# Custom Logstash user role

**URL:** <https://discuss.elastic.co/t/custom-logstash-user-role/352398>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 2, 2024, 12:33pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398 "2024-02-02T12:33:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rokkolesa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokkolesa/32/131366_2.png) [@rokkolesa](https://discuss.elastic.co/u/rokkolesa)\
**Post date:** [February 2, 2024, 12:33pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398/1 "2024-02-02T12:33:29Z")

</div>

Hi,

I'm trying to deploy multiple Logstash instances to two separate k8s namespaces and they both connect to the same Elasticsearch cluster. The problem is that they both write to different ES indices but use the same user role `eck_logstash_user_role`.

It seems that the role is now hard-coded and cannot be changed? I know I can modify the `eck_logstash_user_role` to include both indices (either by exact name or by pattern), but then both Logstash instances would be able to write to both indices.

Example:  
ES cluster: my-es  
Logstash1: writes to `sandbox-1`  
Logstash2: writes to `sandbox-2`

I configure my ES to add

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: my-es
spec:
  ...
  auth:
    roles:
      - secretName: logstash-user-role-secret
  ...
---
kind: Secret
apiVersion: v1
metadata:
  name: logstash-user-role-secret
stringData:
  roles.yml: |-
    eck_logstash_user_role:
      cluster: ["monitor", "manage_ilm", "read_ilm", "manage_logstash_pipelines", "manage_index_templates", "cluster:admin/ingest/pipeline/get"]
      indices:
        - names: ["sandbox-*", "logstash", "logstash-*", "ecs-logstash", "ecs-logstash-*", "logs-*", "metrics-*", "synthetics-*", "traces-*"]
          privileges: ["manage", "write", "create_index", "read", "view_index_metadata"]

```

This configuraton enables `Logstash2` to write to `sandbox-2` but it also enables it to write to `sandbox-1` and I would like to prevent that from happening.  
Bottom line, `Logstash1` should only be able to write to `sandbox-1` and `Logstash2` should only be able to write to `sandbox-2`.

It seems that Logstash will always use the `eck_logstash_user_role` no matter what.

Am I missing something or is this feature missing?

Best regards,  
Rok

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [February 2, 2024, 5:10pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398/2 "2024-02-02T17:10:57Z")

</div>

Hi,

you can create separate roles for each Logstash instance and assign them to separate users. This way, each Logstash instance will have its own user and role, and you can control the indices they can write to.

Regards

---

<div class="post-metadata">

**Author:** ![rokkolesa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokkolesa/32/131366_2.png) [@rokkolesa](https://discuss.elastic.co/u/rokkolesa)\
**Post date:** [February 3, 2024, 1:08am UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398/3 "2024-02-03T01:08:59Z")

</div>

Hi,

I get that, but is there a way in the Logstash CRD to define which role the logstash instance should use? Or in the Elasticsearch CRD?

Otherwise I guess the only way would be to patch the `<logstash-namespace-and-name>-<elastic-namespace-name>-logstash-user` secret after it is created by the operator by changing the user role.. or I guess create the secret manually (but then I would have to know the exact name of the secret in advance AND I have to know how to hash the password).

Regards,  
Rok

---

<div class="post-metadata">

**Author:** ![rokkolesa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokkolesa/32/131366_2.png) [@rokkolesa](https://discuss.elastic.co/u/rokkolesa)\
**Post date:** [February 3, 2024, 10:48pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398/4 "2024-02-03T22:48:11Z")

</div>

Hmm it seems I cannot patch the secret as it is managed by the operator. Every time I try to change the content of the secret, the operator immediately changes it back. So the user role of the logstash user cannot be changed manually.

I believe this is a missing feature in the operator and Logstash CRD

Regards,  
Rok

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2024, 10:48pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398/5 "2024-03-02T22:48:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
