Skip to content

Conversation

@akshraj-crest
Copy link
Contributor

@akshraj-crest akshraj-crest commented Nov 14, 2025

PR Description:

This PR focuses on the short term solution which add the logs-ironscales.incident-* indice under the kibana_system role with deletion privileges to prevent a failed deletion error when the index enters the deletion phase for the ILM lifecycle, in upcoming PR. As it ships transform pipeline too hence read, write permissions are also required.

Current behavior:

It shows permission issue while deleting the index.

Closes - #138093
Relates - elastic/integrations#15982

@akshraj-crest akshraj-crest requested a review from a team as a code owner November 14, 2025 12:52
@elasticsearchmachine elasticsearchmachine added v9.3.0 external-contributor Pull request authored by a developer outside the Elasticsearch team needs:triage Requires assignment of a team area label labels Nov 14, 2025
@mohitjha-elastic mohitjha-elastic added :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team Team:Cloud Security Meta label for Cloud Security team labels Nov 17, 2025
@elasticsearchmachine elasticsearchmachine removed the needs:triage Requires assignment of a team area label label Nov 17, 2025
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

@mohitjha-elastic mohitjha-elastic added >non-issue needs:triage Requires assignment of a team area label auto-backport Automatically create backport pull requests when merged v9.2.2 v8.19.8 v9.1.8 and removed needs:triage Requires assignment of a team area label labels Nov 17, 2025
@mohitjha-elastic
Copy link
Contributor

buildkite test this

Copy link

@jeramysoucy jeramysoucy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - Note: we usually would not grant the system user access to data indexes, but there is an exception for logs-* patterns (documented here).

Could you update the "kibana_system privileges" spreadsheet? I'll DM you a link. I'll DM @mohitjha-elastic to see how to proceed.

@mohitjha-elastic
Copy link
Contributor

@jeramysoucy
Thanks for sharing the spreadsheet. I have updated the details there.
Here is the draft PR for the IRONSCALES intergration - elastic/integrations#15982

Copy link

@jeramysoucy jeramysoucy left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the details and for updating the spreadsheet!

@mohitjha-elastic
Copy link
Contributor

buildkite test this

@mohitjha-elastic
Copy link
Contributor

buildkite test this please

@mohitjha-elastic mohitjha-elastic merged commit 1ff2b5d into elastic:main Nov 24, 2025
41 of 42 checks passed
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
akshraj-crest added a commit to akshraj-crest/elasticsearch that referenced this pull request Nov 24, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
(cherry picked from commit 1ff2b5d)
mohitjha-elastic added a commit that referenced this pull request Nov 25, 2025
…138487)

* Add ILM index for delete previlege

* Add changelog entry

---------


(cherry picked from commit 1ff2b5d)

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
mohitjha-elastic added a commit that referenced this pull request Nov 25, 2025
…138486)

* Add ILM index for delete previlege

* Add changelog entry

---------


(cherry picked from commit 1ff2b5d)

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
mohitjha-elastic added a commit that referenced this pull request Nov 25, 2025
…138485)

* Add ILM index for delete previlege

* Add changelog entry

---------


(cherry picked from commit 1ff2b5d)

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
ncordon pushed a commit to ncordon/elasticsearch that referenced this pull request Nov 26, 2025
)

* Add ILM index for delete previlege

* Add changelog entry

---------

Co-authored-by: Mohit Jha <138874484+mohitjha-elastic@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Automatically create backport pull requests when merged external-contributor Pull request authored by a developer outside the Elasticsearch team >non-issue :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Cloud Security Meta label for Cloud Security team Team:Security Meta label for security team v8.19.8 v9.1.8 v9.2.2 v9.3.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants