# How to restrict access?

**URL:** <https://discuss.elastic.co/t/how-to-restrict-access/5702>\
**Category:** Elasticsearch\
**Created:** [October 27, 2011, 3:21am UTC](https://discuss.elastic.co/t/how-to-restrict-access/5702 "2011-10-27T03:21:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_m/32/3098_2.png) [@Andrew\_M](https://discuss.elastic.co/u/Andrew_M)\
**Post date:** [October 27, 2011, 3:21am UTC](https://discuss.elastic.co/t/how-to-restrict-access/5702/1 "2011-10-27T03:21:06Z")

</div>

OK I'm really new to Elasticsearch, so I apologise if I missed  
something obvious....

What I would like to do is setup a public elasticsearch server using  
the http transport, however I would like to restrict it search request  
only on a particular index, and have new entries via a shared key (or  
some other authentication method).

Is this possible? I know I _could_ write some kind of proxy in Nodejs,  
but I would prefer a plugin solution - and no my Java skills are non-  
existent... 😛

Thanks

Andrew

---

<div class="post-metadata">

**Author:** ![Karussell1](https://avatars.discourse-cdn.com/v4/letter/k/50afbb/32.png) [@Karussell1](https://discuss.elastic.co/u/Karussell1)\
**Post date:** [October 27, 2011, 10:04am UTC](https://discuss.elastic.co/t/how-to-restrict-access/5702/2 "2011-10-27T10:04:03Z")

</div>

Sorry, there is no out of the box solution (yet):

> <https://github.com/elastic/elasticsearch/issues/1379>
>
> There are several points regarding security:
> 1. make sure that one can authentic…ate into ElasticSearch
> 2. make sure that sensitive data is encrypted when sending over the network and also between nodes
> 3. make sure that an authenticated user can see and change only his own 'things' (indices, data, node info)
> 
> Point 1 and 2 are already requested in issue #664. What I'm after is point 3. I wanted to ask you how you would implement point 1 and 3 (point 2 can be handled by someone else ;))
> 
> I've thought one could simply store user and password (as updateable settings) while creating an index. And when searching or indexing one needs to provide the user and pw. To keep it simple there is only one admin user which has access to the node and cluster health information etc. All other users are normal user and can only perform "CRUD" actions for indices and its data.
> 
> Now my problem is that when I intercept every request to authenticate & authorize I would have to touch over 10 Request classes implementing ActionRequest.validate() for the transport client. Also there are no settings stored for those Requests.
> 
> Or how would you implement this?
> 
> And then for the rest client it looks a bit simpler because the settings are already in the request and I could then change the BaseRestHandler only to implement a validation within handleRequest. Is this correct?
> 
> Or is there a simpler or more powerful scenarios to implement my feature requests?

Regards,  
Peter.

On 27 Okt., 05:21, Andrew M [primary....@gmail.com](mailto:primary....@gmail.com) wrote:

> OK I'm really new to Elasticsearch, so I apologise if I missed  
> something obvious....
> 
> What I would like to do is setup a public elasticsearch server using  
> the http transport, however I would like to restrict it search request  
> only on a particular index, and have new entries via a shared key (or  
> some other authentication method).
> 
> Is this possible? I know I _could_ write some kind of proxy in Nodejs,  
> but I would prefer a plugin solution - and no my Java skills are non-  
> existent... 😛
> 
> Thanks
> 
> Andrew

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:50am UTC](https://discuss.elastic.co/t/how-to-restrict-access/5702/3 "2017-07-06T03:50:41Z")

</div>


