# AWS Hosted - Roles not behaving as expected with no Index Patterns available

**URL:** <https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284>\
**Category:** Security\
**Created:** [October 13, 2025, 12:33pm UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284 "2025-10-13T12:33:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicholasvdh](https://avatars.discourse-cdn.com/v4/letter/n/bbe5ce/32.png) [@nicholasvdh](https://forum.opensearch.org/u/nicholasvdh)\
**Post date:** [October 13, 2025, 12:33pm UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284/1 "2025-10-13T12:33:40Z")

</div>

**Versions** OpenSearch/Dashboard/Server AWS Hosted - 2.19 OS/Browser MacOS/Chrome Version 140.0.7339.133):

**Describe the issue** :

When creating a role by adding in an index pattern that the role is allowed to read and search the UI does not show anything. I have found a semi workaround but it is not permanent. This workaround involves changing the index permissions to add “\*_” and loading the discover page in another incognito browser window. Then editing the role to remove the “\*” from the index patterns._

From my initial thoughts it was a problem with my config, however I can not seem to work out what permissions I am missing.

**GOAL:** Create a role that the users in that role can only view the index(s) that are added to the role to be able to read and search. As well as be able to see those index(s) that are on dashboards.

This may be a simple mis-understanding of the way the security permission work but I would really appreciate some guidance here as I have tried for the last week with multiple configs and do not seem to be progressing (you can only google so much, until you ask the community experts for assistance 🙏

**Configuration** :

Role name = devops\_ops\_UAT

Needs permissions to the index - os\_dop\_ops\* and my\_\*

**Relevant Logs or Screenshots** :

This is the config that has been setup

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/4/416764dea04f123b2f37601102a447a83d08b862.png)

---

<div class="post-metadata">

**Author:** ![Leeroy](https://avatars.discourse-cdn.com/v4/letter/l/eb9ed0/32.png) [@Leeroy](https://forum.opensearch.org/u/Leeroy)\
**Post date:** [October 15, 2025, 9:10am UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284/2 "2025-10-15T09:10:01Z")

</div>

Hey @nicholasvdh ,

When you say AWS Hosted, is it a self managed, or managed deployment? If so could you share your configs, also have you tested mapping the users to the role in which grants the permissions?

Leeroy.

---

<div class="post-metadata">

**Author:** ![cwperks](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/cwperks/32/4968_2.png) [@cwperks](https://forum.opensearch.org/u/cwperks)\
**Post date:** [October 15, 2025, 11:33am UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284/3 "2025-10-15T11:33:16Z")

</div>

There is a setting calling [do\_not\_fail\_on\_forbidden](https://docs.opensearch.org/latest/security/access-control/permissions/#do_not_fail_on_forbidden) that can help with this. You will need to reach out to AWS support to toggle this on the cluster.

---

<div class="post-metadata">

**Author:** ![nicholasvdh](https://avatars.discourse-cdn.com/v4/letter/n/bbe5ce/32.png) [@nicholasvdh](https://forum.opensearch.org/u/nicholasvdh)\
**Post date:** [October 16, 2025, 5:53am UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284/4 "2025-10-16T05:53:40Z")

</div>

Hi Leeroy,

We are making use of the Amazon Open Search Service hosted in Cape Town RSA.

The configs I am using are the following:

For the Role

```auto
{
  "devops_ops_UAT": {
    "reserved": false,
    "hidden": false,
    "cluster_permissions": [
      "cluster_composite_ops_ro",
      "cluster_composite_ops"
    ],
    "index_permissions": [
      {
        "index_patterns": [
          "my_*",
          "os_dop_ops*"
        ],
        "dls": "",
        "fls": [],
        "masked_fields": [],
        "allowed_actions": [
          "read",
          "search",
          "indices:admin/mappings/fields/get*"
        ]
      }
    ],
    "tenant_permissions": [],
    "static": false
  }
}

```

For the Mapping on that role

> ```auto
> {
> “devops_ops_UAT”: {
> “hosts”: ,
> “users”: [
> “MY_user”,
> “Another_User”
> ],
> “reserved”: false,
> “hidden”: false,
> “backend_roles”: ,
> “and_backend_roles”: 
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![nicholasvdh](https://avatars.discourse-cdn.com/v4/letter/n/bbe5ce/32.png) [@nicholasvdh](https://forum.opensearch.org/u/nicholasvdh)\
**Post date:** [October 16, 2025, 5:55am UTC](https://forum.opensearch.org/t/aws-hosted-roles-not-behaving-as-expected-with-no-index-patterns-available/27284/5 "2025-10-16T05:55:44Z")

</div>

Thanks @cwperks , I will take this up with AWS
