Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve documentation for package distributions folder access rights #29578

Closed
jstrassb opened this issue Apr 18, 2018 · 2 comments
Closed

Improve documentation for package distributions folder access rights #29578

jstrassb opened this issue Apr 18, 2018 · 2 comments
Labels
:Delivery/Packaging RPM and deb packaging, tar and zip archives, shell and batch scripts >docs General docs changes Team:Delivery Meta label for Delivery team

Comments

@jstrassb
Copy link

Setting up the Elastic Stack https://www.elastic.co/guide/en/elasticsearch/reference/current/settings.html mentions that for the package distributions, the config directory location defaults to /etc/elasticsearch and this can be changed. When setting up security with keystore (https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-settings.html) and following 'All commands here should be run as the user which will run Elasticsearch.' the elasticsearch user does not have access rights to /etc/elasticsearch as intended and explained in #26412

I would propose to state clearer that for package distributions special care must be taken, e.g. changing the default path or running bin/elasticsearch-keystore create with elevated rights in this case.

@jstrassb jstrassb added the >docs General docs changes label Apr 18, 2018
@jasontedor jasontedor added the :Delivery/Packaging RPM and deb packaging, tar and zip archives, shell and batch scripts label Apr 18, 2018
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-core-infra

@rjernst
Copy link
Member

rjernst commented May 20, 2018

The changes in #26412 were explicitly to fix this problem of access writes. By using setgid, all files under elasticsearch will have write permission for the elasticsearch user (through group write). Additionally, as of 6.3.0, creating the keystore will no longer be necessary directly, as it is created on package installation.

Given those points, I'm going to close this as I don't think there is anything necessary to change in the docs.

@rjernst rjernst closed this as completed May 20, 2018
@mark-vieira mark-vieira added the Team:Delivery Meta label for Delivery team label Nov 11, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Delivery/Packaging RPM and deb packaging, tar and zip archives, shell and batch scripts >docs General docs changes Team:Delivery Meta label for Delivery team
Projects
None yet
Development

No branches or pull requests

5 participants