# Creating roles with limited Kibana permissions

**URL:** <https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [June 10, 2020, 11:34am UTC](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502 "2020-06-10T11:34:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![maxdanilov](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@maxdanilov](https://discuss.elastic.co/u/maxdanilov)\
**Post date:** [June 10, 2020, 11:34am UTC](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502/1 "2020-06-10T11:34:00Z")

</div>

Hi,

I'm following this tutorial to create users with eck: [https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html)

The examples there specify roles with Elasticsearch capabilities only, but can I define a role that has limited access to Kibana features? I cannot use `kibana_admin` as that is too permissive.

For example, I need a role that has read-only access to any dashboards in Kibana (and nothing else):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a11575e8bf8b0bf7d1503073b8c4399b62fbcea9.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9b2a20b3e8ff5260d7ad76bc104ab9aabb7ab46.png)

Is it possible to define that kind of role with `eck`?

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [June 10, 2020, 3:14pm UTC](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502/2 "2020-06-10T15:14:44Z")

</div>

Yes you can create restricted roles in ECK as well. This is not a ECK specific feature, we are just exposing the [file based role management feature of Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/current/defining-roles.html#roles-management-file) here.

Restrictions on Kibana usage go into the `applications` section of the roles.yml file. This is just simple example allowing access to Dashboads and Visualizations in all spaces:

```auto
kibana_viz:
  cluster: []
  indices: []
  applications:
  - application: "kibana-.kibana"
    privileges:
    - "feature_dashboard.all"
    - "feature_visualize.all"
    resources:
    - "*"
  run_as: []
  metadata: {}
  transient_metadata:
    enabled: true

```

The way I created this example is by going through the UI creating the role I wanted and then retrieving the resulting role via the API as YAML

---

<div class="post-metadata">

**Author:** ![maxdanilov](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@maxdanilov](https://discuss.elastic.co/u/maxdanilov)\
**Post date:** [June 10, 2020, 4:01pm UTC](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502/3 "2020-06-10T16:01:57Z")

</div>

Great, thank you @pebrc, it works!

Is there any piece of documentation I can read on the fields of this role definition?  
E.g. what are the supported values for `privileges` in Kibana, what is `transient_metadata` and so on?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:01am UTC](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502/4 "2022-11-04T08:01:55Z")

</div>


