# How to create role mapping file

**URL:** <https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 13, 2019, 3:39pm UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459 "2019-09-13T15:39:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sfgroups1](https://avatars.discourse-cdn.com/v4/letter/s/b77776/32.png) [@sfgroups1](https://discuss.elastic.co/u/sfgroups1)\
**Post date:** [September 13, 2019, 3:39pm UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459/1 "2019-09-13T15:39:18Z")

</div>

Hi,  
I am adding the LDAP authentication to my cluster, I need to create the **group\_to\_role\_mapping.yml** file for the roles. Is there an example I can follow?

```
 files:
              role_mapping: "/mnt/elasticsearch/group_to_role_mapping.yml"
            unmapped_groups_as_roles: false

```

Thanks

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [September 30, 2019, 12:06pm UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459/2 "2019-09-30T12:06:47Z")

</div>

Sorry for the late reply!

In principle you would follow the approach outlined in our documentation for custom configuration files [https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-bundles-plugins.html](https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-bundles-plugins.html)

```auto
spec:
  nodes: # incomplete config, just to convey the idea!
  - config:
       xpack.security.authc.realms:
          ...
          ldap.realm1: # adjust to your config of course
             ...
             files.role_mapping: /mnt/config/role-mapping/group_to_role_mapping.yml
    podTemplate:
      spec:
        containers:
        - name: elasticsearch 
          volumeMounts:
          - name: role-mapping
            mountPath: /mnt/config/role-mapping # just an example, you can chose something that works for you here
        volumes:
        - name: role-mapping
          configMap:
            name: role-mappings

```

This assumes you have created a ConfigMap called `role-mappings` containing your `group_to_role_mapping.yml` file

---

<div class="post-metadata">

**Author:** ![sfgroups1](https://avatars.discourse-cdn.com/v4/letter/s/b77776/32.png) [@sfgroups1](https://discuss.elastic.co/u/sfgroups1)\
**Post date:** [October 8, 2019, 5:16pm UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459/3 "2019-10-08T17:16:03Z")

</div>

Thanks for the code.

How do we update the new role mapping, on the running application?

do we need to update the configmap and restart the pods? or do we have any other method?

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [October 18, 2019, 8:40am UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459/4 "2019-10-18T08:40:34Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/7.4/mapping-roles.html#mapping-roles-file](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/mapping-roles.html#mapping-roles-file) says role mapping files are checked for changes every 5 seconds. But the interval is configurable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:25am UTC](https://discuss.elastic.co/t/how-to-create-role-mapping-file/199459/5 "2022-11-04T07:25:20Z")

</div>


