# How to set a user with customized roles for kibana on ECK

**URL:** <https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 20, 2024, 12:54pm UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690 "2024-02-20T12:54:35Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wangxr1985](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wangxr1985/32/117798_2.png) [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Post date:** [February 20, 2024, 12:54pm UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/1 "2024-02-20T12:54:35Z")

</div>

```auto
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: quickstart
spec:
  version: 8.12.0
  count: 1
  elasticsearchRef:
    name: quickstart
    namespace: default
  http:
    tls:
      selfSignedCertificate:
        disabled: true

```

When I create a kibana pod which connects to an ES cluster managed by ECK, the default user in kibana.yaml is "default-quickstart-kibana-user", its role is kibana\_system.  
This user just has permissions to access internal indices, just like .kibana\*、.monitoring-\*.  
I'd like to know how to modify the role, for example, setting it as a superuser.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [February 20, 2024, 6:26pm UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/2 "2024-02-20T18:26:22Z")

</div>

Welcome back @wangxr1985. Thanks for posting! I found a [documentation page that may be helpful here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-users-and-roles.html), and it showed an example that looked similar to what you are looking for.

```auto
apiVersion: v1
kind: Secret
metadata:
  name: secret-basic-auth
type: kubernetes.io/basic-auth
stringData:
  username: rdeniro # required field for kubernetes.io/basic-auth
  password: mypassword # required field for kubernetes.io/basic-auth
  roles: kibana_admin,ingest_admin # optional, not part of kubernetes.io/basic-auth

```

Hope this helps!

---

<div class="post-metadata">

**Author:** ![wangxr1985](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wangxr1985/32/117798_2.png) [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Post date:** [February 21, 2024, 9:23am UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/3 "2024-02-21T09:23:16Z")

</div>

Thanks, I have read this document before and I can create a user with the permissions I need. However, I am not sure how to configure Kibana to use this user.

> **[Connect to an Elasticsearch cluster | Elastic Cloud on Kubernetes \[master\] |...](https://www.elastic.co/guide/en/cloud-on-k8s/master/k8s-kibana-es.html#k8s-kibana-es)**

In the "Elasticsearch is managed by ECK" section of this document, it says: "The Kibana configuration file is automatically setup by ECK to establish a secure connection to Elasticsearch."  
I would like to know how to specify my configured user in the Kibana config file, or give the default user more permissions.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [February 21, 2024, 5:14pm UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/4 "2024-02-21T17:14:10Z")

</div>

Would something like what's [described here](https://discuss.elastic.co/t/creating-roles-with-limited-kibana-permissions/236502) work for you?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 21, 2024, 6:07pm UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/5 "2024-02-21T18:07:43Z")

</div>

Hi @wangxr1985

> [@wangxr1985](#):
>
> I would like to know how to specify my configured user in the Kibana config file, or give the default user more permissions.

This connection between Kibana and Elasticsearch does not affect how users log in, nor what permissions/access, etc, they have.. this is purely how the Kibana Server interacts with the Elasticsearch Server.... it is not about users that use the system

Changing the roles/permission/users is not recommended...as the `kibana_system` is the **exact** correct role for this use case / connections.

Authentication / Authorization / Roles / that Users Log into Kibana and / Elastic are managed separately via Users and Roles.

You should really look at this

> **[User authorization | Elasticsearch Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/authorization.html)**

and This

> **[Security | Kibana Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-security.html)**

Or Got to Kibana -\> Stack management -\> User / Roles and set up the Users and Roles you want.

So to summarize, it is not recommended to change the Auth/Auth in the kibana.yml for the connection between kibana server and elasticsearch server

User Roles are managed as separate Roles and are assigned to Users in a normal RBAC pattern.

---

<div class="post-metadata">

**Author:** ![wangxr1985](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wangxr1985/32/117798_2.png) [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Post date:** [February 22, 2024, 7:21am UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/6 "2024-02-22T07:21:59Z")

</div>

Thank you, I originally wanted to put a monitoring script in this image, and connect to the ES cluster using the url/user/password in the kibana configuration file. It seems that this method is not quite correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2024, 7:22am UTC](https://discuss.elastic.co/t/how-to-set-a-user-with-customized-roles-for-kibana-on-eck/353690/7 "2024-03-21T07:22:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
