# Cannot restore index \[.security-7\]

**URL:** <https://discuss.elastic.co/t/cannot-restore-index-security-7/327473>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, snapshot-and-restore\
**Created:** [March 10, 2023, 8:28pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473 "2023-03-10T20:28:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Verdugo\_Gonzalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/verdugo_gonzalo/32/37680_2.png) [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Post date:** [March 10, 2023, 8:28pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/1 "2023-03-10T20:28:33Z")

</div>

Hello everyone,

I'm trying to migrate all my users from my old 7.9 cluster to a new 8.5 cluster.

I was reviewing the documentation and proceeded to take a snapshot of the security indexes of my old cluster to be able to do a restore in my new cluster, at first glance it sounds easy... but no.

I have created a repository where the old cluster leaves its snapshot and the new cluster can take them.

```auto
GET _snapshot
{
  "test": {
    "type": "fs",
    "settings": {
      "location": "/elastic_backups/migracion-snap"
    }
  }
}

```

```auto
GET _cat/snapshots
snap1 test SUCCESS 1677856088 15:08:08 1677856090 15:08:10 1.6s 1 1 0 1

```

At first glance, everything seems to be ready to perform a restore to said snapshot.

```auto
POST _snapshot/test/snap1/_restore
{
  "indices": ".security*",
  "ignore_unavailable": true,
  "include_global_state": false,
  "include_aliases": false
}

```

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "snapshot_restore_exception",
        "reason": "[test:snap1/dj3QZOk6RiiM8RSHaljugQ] cannot restore index [.security-7] because an open index with same name already exists in the cluster. Either close or delete the existing index or restore the index under a different name by providing a rename pattern and replacement name"
      }
    ],
    "type": "snapshot_restore_exception",
    "reason": "[test:snap1/dj3QZOk6RiiM8RSHaljugQ] cannot restore index [.security-7] because an open index with same name already exists in the cluster. Either close or delete the existing index or restore the index under a different name by providing a rename pattern and replacement name"
  },
  "status": 500
}

```

I try to delete or close the index

```auto
DELETE .security-7
{
  "error": {
    "root_cause": [
      {
        "type": "security_exception",
        "reason": "action [indices:admin/delete] is unauthorized for user [elastic] with effective roles [superuser] on restricted indices [.security-7], this action is granted by the index privileges [delete_index,manage,all]"
      }
    ],
    "type": "security_exception",
    "reason": "action [indices:admin/delete] is unauthorized for user [elastic] with effective roles [superuser] on restricted indices [.security-7], this action is granted by the index privileges [delete_index,manage,all]"
  },
  "status": 403
}

```

```auto
POST .security-7/_close
{
  "error": {
    "root_cause": [
      {
        "type": "security_exception",
        "reason": "action [indices:admin/close] is unauthorized for user [elastic] with effective roles [superuser] on restricted indices [.security-7], this action is granted by the index privileges [manage_follow_index,manage,all]"
      }
    ],
    "type": "security_exception",
    "reason": "action [indices:admin/close] is unauthorized for user [elastic] with effective roles [superuser] on restricted indices [.security-7], this action is granted by the index privileges [manage_follow_index,manage,all]"
  },
  "status": 403
}

```

I also clarify that I create a user with all the roles, create new roles with `[manage_follow_index,manage,all]` but I was not successful.

If someone please has some documentation to be able to perform a clean migration from an old cluster to a new one, I would be very grateful if you share it with me.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 11, 2023, 3:56pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/2 "2023-03-11T15:56:18Z")

</div>

To work on the restricted indices you need to create a special role see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv)

`"allow_restricted_indices": true`

> Restricted indices are a special category of indices that are used internally to store configuration data and should not be directly accessed. Only internal system roles should normally grant privileges over the restricted indices. **Toggling this flag is very strongly discouraged because it could effectively grant unrestricted operations on critical data, making the entire system unstable or leaking sensitive information.** If however, for administrative purposes, you need to create a role with privileges covering restricted indices, you must set this field to `true` (default is `false`), and then the `names` field will cover the restricted indices as well.

Also I am pretty sure you do not actually need to restore that index into your new cluster as it is more of a "definitions" index not an updated index if that makes sense.

---

<div class="post-metadata">

**Author:** ![Verdugo\_Gonzalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/verdugo_gonzalo/32/37680_2.png) [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Post date:** [March 13, 2023, 2:07pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/3 "2023-03-13T14:07:41Z")

</div>

Thank you very much for your reply. I'm going to try today

> [@stephenb](#):
>
> To work on the restricted indices you need to create a special role see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-indices-priv)
> 
> `"allow_restricted_indices": true`

If this is not necessary, how can I migrate my users?

> [@stephenb](#):
>
> Also I am pretty sure you do not actually need to restore that index into your new cluster as it is more of a "definitions" index not an updated index if that makes sense.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 13, 2023, 2:11pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/4 "2023-03-13T14:11:14Z")

</div>

> [@Verdugo\_Gonzalo](#):
>
> If this is not necessary, how can I migrate my users?

Apologies I do not understand....

If you want to work with restricted indices you will need that setting. Just protect that user/role and only use it when necessary.

---

<div class="post-metadata">

**Author:** ![Verdugo\_Gonzalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/verdugo_gonzalo/32/37680_2.png) [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Post date:** [March 13, 2023, 6:48pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/5 "2023-03-13T18:48:23Z")

</div>

For some reason it doesn't work

> [@stephenb](#):
>
> `"allow_restricted_indices": true`

`GET _security/role/SUPERMAN`

```auto
{
  "SUPERMAN": {
    "cluster": [
      "all"
    ],
    "indices": [
      {
        "names": [
          "*"
        ],
        "privileges": [
          "all",
          "manage",
          "manage_follow_index"
        ],
        "field_security": {
          "grant": [
            "*"
          ],
          "except": []
        },
        "allow_restricted_indices": false
      }
    ],
    "applications": [
      {
        "application": "kibana-.kibana",
        "privileges": [
          "space_all"
        ],
        "resources": [
          "space:default"
        ]
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  }
}

```

`POST .security-7/_close`

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "security_exception",
        "reason": "action [indices:admin/close] is unauthorized for user [gverdugo] with effective roles [SUPERMAN] on restricted indices [.security-7], this action is granted by the index privileges [manage_follow_index,manage,all]"
      }
    ],
    "type": "security_exception",
    "reason": "action [indices:admin/close] is unauthorized for user [gverdugo] with effective roles [SUPERMAN] on restricted indices [.security-7], this action is granted by the index privileges [manage_follow_index,manage,all]"
  },
  "status": 403
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 13, 2023, 7:18pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/6 "2023-03-13T19:18:01Z")

</div>

Try

```auto
        "names": [
          "*",
          ".*" <!--- This 
        ],

```

---

<div class="post-metadata">

**Author:** ![Verdugo\_Gonzalo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/verdugo_gonzalo/32/37680_2.png) [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Post date:** [March 13, 2023, 9:39pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/7 "2023-03-13T21:39:19Z")

</div>

I omitted that index too, thank you very much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2023, 9:39pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473/8 "2023-04-10T21:39:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
