# A custom role which contains all privileges is not updated after changing to read only role

**URL:** <https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [March 23, 2021, 10:13pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147 "2021-03-23T22:13:14Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 23, 2021, 10:13pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/1 "2021-03-23T22:13:14Z")

</div>

Please help to configure how a custom role which contains all privileges is not updated after changing to read only role.

Steps to reproduce:

1. First, create a custom role which contains all privileges  
curl -XPUT [http://server:9200/security/role/CUSTOM\_ROLE](http://server:9200/security/role/CUSTOM_ROLE) -H 'Content-Type: application/json' -d'  
{  
"cluster" : [  
"monitor",  
"manage\_index\_templates",  
"cluster:admin/xpack/monitoring/bulk",  
"manage\_saml",  
"manage\_token",  
"manage\_oidc",  
"cluster:admin/xpack/security/api\_key/invalidate",  
"grant\_api\_key",  
"cluster:admin/xpack/security/privilege/builtin/get",  
"delegate\_pki",  
"cluster:admin/ilm/get",  
"cluster:admin/ilm/put",  
"manage\_ml",  
"cluster:admin/analyze"  
],

"indices" : [  
{  
"names" : [  
".kibana\*",  
".reporting-_"  
],  
"privileges" : [  
"all"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".monitoring-_"  
],  
"privileges" : [  
"read",  
"read\_cross\_cluster"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".management-beats"  
],  
"privileges" : [  
"create\_index",  
"read",  
"write"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".ml-anomalies\*",  
".ml-notifications\*",  
".ml-stats-_"  
],  
"privileges" : [  
"read"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".ml-annotations_"  
],  
"privileges" : [  
"read",  
"write"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".apm-agent-configuration"  
],  
"privileges" : [  
"all"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".apm-custom-link"  
],  
"privileges" : [  
"all"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
"apm-_"  
],  
"privileges" : [  
"read",  
"read\_cross\_cluster"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
"_"  
],  
"privileges" : [  
"view\_index\_metadata",  
"monitor"  
],  
"allow\_restricted\_indices" : false  
},  
{  
"names" : [  
".logs-endpoint.diagnostic.collection-\*"  
],  
"privileges" : [  
"read"  
],  
"allow\_restricted\_indices" : false  
}  
],  
"applications" : [  
{  
"application" : "kibana-.kibana",  
"privileges" : [  
"feature\_discover.all",  
"feature\_dashboard.all",  
"feature\_canvas.all",  
"feature\_maps.all",  
"feature\_ml.all",  
"feature\_graph.all",  
"feature\_visualize.all"  
],  
"resources" : [  
"space:default"  
]  
}  
],  
"run\_as" : ["\_anonymous"],  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
'

1. Assign this role to anonymous user in elasticsearch.yml file

- xpack.security.authc.anonymous.roles: CUSTOM\_ROLE

1. Restart Elasticsearch
2. Log into Kibana to verify all features are displayed.
3. Now update this role to Read Only role  
curl -X PUT [http://server:9200/security/role/CUSTOM\_ROLE](http://server:9200/security/role/CUSTOM_ROLE) -H 'Content-Type: application/json' -d'  
{  
"cluster" : ,  
"indices" : [  
{  
"names" : ,  
"privileges" : [  
"view\_index\_metadata",  
"read"  
],  
"field\_security" : {  
"grant" : [  
"\*"  
],  
"except" :   
},  
"allow\_restricted\_indices" : false  
}  
],  
"applications" : [  
{  
"application" : "kibana-.kibana",  
"privileges" : [  
"feature\_discover.all",  
"feature\_dashboard.all",  
"feature\_canvas.all",  
"feature\_maps.all",  
"feature\_ml.all",  
"feature\_graph.all",  
"feature\_visualize.all"  
],  
"resources" : [  
"space:default"  
]  
}  
],  
"run\_as" : ["anonymous"],  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
'
4. Restart Elasticsearch
5. Login back to Kibana to verify that there should be ONLY read only Kibana features displayed (NO Stack Management feature)

\*\*\* Actual Results: ALL features of Kibana are displayed. A read only role seems not updated.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 24, 2021, 2:41am UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/2 "2021-03-24T02:41:24Z")

</div>

> [@thiton](#):
>
> Login back to Kibana to verify that there should be ONLY read only Kibana features displayed (NO Stack Management feature)

What do you mean by "login" to Kibana?  
Do you have a login page on Kibana in which you enter credentials, or do you just mean "start a new session" ?

