Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Expand fleet-server privileges to include restricted indices #77531

Merged
merged 2 commits into from
Sep 10, 2021

Conversation

ywangd
Copy link
Member

@ywangd ywangd commented Sep 10, 2021

Since #74212, all system indices are now treated as restricted indices,
which includes the fleet system indices. As a result, the fleet-server
server account needs privileges to access restricted indices under the
fleet-* namespace.

Relates: #74212

Since elastic#74212, all system indices are now treated as restricted indices,
which includes the fleet system indices. As a result, the fleet-server
server account needs privileges to access restricted indices under the
fleet-* namespace.

Relates: elastic#74212
@ywangd ywangd added >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC v8.0.0 labels Sep 10, 2021
@ywangd ywangd requested a review from tvernum September 10, 2021 00:18
@elasticmachine elasticmachine added the Team:Security Meta label for security team label Sep 10, 2021
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

Copy link
Contributor

@tvernum tvernum left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ywangd ywangd merged commit 28503d7 into elastic:master Sep 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
>non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team v8.0.0-alpha2
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants