I have 5 nodes cluster of elasticsearch integrated to SAML IDP.
i want to migrate to new SAML IDP but i don't have working test environment to integrate to this new IDP.
Below scenario that i can think of, do you think this will be feasible ( mostly the part where i want to change the SAML configuration on one node only to test the integration ).
create local users and provide existing users with this temporary local users
offload 1 elasticsearch node ( because i didn't enable replica and restart of the live node will have impact to the service )
configure kibana elasticsearch host to this offloaded node
configure new SAML IDP in this node and test the integration
However, you can have multiple SAML realms on a node, and configure Kibana to prompt users to pick which one to use.
If your old IdP is going to remain available during the migration, you should be able to add the new IdP, test it, and then remove the old one without needing to isolate a node.
i am using elasticsearch 7.16.2 and kibana 7.13.2 , is that multiple saml realm supported and whether kibana will show the login selector by default or need to be configured
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.