Skip to content

Add permissions for apm_user for datastreams #72739

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 5, 2021

Conversation

simitt
Copy link
Contributor

@simitt simitt commented May 5, 2021

As described in #72737 we would like to get this fix into 7.13. @henningandersen could you please take a look if that's feasible?

cc @elastic/apm-server @kobelb

@elasticsearchmachine elasticsearchmachine added the external-contributor Pull request authored by a developer outside the Elasticsearch team label May 5, 2021
@simitt simitt added the v7.13.0 label May 5, 2021
@henningandersen henningandersen added :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC v8.0.0 labels May 5, 2021
@elasticmachine elasticmachine added the Team:Security Meta label for security team label May 5, 2021
@elasticmachine
Copy link
Collaborator

Pinging @elastic/es-security (Team:Security)

Copy link
Contributor

@henningandersen henningandersen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@henningandersen henningandersen merged commit 34f9691 into elastic:master May 5, 2021
henningandersen pushed a commit that referenced this pull request May 5, 2021
Based on recent conversations around data streams for APM, there is no final
decision yet that apm data streams will be created per instrumented Service.
If datastreams are not created per service, the current pattern for the apm_user
permissions need to be adapted to not only support <type>-apm.* but also
<type>-apm-*.

fixes #72737
henningandersen pushed a commit that referenced this pull request May 5, 2021
Based on recent conversations around data streams for APM, there is no final
decision yet that apm data streams will be created per instrumented Service.
If datastreams are not created per service, the current pattern for the apm_user
permissions need to be adapted to not only support <type>-apm.* but also
<type>-apm-*.

fixes #72737
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
>enhancement external-contributor Pull request authored by a developer outside the Elasticsearch team :Security/Authorization Roles, Privileges, DLS/FLS, RBAC/ABAC Team:Security Meta label for security team v7.13.0 v7.14.0 v8.0.0-alpha1
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants