# How to get a NodeClient inside a X-Pack plugin?

**URL:** <https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347>\
**Category:** Elasticsearch\
**Created:** [November 12, 2018, 8:50pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347 "2018-11-12T20:50:29Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcel-Hillmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel-hillmann/32/37666_2.png) [@Marcel-Hillmann](https://discuss.elastic.co/u/Marcel-Hillmann)\
**Post date:** [November 12, 2018, 8:50pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/1 "2018-11-12T20:50:29Z")

</div>

I would like to read/write an index inside our custom X-Pack plugin.  
I use the SecurityExtension interface v6.3.1 to load the Realm.

In org.elasticsearch.xpack.security.Security is no delegation for the Client object.  
I tried to use the RestHighLevelClient but that failed at runtime.

I checked, different X-Pack plugin implementation but could not find a solution.

What is the right solution?

Thanks  
Marcel

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 13, 2018, 1:52pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/2 "2018-11-13T13:52:01Z")

</div>

A `Client` is passed into each `Plugin` via the `createComponents()` method:

> <https://github.com/elastic/elasticsearch/blob/v6.3.1/server/src/main/java/org/elasticsearch/plugins/Plugin.java#L127-L130>

In practice what it gets seems to be a `NodeClient` but you shouldn't rely on this.

---

<div class="post-metadata">

**Author:** ![Marcel-Hillmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel-hillmann/32/37666_2.png) [@Marcel-Hillmann](https://discuss.elastic.co/u/Marcel-Hillmann)\
**Post date:** [November 13, 2018, 1:56pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/3 "2018-11-13T13:56:53Z")

</div>

Hi David,

that is correct for Elasticsearch Plugins not for X-Pack Plugins, in  
org.elasticsearch.xpack.security.Security

[https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/Security.java#L383-L467](https://github.com/elastic/elasticsearch/blob/master/x-pack/plugin/security/src/main/java/org/elasticsearch/xpack/security/Security.java#L383-L467)

Is no delagation of the Client object to the plugin.

Thanks  
Marcel

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 13, 2018, 1:57pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/4 "2018-11-13T13:57:29Z")

</div>

I am facing the same issue.

The createComponents gets called in the \*Plugin class; The CustomRealm is created in SecurityExtension.  
Additionally the getRealms method of the SecurityExtension is called before the createComponents of the Plugin.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [November 13, 2018, 3:02pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/5 "2018-11-13T15:02:34Z")

</div>

I misunderstood your question. You are not asking about plugins (i.e. things that derive from `org.elasticsearch.plugins.Plugin`) which includes various X-pack plugins. You are asking about security extensions (i.e. things that derive from `org.elasticsearch.xpack.core.security.SecurityExtension`). I cannot see an easy way to get hold of a client from within such a thing.

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 13, 2018, 3:13pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/6 "2018-11-13T15:13:19Z")

</div>

I am currently trying to have my Plugin class implement the SecurityExtension. The plugin / realm starts. The above mentioned issue with the order in which what is called I "solved" by declaring a

> `protected static Client client;`

and using a Supplier \<Client\> to feed it into the Realm. Currently when I use the Client

> `SearchRequestBuilder request = client.prepareSearch("admin-stuff").setTypes("grp") .setQuery(QueryBuilders.matchAllQuery()); logger.info(request.toString()); SearchHits result = request.get().getHits();`

I get the the following log output and then ES dies because of an StackOverflow Exception

> JWTSecurityRealm] REALM: org.elasticsearch.client.node.NodeClient@588d630d  
> [2018-11-13T16:03:15,451][INFO][i.z.s.p.e.j.JWTSecurityRealm] {"query":{"match\_all":{"boost":1.0}}}  
> [2018-11-13T16:03:15,454][WARN][i.z.s.p.e.j.JWTSecurityRealm] REALM: org.elasticsearch.client.node.NodeClient@588d630d  
> [2018-11-13T16:03:15,454][INFO][i.z.s.p.e.j.JWTSecurityRealm] {"query":{"match\_all":{"boost":1.0}}}  
> [2018-11-13T16:03:15,456][WARN][i.z.s.p.e.j.JWTSecurityRealm] REALM: org.elasticsearch.client.node.NodeClient@588d630d  
> [2018-11-13T16:03:15,456][INFO][i.z.s.p.e.j.JWTSecurityRealm] {"query":{"match\_all":{"boost":1.0}}}

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [November 13, 2018, 11:27pm UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/7 "2018-11-13T23:27:53Z")

</div>

Hi @gsu Could you please share the exception stack trace? Thanks.