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 24, 2021, 4:07pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/3 "2021-03-24T16:07:23Z")

</div>

Hi Tim,  
Thanks so much for response.

I mean login to Kibana as anonymous user. There is no login page since xpack.security.enable is set to false in kibana.yml file. It is purpose of requirement. Thanks again.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 25, 2021, 5:00am UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/4 "2021-03-25T05:00:16Z")

</div>

> [@thiton](#):
>
> xpack.security.enable is set to false in kibana.yml

This tells Kibana that you don't want security. So ...

> [@thiton](#):
>
> ALL features of Kibana are displayed

If you tell Kibana to disable security, then it really does, and the UI will not reflect the user's privileges because you have asked Kibana to disable all access checks.

If you want anonymous access in Kibana, then you need to use [Kibana's anonymous access feature](https://www.elastic.co/guide/en/kibana/7.11/kibana-authentication.html#anonymous-authentication) instead. That requires 7.11 or higher.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 25, 2021, 4:35pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/5 "2021-03-25T16:35:11Z")

</div>

Thanks so much for your help, Tim.

Per your advise, I try to use Kibana's anonymous access by setting as below in kibana.yml file but I get error {reason[\](file:///)":[\](file:///)"action [cluster:monitor/xpack/info] is unauthorized for user [anonymous][\](file:///)"},[\](file:///)"status[\](file:///)":403}"}. Please help. Thanks again.

xpack.security.authc.providers:  
anonymous.anonymous1:  
order: 0  
credentials: "elasticsearch\_anonymous\_user"

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 25, 2021, 11:23pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/6 "2021-03-25T23:23:56Z")

</div>

You need to provide more information.

Where did you see that error?  
What were you trying to do?  
What other messages are in the logs?

It is almost impossible for anyone to help you based purely on a single error message with zero context.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 27, 2021, 12:11am UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/7 "2021-03-27T00:11:51Z")

</div>

Hi Tim,

Sorry for the late reply. Many thanks for your response.

1. Where did you see that error?

- It is returned in output 'kibana.out' file.

1. What were you trying to do?

- My task is to allow anonymous user login to Kibana (no login page) and ONLY Kibana's Analytic features display (no Stack Management).

1. What other messages are in the logs?

- _**{"type":"log","@timestamp":"2021-03-10T19:54:10-08:00","tags":["warning","plugins","licensing"],"pid":25096,"message":"License information could not be obtained from Elasticsearch due to [security\_exception] action [cluster:monitor/xpack/info] is unauthorized for user [anonymous] :: {"path":"/\_xpack?accept\_enterprise=true","statusCode":403,"response":"{[\](file:///)"error[\](file:///)":{[\](file:///)"root\_cause[\](file:///)":[{[\](file:///)"type[\](file:///)":[\](file:///)"security\_exception[\](file:///)",[\](file:///)"reason[\](file:///)":[\](file:///)"action [cluster:monitor/xpack/info] is unauthorized for user [anonymous][\](file:///)"}],[\](file:///)"type[\](file:///)":[\](file:///)"security\_exception[\](file:///)",[\](file:///)"reason[\](file:///)":[\](file:///)"action [cluster:monitor/xpack/info] is unauthorized for user [anonymous][\](file:///)"},[\](file:///)"status[\](file:///)":403}"} error"}**_

