mirror of
https://github.com/elastic/kibana.git
synced 2025-04-24 09:48:58 -04:00
* Reduce permissions. * Change permissions back. * Reducing permissions on fleet_enroll role - 'write', 'create_index' -> 'auto_configure', 'create_doc' * Remove indices:admin/auto_create from privileges.
This commit is contained in:
parent
55ff85aeb5
commit
a936fe67a6
4 changed files with 10 additions and 53 deletions
|
@ -22,17 +22,8 @@ export async function generateOutputApiKey(
|
|||
cluster: ['monitor'],
|
||||
index: [
|
||||
{
|
||||
names: [
|
||||
'logs-*',
|
||||
'metrics-*',
|
||||
'traces-*',
|
||||
'.ds-logs-*',
|
||||
'.ds-metrics-*',
|
||||
'.ds-traces-*',
|
||||
'.logs-endpoint.diagnostic.collection-*',
|
||||
'.ds-.logs-endpoint.diagnostic.collection-*',
|
||||
],
|
||||
privileges: ['write', 'create_index', 'indices:admin/auto_create'],
|
||||
names: ['logs-*', 'metrics-*', 'traces-*', '.logs-endpoint.diagnostic.collection-*'],
|
||||
privileges: ['auto_configure', 'create_doc'],
|
||||
},
|
||||
],
|
||||
},
|
||||
|
|
|
@ -192,17 +192,8 @@ async function putFleetRole(callCluster: CallESAsCurrentUser) {
|
|||
cluster: ['monitor', 'manage_api_key'],
|
||||
indices: [
|
||||
{
|
||||
names: [
|
||||
'logs-*',
|
||||
'metrics-*',
|
||||
'traces-*',
|
||||
'.ds-logs-*',
|
||||
'.ds-metrics-*',
|
||||
'.ds-traces-*',
|
||||
'.logs-endpoint.diagnostic.collection-*',
|
||||
'.ds-.logs-endpoint.diagnostic.collection-*',
|
||||
],
|
||||
privileges: ['write', 'create_index', 'indices:admin/auto_create'],
|
||||
names: ['logs-*', 'metrics-*', 'traces-*', '.logs-endpoint.diagnostic.collection-*'],
|
||||
privileges: ['auto_configure', 'create_doc'],
|
||||
},
|
||||
],
|
||||
},
|
||||
|
|
|
@ -60,17 +60,8 @@ export default function (providerContext: FtrProviderContext) {
|
|||
cluster: ['monitor', 'manage_api_key'],
|
||||
indices: [
|
||||
{
|
||||
names: [
|
||||
'logs-*',
|
||||
'metrics-*',
|
||||
'traces-*',
|
||||
'.ds-logs-*',
|
||||
'.ds-metrics-*',
|
||||
'.ds-traces-*',
|
||||
'.logs-endpoint.diagnostic.collection-*',
|
||||
'.ds-.logs-endpoint.diagnostic.collection-*',
|
||||
],
|
||||
privileges: ['write', 'create_index', 'indices:admin/auto_create'],
|
||||
names: ['logs-*', 'metrics-*', 'traces-*', '.logs-endpoint.diagnostic.collection-*'],
|
||||
privileges: ['auto_configure', 'create_doc'],
|
||||
allow_restricted_indices: false,
|
||||
},
|
||||
],
|
||||
|
|
|
@ -62,15 +62,8 @@ export default function (providerContext: FtrProviderContext) {
|
|||
cluster: ['monitor', 'manage_api_key'],
|
||||
indices: [
|
||||
{
|
||||
names: [
|
||||
'logs-*',
|
||||
'metrics-*',
|
||||
'traces-*',
|
||||
'.ds-logs-*',
|
||||
'.ds-metrics-*',
|
||||
'.ds-traces-*',
|
||||
],
|
||||
privileges: ['write', 'create_index', 'indices:admin/auto_create'],
|
||||
names: ['logs-*', 'metrics-*', 'traces-*'],
|
||||
privileges: ['create_doc', 'indices:admin/auto_create'],
|
||||
allow_restricted_indices: false,
|
||||
},
|
||||
],
|
||||
|
@ -101,17 +94,8 @@ export default function (providerContext: FtrProviderContext) {
|
|||
cluster: ['monitor', 'manage_api_key'],
|
||||
indices: [
|
||||
{
|
||||
names: [
|
||||
'logs-*',
|
||||
'metrics-*',
|
||||
'traces-*',
|
||||
'.ds-logs-*',
|
||||
'.ds-metrics-*',
|
||||
'.ds-traces-*',
|
||||
'.logs-endpoint.diagnostic.collection-*',
|
||||
'.ds-.logs-endpoint.diagnostic.collection-*',
|
||||
],
|
||||
privileges: ['write', 'create_index', 'indices:admin/auto_create'],
|
||||
names: ['logs-*', 'metrics-*', 'traces-*', '.logs-endpoint.diagnostic.collection-*'],
|
||||
privileges: ['auto_configure', 'create_doc'],
|
||||
allow_restricted_indices: false,
|
||||
},
|
||||
],
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue