# Automatically create role based on index

**URL:** <https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 16, 2019, 3:48pm UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693 "2019-09-16T15:48:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sthomps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sthomps/32/54275_2.png) [@sthomps](https://discuss.elastic.co/u/sthomps)\
**Post date:** [September 16, 2019, 3:48pm UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693/1 "2019-09-16T15:48:47Z")

</div>

Hi,

In my setup I'll be creating indexes where the index is the id = an associated group of applications.  
This id will be in an LDAP tree where the user has access to a # of id's.

Is there a way to automatically setup/create an READ only index role when a new index is created in ES?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 25, 2019, 9:38am UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693/2 "2019-09-25T09:38:27Z")

</div>

> [@sthomps](#):
>
> In my setup I'll be creating indexes where the index is the id = an associated group of applications.  
> This id will be in an LDAP tree where the user has access to a # of id's.

Apologies, but I'm not sure I follow this. Could you try to elaborate or add a more concrete example ?

> [@sthomps](#):
>
> Is there a way to automatically setup/create an READ only index role when a new index is created in ES?

If you mean internally to elasticsearch, no. There is no functionality to trigger role creation based on index creation and there is no template option for roles that would take into consideration the index name. One possibility might be to have a watch with a [short trigger](https://www.elastic.co/guide/en/elastic-stack-overview/current/trigger-schedule.html) that would perform a [search](https://www.elastic.co/guide/en/elastic-stack-overview/current/input-search.html) as input and then use the [webhook action](https://www.elastic.co/guide/en/elastic-stack-overview/current/actions-webhook.html) to call the [Create Role API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html) to add the role you want. I haven't done something similar before but it looks possible.

---

<div class="post-metadata">

**Author:** ![sthomps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sthomps/32/54275_2.png) [@sthomps](https://discuss.elastic.co/u/sthomps)\
**Post date:** [September 25, 2019, 4:33pm UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693/3 "2019-09-25T16:33:38Z")

</div>

As an example:

elasticsearch indexes = [1,2,3]

**LDAP**  
Search Base: ou=groups,dc=com  
Search Filter: (member=cn=sthomps,ou=users,dc=com)

**LDAP Results**  
cn=1,dc=com  
cn=2,dc=com

The user will be authenticated via SAML but authorized via LDAP. When they login, they should only be able to view indexes: 1 & 2 - not 3.

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [September 26, 2019, 1:25pm UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693/4 "2019-09-26T13:25:14Z")

</div>

Hi @sthomps,

I think you could achieve your use case by implementing a custom role provider and having a role mapping configured to use role templates.

- First, you need to use the role mapping API to assign roles to the user.  
Here you can use the `role-template` which can make use of the [user fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/role-mapping-resources.html#_user_fields) and generate the role names dynamically.  
For more details check:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role-mapping.html#\_role\_templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role-mapping.html#_role_templates)  
In your case, the role template could generate based on `cn` the role names like `1-read`, `2-read`

- Then you need to write a security extension and implement a custom role provider.  
This allows you to define what the role is. The role names you would receive would be the ones generated dynamically as mentioned above.  
[https://www.elastic.co/guide/en/elastic-stack-overview/7.x/custom-roles-authorization.html#implementing-custom-roles-provider](https://www.elastic.co/guide/en/elastic-stack-overview/7.x/custom-roles-authorization.html#implementing-custom-roles-provider)  
For example, the role descriptor that you generate for a user having roles `1-read`, `2-read` as

```auto
{
  "indices": [
    {
      "names": ["1", "2"],
      "privileges": ["read"]
    }
  ]
}

```

You can check out the blog on how to write a custom extension and a custom role provider

> **[How to Develop Your Own Security Extensions and Custom Realms for Elasticsearch](https://www.elastic.co/blog/how-to-develop-your-own-security-extensions-and-custom-realms-for-elasticsearch)**
>
> Learn how to build and deploy your own X-Pack security extensions and custom realms for Elasticsearch 6.3

Hope this helps.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2019, 1:34pm UTC](https://discuss.elastic.co/t/automatically-create-role-based-on-index/199693/5 "2019-10-24T13:34:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