**/** \* Here are steps to reproduce \ ***/**

1. Create a new read only custom role 'CUSTOM\_ROLE'.

curl -X PUT [http://server:9200/security/role/CUSTOM\_ROLE](http://server:9200/security/role/CUSTOM_ROLE) -H 'Content-Type: application/json' -d'  
{  
"cluster" : ,  
"indices" : [  
{  
"names" : ,  
"privileges" : [  
"view\_index\_metadata",  
"read"  
],  
"field\_security" : {  
"grant" : [  
"\*"  
],  
"except" :   
},  
"allow\_restricted\_indices" : false  
}  
],  
"applications" : [  
{  
"application" : "kibana-.kibana",  
"privileges" : [  
"feature\_discover.all",  
"feature\_dashboard.all",  
"feature\_canvas.all",  
"feature\_maps.all",  
"feature\_ml.all",  
"feature\_graph.all",  
"feature\_visualize.all"  
],  
"resources" : [  
"space:default"  
]  
}  
],  
"run\_as" : ["anonymous"],  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
'

1. Configure ElasticSearch.yml: assign this role to anonymous user

**-xpack.security.authc.anonymous.username: anonymous**

**- xpack.security.authc.anonymous.roles: CUSTOM\_ROLE**

**- xpack.security.enabled: true**

1. Configure Kibana.yml:

- Turn off security: **xpack.security.enabled: false**
- Add below commands  
\*\* xpack.security.authc.providers:\*\*  
\*\* anonymous.anonymous1:\*\*  
\*\* order: 0\*\*  
\*\* credentials: "elasticsearch\_anonymous\_user"\*\*

/\*\*\* **Actual Results** : I got error as _t_ype":"log","@timestamp":"2021-03-10T19:54:10-08:00","tags":["warning","plugins","licensing"],"pid":25096,"message":"License information could not be obtained from Elasticsearch due to [security\_exception] action [cluster:monitor/xpack/info] is unauthorized for user [anonymous] :: {"path":"/\_xpack?accept\_enterprise=true","statusCode":403,"response":"{[\](file:///)"error[\](file:///)":{[\](file:///)"root\_cause[\](file:///)":[{[\](file:///)"type[\](file:///)":[\](file:///)"security\_exception[\](file:///)",[\](file:///)"reason[\](file:///)":[\](file:///)"action [cluster:monitor/xpack/info] is unauthorized for user [anonymous][\](file:///)"}],[\](file:///)"type[\](file:///)":[\](file:///)"security\_exception[\](file:///)",[\](file:///)"reason[\](file:///)":[\](file:///)"action [cluster:monitor/xpack/info] is unauthorized for user [anonymous][\](file:///)"},[\](file:///)"status[\](file:///)":403}"} error"}\*

_/_\*\*\* Then, I tried to modify my CUSTOM\_ROLE with the full privileges as above and assign it to anonymous user. I am able to login Kibana as anonymous user without error '403'.  
After that, I convert CUSTOM\_ROLE to read\_only role as step #1 above. However, there is Stack Management feature still displayed in Kibana.

- Now, Kibana output file now returns as _**'{"type":"log","@timestamp":"2021-03-26T13:51:49-07:00","tags":["warning","plugins","monitoring","monitoring","kibana-monitoring"],"pid":27101,"message":"Error: [security\_exception] action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [\_anonymous]\n at respond (/elastic/apps/monitoring/kibana/kibana-7.11.1-linux-x86\_64/node\_modules/elasticsearch/src/lib/transport.js:349:15)\n at checkRespForFailure (/elastic/apps/monitoring/kibana/kibana-7.11.1-linux-x86\_64/node\_modules/elasticsearch/src/lib/transport.js:306:7)\n at HttpConnector. (/elastic/apps/monitoring/kibana/kibana-7.11.1-linux-x86\_64/node\_modules/elasticsearch/src/lib/connectors/http.js:173:7)\n at IncomingMessage.wrapper (/elastic/apps/monitoring/kibana/kibana-7.11.1-linux-x86\_64/node\_modules/lodash/lodash.js:4949:19)\n at IncomingMessage.emit (events.js:327:22)\n at endReadableNT (internal/streams/readable.js:1327:12)\n at processTicksAndRejections (internal/process/task\_queues.js:80:21)"}**_  
_**{"type":"log","@timestamp":"2021-03-26T13:51:49-07:00","tags":["warning","plugins","monitoring","monitoring","kibana-monitoring"],"pid":27101,"message":"Unable to bulk upload the stats payload to the local cluster"}'**_

/\*\*\* As you can see, there is no more '403' error returned but error ""Error: [security\_exception] action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [\_anonymous]\n " is still returned. Read\_Only role seems not picking up. My goals is only Analytic feature displayed in Kibana.

