# Kibana upgrade from 7 to 8.12 errors with security\_exception on saved objects migration

**URL:** <https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669>\
**Category:** Kibana\
**Tags:** migration\
**Created:** [January 23, 2024, 9:20pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669 "2024-01-23T21:20:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael.brizic](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@michael.brizic](https://discuss.elastic.co/u/michael.brizic)\
**Post date:** [January 23, 2024, 9:20pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669/1 "2024-01-23T21:20:57Z")

</div>

I checked Upgrade Assistant prior to performing the upgrade.  
I was also on the latest version of 7.17 before upgrading.

I'm attempting to upgrade to version 8.12 on my locally running development environment.  
Thus, I manage the users, roles and users\_roles in files that I mount inside the elastic stack containers.

Upon startup of kibana, I see a ton of these errors:

2024-01-23 15:14:54 [2024-01-23T21:14:54.299+00:00][ERROR][savedobjects-service] [.kibana\_ingest] Action failed with 'security\_exception  
2024-01-23 15:14:54 Root causes:  
2024-01-23 15:14:54 security\_exception: action [indices:admin/create] is unauthorized for user [admin] with effective roles [kibana\_admin,superuser] on restricted indices [.kibana\_ingest\_8.12.0\_reindex\_temp], this action is granted by the index privileges [create\_index,manage,all]'. Retrying attempt 15 in 64 seconds.

They are logged for many .kibana indices.

i've tried adding the missing privileges to the kibana\_admin role that I created but it obviously is not correct.

Is anyone able to help point me in the right direction?

---

<div class="post-metadata">

**Author:** ![michael.brizic](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@michael.brizic](https://discuss.elastic.co/u/michael.brizic)\
**Post date:** [January 24, 2024, 2:16pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669/3 "2024-01-24T14:16:09Z")

</div>

I'm managing my users, roles, permissions using files I mount in the elasticsearch docker container as this is for local development.

I discovered a reserved/built-in role named `kibana_system` that apparently has the correct permissions needed to solve the errors above.

I added a user with that role and used that user for the kibana docker container and it started up with no errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2024, 2:16pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-to-8-12-errors-with-security-exception-on-saved-objects-migration/351669/4 "2024-02-21T14:16:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
