Skip to content

Commit baa4e56

Browse files
committed
extend kibana-system permissions for .entities.* indices
1 parent 953b9ef commit baa4e56

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/store/KibanaOwnedReservedRoleDescriptors.java

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -593,7 +593,11 @@ static RoleDescriptor kibanaSystem(String name) {
593593
.indices(".asset-criticality.asset-criticality-*")
594594
.privileges("create_index", "manage", "read", "write")
595595
.build(),
596-
RoleDescriptor.IndicesPrivileges.builder().indices(".entities.v1.latest.security*").privileges("read", "write").build(),
596+
RoleDescriptor.IndicesPrivileges.builder().indices(".entities.*").privileges("read", "write").build(),
597+
RoleDescriptor.IndicesPrivileges.builder()
598+
.indices(".entities.*history*")
599+
.privileges("create_index", "manage", "read", "write")
600+
.build(),
597601
// For cloud_defend usageCollection
598602
RoleDescriptor.IndicesPrivileges.builder()
599603
.indices("logs-cloud_defend.*", "metrics-cloud_defend.*")

0 commit comments

Comments
 (0)