# Is there a way to add additional role to user without specifying full array of roles?

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 23, 2020, 11:29am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455 "2020-04-23T11:29:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [April 23, 2020, 11:29am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455/1 "2020-04-23T11:29:26Z")

</div>

Hi,

Is there a way to add additional roles for a user per api without specifying the full set of roles (old roles + new role)?

I want to script user creation via ansible and it would be nice if I can just create a new role and add it to the user so that it is only appended.

Thanks, Andreas

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [April 23, 2020, 12:52pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455/2 "2020-04-23T12:52:40Z")

</div>

It is not possible through the officially supported security APIs.

**DISCLAIMER** : **WARNING! WARNING!!** the following content is provided only for discussion purpose. It is **NOT** recommended or supported in anyway. Doing it is a risk to your cluster integrity. Do **NOT** do it on your production cluster.

Users from native realms are stored in the `.security` index as regulard elasticsearch document. Therefore it possible to [update](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update.html) it directly just as a normal document. Since the update is done without going through the normal security APIs, cache needs to be [cleared](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-clear-cache.html) before the new roles can be recognised.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 23, 2020, 3:44pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455/3 "2020-04-23T15:44:35Z")

</div>

I think the proper way forward is to do the extra step of making a [request to the GET user API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-user.html#security-api-get-user-example), get the JSON array of roles, add your new one and then perform the `PUT` request to update the user.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2020, 3:44pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-additional-role-to-user-without-specifying-full-array-of-roles/229455/4 "2020-05-21T15:44:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
