# Do I still have to setup roles and users after I successfully added one user in file realm?

**URL:** <https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 14, 2019, 1:03pm UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143 "2019-01-14T13:03:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)\
**Post date:** [January 14, 2019, 1:03pm UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143/1 "2019-01-14T13:03:00Z")

</div>

In the online document - Configuring security in elasticsearch,  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-security.html#](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-security.html#)

the step 7 is  
Choose which types of realms you want to use to authenticate users.

- [Configure an Active Directory realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-ad-realm.html).
- [Configure a file realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-file-realm.html).
- [Configure an LDAP realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-ldap-realm.html).
- [Configure a native realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-native-realm.html).
- [Configure a PKI realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-pki-realm.html).
- [Configure a SAML realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-saml-realm.html).
- [Configure a Kerberos realm](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-kerberos-realm.html).

While in configure a file realm, I already added a user with user role, say, superuser. But the step 8 is : Set up roles and users to control access to Elasticsearch. For example, to grant _John Doe_ full access to all indices that match the pattern `events*` and enable him to create visualizations and dashboards for those indices in Kibana, you could create an `events_admin` role and assign the role to a new `johndoe` user.  
Do I still need to do so after I already added a user by [_elasticsearch-users_](https://www.elastic.co/guide/en/elasticsearch/reference/current/users-command.html) tool which adds an item in both ES\_PATH\_CONF/users file and ES\_PATH\_CONF/users\_roles file?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 15, 2019, 1:56am UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143/2 "2019-01-15T01:56:41Z")

</div>

If you only want to have a single user, then you don't need to set anything else up.

But for most use cases, a single user isn't a good idea. You shouldn't have everything connect to your cluster as `superuser`, it is much better to create users and roles for specific purposes that limit the user's access to just what they need.

---

<div class="post-metadata">

**Author:** ![li\_jessen2016](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/li_jessen2016/32/38817_2.png) [@li\_jessen2016](https://discuss.elastic.co/u/li_jessen2016)\
**Post date:** [January 15, 2019, 2:02am UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143/3 "2019-01-15T02:02:09Z")

</div>

But all these can also be done in file realm by elasticsearch-users tool. So I don't think step 8 is necessary. Have I made my question clear?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 15, 2019, 3:27am UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143/4 "2019-01-15T03:27:50Z")

</div>

Step 7 is to decide what realm types you want. You have decided on a file realm (which is not our usual recommendation, but that's a separate issue).

Step 8 is to set up roles and users in the realms you want to use. The _example_ there shows creating a Native role and Native user, but it's just an example. You can create File roles and users instead.

So, you need to do step 8, but what you do in step 8 is entirely dependent on the decisions you made in step 7.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2019, 3:27am UTC](https://discuss.elastic.co/t/do-i-still-have-to-setup-roles-and-users-after-i-successfully-added-one-user-in-file-realm/164143/5 "2019-02-12T03:27:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
