# Add AWS Cognito to Elastic Cloud hosted Elasticsearch and self-hosted Kibana

**URL:** <https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 26, 2019, 12:36pm UTC](https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508 "2019-11-26T12:36:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![firabby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/firabby/32/58342_2.png) [@firabby](https://discuss.elastic.co/u/firabby)\
**Post date:** [November 26, 2019, 12:36pm UTC](https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508/1 "2019-11-26T12:36:50Z")

</div>

I am very new to Elastic Stack. So, please forgive my ignorance.

I am using version 7.4

What I want to achieve is,

1. Integrate AWS cognito to kibana. Cognito user-pool has two user groups. Admin and User
2. When a user signs up, he is assigned "User" role. An index is created in Elasticsearch and the user can only see data from that index.
3. When a user logs in, he gets superuser permission if he is Admin group in cognito. Otherwise he gets read only permission

What should be my approach to achieve this? Please describe a little bit so that a noob like me can understand better.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 26, 2019, 1:08pm UTC](https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508/2 "2019-11-26T13:08:46Z")

</div>

> [@firabby](#):
>
> Integrate AWS cognito to kibana. Cognito user-pool has two user groups. Admin and User

If by "integrate" you mean "use AWS Cognito to authenticate to the Elastic Stack" then you should start by reading about OpenID Connect and see our guide on how to configure OpenID Connect with the Elastic Stack in [Configure Elasticsearch for OpenID Connect authentication | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/oidc-guide-authentication.html)

> [@firabby](#):
>
> When a user signs up, he is assigned "User" role. An index is created in Elasticsearch

The first part happens in Cognito so I guess you need to define a default configuration so that all new users end up in the `User` group in Cognito. For the second part there is no out of the box solution as far as I know, you would have to come up with something yourself.

> [@firabby](#):
>
> and the user can only see data from that index.

This is something you can set up quite easily with templated role mappings. You would need

1. one role per index which would give read permission to that index, see [Create or update roles API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html)
2. A templated role mapping that would give each user the necessary role based on their username ( which is also the index name as above ) , see [Create or update role mappings API | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/security-api-put-role-mapping.html) for more details.

> [@firabby](#):
>
> When a user logs in, he gets superuser permission if he is Admin group in cognito. Otherwise he gets read only permission

Create an extra role mapping that would map the `Admin` group value to a `superuser` role in Elasticsearch, see [Configuring role mappings | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/oidc-role-mapping.html) for more details.

I would also like to point out that the `1 index per user` approach is not the only applicable one for authorization, you can and should look into [Document Level Security](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/document-level-security.html) and [Field Level Security](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/field-level-security.html) that might allow you more granular control without creating new indices for each of your users.

Hope this helps as a starting point

---

<div class="post-metadata">

**Author:** ![firabby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/firabby/32/58342_2.png) [@firabby](https://discuss.elastic.co/u/firabby)\
**Post date:** [November 26, 2019, 1:32pm UTC](https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508/3 "2019-11-26T13:32:51Z")

</div>

Thanks a lot for such a detail answer. I will seek further help if needed. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2019, 1:32pm UTC](https://discuss.elastic.co/t/add-aws-cognito-to-elastic-cloud-hosted-elasticsearch-and-self-hosted-kibana/209508/4 "2019-12-24T13:32:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