/\*\*\* I am not sure that I am in the right direction. Please help. Many thanks in advance for your help and time. \*\*\*/

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 29, 2021, 2:41am UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/8 "2021-03-29T02:41:04Z")

</div>

> [@thiton](#):
>
> **xpack.security.enabled: false**

Don't do that.  
You are running with security enabled in Elasticsearch, you need Kibana to have security as well.

You need to configure Elasticsearch & Kibana to have security, and then enable anonymous access in Kibana.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 29, 2021, 3:43pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/9 "2021-03-29T15:43:23Z")

</div>

Thanks so much for your help, Tim.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [March 31, 2021, 4:48pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/10 "2021-03-31T16:48:03Z")

</div>

Hi Tim,

Sorry to bother you again.

Your quote " "You need to configure Elasticsearch & Kibana to have security, and then enable anonymous access in Kibana."

May I ask that you mean I need to set ' **xpack.security.enabled: true**' in both Elasticsearch and Kibana.yml, and enable anonymous access in Kibana by setting as below in Kibana.yml ? **xpack.security.authc.providers:**  
\*\* anonymous.anonymous1:\*\*  
\*\* order: 0\*\*  
\*\* credentials: "elasticsearch\_anonymous\_user"\*\*

Thanks again for your help.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 31, 2021, 11:34pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/11 "2021-03-31T23:34:07Z")

</div>

Yes, but more explicitly you should:

1. Follow the instructions for [enabling security on the stack](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/configuring-stack-security.html)
2. After that is working, [enable Kibana anonymous access](https://www.elastic.co/guide/en/kibana/7.12/kibana-authentication.html#anonymous-authentication)

You cannot jump straight to step 2, you need to do them in that order.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [April 1, 2021, 12:22am UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/12 "2021-04-01T00:22:06Z")

</div>

Thanks Tim. I will give it a try.

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [April 1, 2021, 6:33pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/13 "2021-04-01T18:33:06Z")

</div>

Hi Tim,

Sorry to bother you again.

I follow the instructions and configure as follow:

1. Update ElasticSearch.yml file as below  
o xpack.security.enabled: true  
o xpack.security.authc.anonymous.username: \_anonymous  
o xpack.security.authc.anonymous.roles: CUSTOM\_ROLE

2. Update Kibana.yml file as below  
o elasticsearch.username: "kibana\_sytem"  
o elasticsearch.password: "xxxxxxxxx"  
o xpack.security.enabled: true  
o xpack.security.authc.providers:  
anonymous.anonymous1:  
order: 0  
credentials: "elasticsearch\_anonymous\_user"

/\*\*\* I get error as below in kibana.out file. Please advise. Many thanks again for your help.

_**FATAL Error: [config validation of [xpack.security].authc.providers]: types that failed validation:**_  
_**- [config validation of [xpack.security].authc.providers.0]: expected value of type [array] but got [null]**_  
_**- [config validation of [xpack.security].authc.providers.1]: expected a plain object value, but found [null] instead.**_

---

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [April 1, 2021, 7:12pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/14 "2021-04-01T19:12:54Z")

</div>

Hi Tim,

Please ignore my previous question. I figure out. Thanks for your help always.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2021, 7:12pm UTC](https://discuss.elastic.co/t/a-custom-role-which-contains-all-privileges-is-not-updated-after-changing-to-read-only-role/268147/15 "2021-04-29T19:12:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
