# How to allow bulk create only (disallow index, delete and update)

**URL:** <https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912>\
**Category:** Elasticsearch\
**Created:** [February 13, 2017, 5:40pm UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912 "2017-02-13T17:40:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![amano](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@amano](https://discuss.elastic.co/u/amano)\
**Post date:** [February 13, 2017, 5:40pm UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912/1 "2017-02-13T17:40:20Z")

</div>

Hello,

I'm currently evaluating X-Pack for my company and as a requirement we need:

- any user can write data to elasticsearch using bulk API;
- disallow any other bulk operation (index, delete and update);

Looking at the "Indices Privileges" table (here: [https://www.elastic.co/guide/en/x-pack/current/security-privileges.html#privileges-list-indices](https://www.elastic.co/guide/en/x-pack/current/security-privileges.html#privileges-list-indices)),  
A Role with privileges “index” and/or “create” is not able to write using Bulk API;  
Bulk API only works with “write" privilege but this also allows deletion and updates (which we don’t want).

Is this a bug? It doesn’t seem correct to have only one big bag of privileges (“write”) for bulk operations.  
We are testing with version 5.1.2

For performance reasons we are not interested in using any other API to upload documents - only bulk API;  
Using a reverse proxy to filter this requests is not an option either: bulk operations all use POST – we would need to inspect the JSON in the message body (big performance impact);

Any help appreciated 🙂  
Thank you

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 14, 2017, 12:33am UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912/2 "2017-02-14T00:33:33Z")

</div>

This is not something that can be done in current versions of Elasticsearch.

Because the Bulk API can be used to create, update and delete, it is only available to users with `write` privileges. We don't currently apply this sort of security filtering to the content that goes through the Bulk API, so if a user was give access to the bulk API, then there would be no way of preventing them from doing deletes or updates.

We do hope to support this use case in future versions, but it is not currently possible.

---

<div class="post-metadata">

**Author:** ![amano](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@amano](https://discuss.elastic.co/u/amano)\
**Post date:** [February 14, 2017, 7:47am UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912/3 "2017-02-14T07:47:03Z")

</div>

> [@TimV](#):
>
> do hope to support this use case in future versions, but it is not currently possi

Thank you for the quick reply Tim.

This is a big drawback for us since we have a set of standalone distributed clients that upload lots of information using Bulk API. For backward compatibility we need those clients to keep using bulk API which, in turn, means we cannot secure the data...

We do hope to see this supported in future versions also.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2017, 7:47am UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912/4 "2017-03-14T07:47:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 29, 2017, 1:14am UTC](https://discuss.elastic.co/t/how-to-allow-bulk-create-only-disallow-index-delete-and-update/74912/5 "2017-03-29T01:14:16Z")

</div>

Followup: As of Elasticsearch/X-Pack [5.3.0](https://www.elastic.co/guide/en/x-pack/5.3/xpack-release-notes.html) it is possible to use the bulk API if you have some "modify" (create/update/delete) permissions, even if you don't have fully `write` permission.