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 14, 2018, 8:27am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/8 "2018-11-14T08:27:34Z")

</div>

Have a look at:

> **[Georg Summer / es-custom-plugin-issues](https://gitlab.com/gsu/es-custom-plugin-issues)**
>
> The problems faced when trying to talk to ES from within a Custom Realm for x-pack

The stack-trace is too big for this text-box here.

---

<div class="post-metadata">

**Author:** ![Marcel-Hillmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel-hillmann/32/37666_2.png) [@Marcel-Hillmann](https://discuss.elastic.co/u/Marcel-Hillmann)\
**Post date:** [November 14, 2018, 8:31am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/9 "2018-11-14T08:31:56Z")

</div>

Look like a recursive call.

Like calling Endpoint, which calls an Endpoint, .... .

So the jvm is killing the server to protect the environment.

Thanks  
Marcel

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 14, 2018, 8:44am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/10 "2018-11-14T08:44:24Z")

</div>

Figured so. I could imagine that the nodeclient tries to authenticate itself. So I added the withHeaders and authorization to it. It obviously isn't working. Alternative would be to try and create a new NodeClient with authorization backed it. Kind of defeats the whole purpose of what we want to achieve.

---

<div class="post-metadata">

**Author:** ![Marcel-Hillmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel-hillmann/32/37666_2.png) [@Marcel-Hillmann](https://discuss.elastic.co/u/Marcel-Hillmann)\
**Post date:** [November 14, 2018, 9:29am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/11 "2018-11-14T09:29:22Z")

</div>

Sorry, but without JWTSecurityRealm source I couldn't give you an advise.

Thanks  
Marcel

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 14, 2018, 9:31am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/12 "2018-11-14T09:31:53Z")

</div>

added the code calling the client and the Classes properties.

---

<div class="post-metadata">

**Author:** ![Marcel-Hillmann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcel-hillmann/32/37666_2.png) [@Marcel-Hillmann](https://discuss.elastic.co/u/Marcel-Hillmann)\
**Post date:** [November 14, 2018, 9:38am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/13 "2018-11-14T09:38:45Z")

</div>

You need an exit dialog in the method token, like  
" public AuthenticationToken token(final ThreadContext threadContext) {  
 if(threadContext.getHeader("internal-callback") != null){  
 return null;  
 }"

and in "protected Set getPermissions(JsonWebToken jwt) {" you have to set the header.

Thx  
Marcel

---

<div class="post-metadata">

**Author:** ![gsu](https://avatars.discourse-cdn.com/v4/letter/g/3da27b/32.png) [@gsu](https://discuss.elastic.co/u/gsu)\
**Post date:** [November 14, 2018, 11:57am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/14 "2018-11-14T11:57:49Z")

</div>

Good idea, thanks @Marcel-Hillmann. Worked like a charm until

```
{
        "error": {
            "root_cause": [
                {
                    "type": "security_exception",
                    "reason": "action [indices:data/read/search] is unauthorized for user [_system]",
                    "header": {
                        "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\""
                    }
                }
            ],
            "type": "security_exception",
            "reason": "action [indices:data/read/search] is unauthorized for user [_system]",
            "header": {
                "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\""
            }
        },
        "status": 403
    }

```

The \_system user is used by xpack internally. It seems  
Looking at the documentation

> **[Java client and security | Elasticsearch Guide \[6.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/java-clients.html)**

tells us:

> Using the Java Node Client with secured clusters is not recommended or supported.

I added the \_system user via the user\_roles file to the superuser group, didn't change anything. Interestingly the Authorization: Basic header I add isn't used in the request even though the internal-callback is.

> ```
> {
> Map<String, String> headers = new HashMap<String, String>();
> headers.put("internal-callback", "internal-callback");
> headers.put("Authorization", "Basic ");
> Client authClient = client.filterWithHeader(headers);
> SearchRequestBuilder request = authClient.prepareSearch("admin-stuff").setTypes("grp").setQuery(QueryBuilders.matchAllQuery());
> }
> 
> ```

Resulting in log output:

> [2018-11-14T12:33:54,975][INFO][i.z.s.p.e.j.JWTSecurityRealm] TOKEN:{Authorization=Bearer JWT-TOKEN}  
> [2018-11-14T12:33:55,085][WARN][i.z.s.p.e.j.JWTSecurityRealm] REALM: org.elasticsearch.client.node.NodeClient@588d630d  
> [2018-11-14T12:33:55,092][INFO][i.z.s.p.e.j.JWTSecurityRealm] {"query":{"match\_all":{"boost":1.0}}}  
> [2018-11-14T12:33:55,093][INFO][i.z.s.p.e.j.JWTSecurityRealm] TOKEN:{Authorization=Bearer JWT-TOKEN, internal-callback=internal-callback}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2018, 11:57am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-x-pack-plugin/156347/15 "2018-12-12T11:57:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
