# Elasticsearch 1.3+ and secure scripts workflow

**URL:** <https://discuss.elastic.co/t/elasticsearch-1-3-and-secure-scripts-workflow/20479>\
**Category:** Elasticsearch\
**Created:** [October 29, 2014, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-1-3-and-secure-scripts-workflow/20479 "2014-10-29T14:08:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deryk\_Wenaus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deryk_wenaus/32/1147_2.png) [@Deryk\_Wenaus](https://discuss.elastic.co/u/Deryk_Wenaus)\
**Post date:** [October 29, 2014, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-1-3-and-secure-scripts-workflow/20479/1 "2014-10-29T14:08:38Z")

</div>

I've upgraded to Elasticsearch 1.3.x and by default dynamic scripting is  
disabled for security reasons. The advice is now to place any used scripts  
as a file in config/scripts directory. My question is how to integrate this  
into a multi-user production environment? Each developer needs to have it  
installed, the circleci needs it, I have to ensure the search cluster  
connected to Heroku has it. Is there anyway I can integrate this into our  
git workflow?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [October 29, 2014, 2:10pm UTC](https://discuss.elastic.co/t/elasticsearch-1-3-and-secure-scripts-workflow/20479/2 "2014-10-29T14:10:49Z")

</div>

I just use dynamic groovy scripts which are acceptable because they are  
sandboxed. If the sandbox is too restrictive you can carefully loosen it  
using configuration.

Nik

On Wed, Oct 29, 2014 at 10:08 AM, Deryk Wenaus [deryk@bluemandala.com](mailto:deryk@bluemandala.com)  
wrote:

> I've upgraded to Elasticsearch 1.3.x and by default dynamic scripting is  
> disabled for security reasons. The advice is now to place any used scripts  
> as a file in config/scripts directory. My question is how to integrate this  
> into a multi-user production environment? Each developer needs to have it  
> installed, the circleci needs it, I have to ensure the search cluster  
> connected to Heroku has it. Is there anyway I can integrate this into our  
> git workflow?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/e75bcf24-60b1-49bb-a6b4-7fe302938d81%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAPmjWd0i0TuWqsgZvzyhCk8spR\_28R8p5jX4PUG%2BVjeUh6yzNA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAPmjWd0i0TuWqsgZvzyhCk8spR_28R8p5jX4PUG%2BVjeUh6yzNA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:53am UTC](https://discuss.elastic.co/t/elasticsearch-1-3-and-secure-scripts-workflow/20479/3 "2017-07-06T00:53:12Z")

</div>


