# Customize ECK Elastic Search for Active Directory Realms?

**URL:** <https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [May 11, 2020, 8:23pm UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110 "2020-05-11T20:23:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adam\_Fink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adam_fink/32/45742_2.png) [@Adam\_Fink](https://discuss.elastic.co/u/Adam_Fink)\
**Post date:** [May 11, 2020, 8:23pm UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/1 "2020-05-11T20:23:03Z")

</div>

Hi Team,

I have a new Elastic Search ECK installation (Running ECK 1.1 and Elastic 7.6.2 ) and need to implement AD Realm security. Is this possible?

I see where ECK supports Native and File Security Realms  
[https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html)

Is there a way to customize ECK Elastic Search for Active Directory Realms?

As with the standard ES product?  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/active-directory-realm.html)

Thanks!  
Adam

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [May 12, 2020, 7:16am UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/2 "2020-05-12T07:16:02Z")

</div>

You can follow the Elasticsearch documentation for configuring Active Directory with ECK. The configuration values go into the `spec.nodeSets[].config` section of the YAML manifest. This is an example of how it could be done: [https://github.com/elastic/cloud-on-k8s/issues/40#issuecomment-571621798](https://github.com/elastic/cloud-on-k8s/issues/40#issuecomment-571621798)

---

<div class="post-metadata">

**Author:** ![Adam\_Fink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adam_fink/32/45742_2.png) [@Adam\_Fink](https://discuss.elastic.co/u/Adam_Fink)\
**Post date:** [May 12, 2020, 9:33pm UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/3 "2020-05-12T21:33:05Z")

</div>

Hi Charith, thank you very much for your reply. This is exactly what I needed but I do have a follow-up question please...

What is the recommended way in ECK to edit the role\_mapping.yml information? Can I specify the AD role mapping in the nodeSet config?

Such as the following role mapping:

```
super_user:
  - "CN=Web_Elastic_Admin,OU=DataAccess,OU=ouGroups,DC=bcbsnc,DC=com"
```

---

<div class="post-metadata">

**Author:** ![charith-elastic](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@charith-elastic](https://discuss.elastic.co/u/charith-elastic)\
**Post date:** [May 13, 2020, 7:18am UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/4 "2020-05-13T07:18:17Z")

</div>

You can use the [role-mapping APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api.html#security-role-mapping-apis) or use [Kubernetes secrets to provide your own role-mapping file](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html#k8s_creating_custom_roles).

---

<div class="post-metadata">

**Author:** ![Adam\_Fink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adam_fink/32/45742_2.png) [@Adam\_Fink](https://discuss.elastic.co/u/Adam_Fink)\
**Post date:** [May 14, 2020, 2:21pm UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/5 "2020-05-14T14:21:37Z")

</div>

Awesome! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:57am UTC](https://discuss.elastic.co/t/customize-eck-elastic-search-for-active-directory-realms/232110/6 "2022-11-04T07:57:45Z")

</div>


