# Can role be picked from yml and user from API

**URL:** <https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968>\
**Category:** Elasticsearch\
**Created:** [July 4, 2019, 7:41pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968 "2019-07-04T19:41:32Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 4, 2019, 7:41pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/1 "2019-07-04T19:41:32Z")

</div>

I am creating a user via curl and assigning a it a role which is defined in roles.yml. Is that a valid way of assigning roles? Do I have to create roles via curl also?

---

<div class="post-metadata">

**Author:** ![Juanma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanma/32/49076_2.png) [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Post date:** [July 4, 2019, 8:54pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/2 "2019-07-04T20:54:44Z")

</div>

Hello @amitavmohanty01

In my opinion roles on roles.yml is valid but is a bit painful because it doesn't let you scalate easily due the need of modify each roles.yml file.

In my opinion if you don't need really advanced roles and for easier management would be better use Kibana management UI.

If you need more advanced roles that goes beyond Kibana's security UI I would recommend to use the API.

Kibana Documentation: [https://www.elastic.co/guide/en/kibana/current/xpack-security.html](https://www.elastic.co/guide/en/kibana/current/xpack-security.html)

I hope this helps. 🙂

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 5, 2019, 5:44am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/3 "2019-07-05T05:44:47Z")

</div>

> [@amitavmohanty01](#):
>
> Is that a valid way of assigning roles?

That is valid, but I would question _why_ you would choose to do that.  
We recommend you use API for easy of maintenance, and only use files for the users + roles that absolutely have to work even when your cluster is red.

---

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 5, 2019, 3:08pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/4 "2019-07-05T15:08:47Z")

</div>

> [@TimV](#):
>
> That is valid, but I would question _why_ you would choose to do that.

The why part is very simple. When you have an orchestration tool like Puppet, it is simpler to make modifications in multiple places/servers. Invoking a REST API will require me to have another server from which I make the REST call.

---

<div class="post-metadata">

**Author:** ![Juanma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanma/32/49076_2.png) [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Post date:** [July 5, 2019, 9:35pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/5 "2019-07-05T21:35:32Z")

</div>

Mmmm You don't need a server to make a rest api call, you can do it from Kibana's Dev tools or tools like postman if you use windows in case you use linux its even easier with curl.

---

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 6, 2019, 5:53am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/6 "2019-07-06T05:53:47Z")

</div>

I absolutely understand what you are saying but probably you did not get what I am going for. When I am using a deployment tool like Puppet, I would define a role which gets applied to a server. So, let's say I have roles for all elastic components, viz. elasticsearch, Kibana, Filebeat, etc. Now, to execute the curl command, I have two options:

1. manually execute the curl command from a machine (not acceptable)
2. put the curl command as part of the deployment scripts: Let's say the curl command is part of elasticsearch setup. That will make the command execute on each elasticsearch node which does not make sense.

---

<div class="post-metadata">

**Author:** ![Juanma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanma/32/49076_2.png) [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Post date:** [July 6, 2019, 9:45am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/7 "2019-07-06T09:45:14Z")

</div>

I never worked personally with puppet, but I find hard to believe that it doesn't allow you to to use different configurations or tasks after orchestate the deployment of a number of machines, even in elasticsearch the nodes are not allways contains the same configuration etc.. I think there must be a way to execute a script after that in only one machine or even in the orchestator server.

Why would you want to use an orchestation tool for something that needs to be done only in 1 place?. You only have to change it in one place.

---

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 6, 2019, 12:54pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/8 "2019-07-06T12:54:28Z")

</div>

> [@Juanma](#):
>
> Why would you want to use an orchestation tool for something that needs to be done only in 1 place?. You only have to change it in one place.

If I were not to use a configuration management tool for it, how do you suggest that I should do it?

---

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 6, 2019, 12:57pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/9 "2019-07-06T12:57:13Z")

</div>

> [@Juanma](#):
>
> I think there must be a way to execute a script after that in only one machine or even in the orchestator server.

How would you automate that? The elasticsearch machines will be segregated by roles: master, indexer etc. How will you pick which machine to run the one-time script on?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 6, 2019, 1:03pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/10 "2019-07-06T13:03:46Z")

</div>

When setting up an evironment there are often tasks that you need to perform once for a group of hosts so I would be surprised if Puppet (which I have never used) does not support this. That is however a question better suited for a Puppet forum.

---

<div class="post-metadata">

**Author:** ![Juanma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanma/32/49076_2.png) [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Post date:** [July 6, 2019, 1:09pm UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/11 "2019-07-06T13:09:24Z")

</div>

Hi

Depending of your infraestructure I can think this methods:

- In the same script have a list of node and a little function which check the health before pick one in order to make the rest call.

- Just put the client nodes in front of a LB and point the script to the LB.

As always in elastic it depends, you also must be aware of your architecture, if you have client nodes just figure out a way to ensure that the REST call arrives to any of them with for example any of the provided methods above.

The only nodes which I wouldn't send requests are the master dedicated.

I hope this helps 🙂

---

<div class="post-metadata">

**Author:** ![amitavmohanty01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amitavmohanty01/32/58017_2.png) [@amitavmohanty01](https://discuss.elastic.co/u/amitavmohanty01)\
**Post date:** [July 9, 2019, 4:49am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/12 "2019-07-09T04:49:03Z")

</div>

Thanks for the inputs @Christian_Dahlqvist and @Juanma. I will follow up with Puppet folks to find out more.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 9, 2019, 6:02am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/13 "2019-07-09T06:02:05Z")

</div>

Logically speaking, an Elasticsearch _cluster_ is a thing to manage. It is made up of _nodes_ that also need to be managed, but there are many things that you might want to manage as a "thing" in a cluster not per-node.

Roles are one such thing, but so are index templates, scripts and cluster settings.

Even if you put roles into a per-node file, you will eventually run into problems that cannot be solved by simply treating a cluster as a series of nodes. You will need to find a way to use puppet (or if necessary some other tool) to manage a _cluster_.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 6:02am UTC](https://discuss.elastic.co/t/can-role-be-picked-from-yml-and-user-from-api/188968/14 "2019-08-06T06:02:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
