Skip to content

Conversation

naemono
Copy link
Contributor

@naemono naemono commented Oct 6, 2025

The following elastic/cloud-on-k8s#8817 is planned to be released with the ECK 3.2/Stack 9.2 release.

(replaces #3322 as it was based of the wrong branch)

Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
@naemono naemono requested a review from a team as a code owner October 6, 2025 13:50
@naemono naemono changed the title Eck enterprise password additions v2 Add documentation for managing ECK file-based password length. Oct 6, 2025
Signed-off-by: Michael Montgomery <[email protected]>
@naemono naemono changed the base branch from main to eck-3.2.0 October 6, 2025 13:53
Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
Copy link

github-actions bot commented Oct 6, 2025

Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
Copy link
Contributor

@eedugon eedugon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!
I have suggested to place the applies_to right after the heading, and not after the initial note.

Signed-off-by: Michael Montgomery <[email protected]>
@naemono naemono requested a review from pebrc October 6, 2025 18:22
Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks really good. I think we want to consider relocating this chunk of info though because it's specific to the file realm. would you consider making it an H4 under the File realm heading?

https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3339/deploy-manage/users-roles/cluster-or-deployment-auth/managed-credentials-eck#file-realm

Comment on lines 114 to 116
:::{note}
Changing these values does not update existing passwords. To rotate current credentials, refer to the [rotating credentials documentation](#k8s-rotate-credentials)
:::
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

probably ok outside of a note

Suggested change
:::{note}
Changing these values does not update existing passwords. To rotate current credentials, refer to the [rotating credentials documentation](#k8s-rotate-credentials)
:::
Changing these values does not update existing passwords. To rotate current credentials, refer to the [rotating credentials documentation](#k8s-rotate-credentials)

```

:::{note}
The ability to control the length of passwords for [file-based credentials](/deploy-manage/users-roles/cluster-or-deployment-auth/file-based.md) generated by {{eck}} requires an Enterprise license.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we want this to not be two notes in a trenchcoat

image
Suggested change
The ability to control the length of passwords for [file-based credentials](/deploy-manage/users-roles/cluster-or-deployment-auth/file-based.md) generated by {{eck}} requires an Enterprise license.
The ability to control the length of passwords for [file-based credentials](/deploy-manage/users-roles/cluster-or-deployment-auth/file-based.md) generated by {{eck}} requires an Enterprise license.
:::

Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(+ approving to unblock)

(oops, guess this tab was old and edu already got you)

Signed-off-by: Michael Montgomery <[email protected]>
Signed-off-by: Michael Montgomery <[email protected]>
@naemono
Copy link
Contributor Author

naemono commented Oct 7, 2025

looks really good. I think we want to consider relocating this chunk of info though because it's specific to the file realm. would you consider making it an H4 under the File realm heading?

https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3339/deploy-manage/users-roles/cluster-or-deployment-auth/managed-credentials-eck#file-realm

@shainaraskas , @pebrc and I spoke, and though moving all of this under file realm maybe wasn't the best approach being that the file realm section also explains to customers how to create their own users, which password-length doesn't really apply to. We instead thought creating a new ECK auto-generate credentials section with to sub-sections for 1) rotating and 2) controlling length made more sense. Let us know your thoughts. Thanks.

Signed-off-by: Michael Montgomery <[email protected]>
Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks - this grouping now makes more sense to me. added some additional comments that could clarify things a little further (and I think you have the wrong version # in there)

Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks - this grouping now makes more sense to me. added some additional comments that could clarify things a little further (and I think you have the wrong version # in there)

Signed-off-by: Michael Montgomery <[email protected]>
Copy link
Collaborator

@shainaraskas shainaraskas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nice!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants