# Pipelines processor and xpack permissions order of evaluation

**URL:** <https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504>\
**Category:** Elasticsearch\
**Created:** [February 15, 2019, 1:37am UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504 "2019-02-15T01:37:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![leandro](https://avatars.discourse-cdn.com/v4/letter/l/50afbb/32.png) [@leandro](https://discuss.elastic.co/u/leandro)\
**Post date:** [February 15, 2019, 1:37am UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504/1 "2019-02-15T01:37:24Z")

</div>

Hi all,

I have a pipeline on my cluster to process items from metricbeats.  
The pipeline is responsible to modify the index based on the original doc.

> PUT \_ingest/pipeline/metricbeat  
> {  
> "description": "Pipeline to ingest metrics from Metricbeat",  
> "processors": [  
> {  
> "set": {  
> "field": "hostname",  
> "value": "anyhost"  
> }  
> },  
> {  
> "script": {  
> "source": "if (ctx.metricset.module == 'kubernetes') { ctx.\_index = 'metricbeats-linux-kubernetes' ;} "  
> }  
> }  
> ]  
> }

The user has the permission to save on that index:

> GET \_xpack/security/user/\_has\_privileges  
> {  
> "cluster": ["manage\_index\_templates", "monitor"],  
> "index" : [  
> {  
> "names": ["metricbeats\*"],  
> "privileges": ["create","create\_index"]  
> }  
> ]  
> }  
> {  
> "username" : "metricbeats\_user",  
> "has\_all\_requested" : true,  
> "cluster" : {  
> "manage\_index\_templates" : true,  
> "monitor" : true  
> },  
> "index" : {  
> "metricbeats\*" : {  
> "create\_index" : true,  
> "create" : true  
> }  
> },  
> "application" : { }  
> }

When I try to post it to a random index, I receive a 403 error.

> POST any\_index\_name/doc?pipeline=metricbeat  
> {  
> "@timestamp": "2019-02-13T06:43:50.913Z",  
> "@metadata": {  
> "beat": "metricbeat",  
> "type": "doc",  
> "version": "7.0.0-alpha1"  
> },  
> "os\_type": "linux",  
> "version": "v1",  
> "metricset": {  
> "name": "container",  
> "module": "kubernetes"  
> }  
> }  
> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "security\_exception",  
> "reason": "action [indices:admin/create] is unauthorized for user [metricbeats\_user]"  
> }  
> ],  
> "type": "security\_exception",  
> "reason": "action [indices:admin/create] is unauthorized for user [metricbeats\_user]"  
> },  
> "status": 403  
> }

If I post the samething using the endpoint `metricbeats/doc?pipeline=metricbeat`, it works fine.  
However, since the pipeline change the index, I was expecting to be able to Post it to any index.

Is it the expected behavior? Is it configurable?

Thank you

Leandro

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [February 15, 2019, 4:38am UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504/2 "2019-02-15T04:38:25Z")

</div>

Hi @leandro,

It seems like the user does not have index permissions on `any_index_name`.  
You can check by invoking `/_xpack/security/_authenticate` API to see what roles, indices are allowed for the logged in user.  
Or you could check using `_has_privileges` API whether the user has appropriate privileges:

> [@leandro](#):
>
> GET \_xpack/security/user/\_has\_privileges  
> {  
> "cluster": ["manage\_index\_templates", "monitor"],  
> "index" : [  
> {  
> "names": ["metricbeats\*", " **any\_index\_name**"],  
> "privileges": ["create","create\_index"]  
> }  
> ]  
> }

Hope this helps.

Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![leandro](https://avatars.discourse-cdn.com/v4/letter/l/50afbb/32.png) [@leandro](https://discuss.elastic.co/u/leandro)\
**Post date:** [February 15, 2019, 5:42am UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504/3 "2019-02-15T05:42:59Z")

</div>

Hi @Yogesh_Gaikwad

You are right about that. The user doesn't have the permission to that index, but the pipeline change the index of the docs. So, no matter which index you use to send the request, the pipeline will change it to `metricbeats-linux-kubernetes`, so I thought that I could use any index, but apparently not. I'm not sure if that is configurable or not, but to me it would make more sense to check the permissions after the pipeline processor and not before.

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [February 18, 2019, 10:17pm UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504/4 "2019-02-18T22:17:23Z")

</div>

Hi @leandro,

When you invoke `POST any_index_name/doc?pipeline=metricbeat` you are trying an action on an index(`any_index_name`), so ES will always check if you have right set of permissions to invoke the action on the given index.  
Hope this helps.

Regards,  
Yogesh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2019, 10:17pm UTC](https://discuss.elastic.co/t/pipelines-processor-and-xpack-permissions-order-of-evaluation/168504/5 "2019-03-18T22:17:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
