by: Davis Plumlee <56367316+dplumlee@users.noreply.github.com>
@dplumlee
Copy link
Contributor Author

@ywangd just 8.0, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
auto-backport Automatically create backport pull requests when merged >enhancement external-contributor Pull request authored by a developer outside the Elasticsearch team :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team v8.0.0-rc1 v8.1.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

6 participants