# Best option for automating role creation in Kibana?

**URL:** <https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438>\
**Category:** Security\
**Created:** [August 3, 2020, 2:44pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438 "2020-08-03T14:44:48Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![hainesgreg](https://avatars.discourse-cdn.com/v4/letter/h/b38774/32.png) [@hainesgreg](https://forum.opensearch.org/u/hainesgreg)\
**Post date:** [August 3, 2020, 2:44pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/1 "2020-08-03T14:44:48Z")

</div>

Hi,

Other than going to the Kibana console and creating a role with a set of permissions manually, what other methods are best to carry out this type of request?

We need to be able to automate the process.

Thanks

---

<div class="post-metadata">

**Author:** ![bonwier](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/bonwier/32/798_2.png) [@bonwier](https://forum.opensearch.org/u/bonwier)\
**Post date:** [September 11, 2020, 12:34am UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/2 "2020-09-11T00:34:51Z")

</div>

PLUS ONE – I have also encountered this recently and would be interested in this functionality - Thanks

---

<div class="post-metadata">

**Author:** ![stmx38](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/stmx38/32/4354_2.png) [@stmx38](https://forum.opensearch.org/u/stmx38)\
**Post date:** [September 11, 2020, 7:38am UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/3 "2020-09-11T07:38:05Z")

</div>

We usually do it via configuration files - in order to be able to restore all required permissions in case of he security index initialisation.

---

<div class="post-metadata">

**Author:** ![bonwier](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/bonwier/32/798_2.png) [@bonwier](https://forum.opensearch.org/u/bonwier)\
**Post date:** [September 11, 2020, 12:28pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/4 "2020-09-11T12:28:08Z")

</div>

Thanks for your response. Yes, we also modify the YML files in opendistroelasticsearch to retain the settings.  
Please let me clarify.  
In Kibana (opendistro-kibana)  
Security  
Roles  
logstash (reserved)

Logstash had MOST of what I needed however, I had to add cluster:monitor/main so I cloned into logstash-writer and added the right.

When I reran securityadmin.sh to fix another small issue - - my new logstatsh-writer disappeared.

Is there a YML I could add this to?  
b/c I have yet to find it

thanks in advance

---

<div class="post-metadata">

**Author:** ![tony](https://avatars.discourse-cdn.com/v4/letter/t/ee7513/32.png) [@tony](https://forum.opensearch.org/u/tony)\
**Post date:** [September 11, 2020, 12:33pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/5 "2020-09-11T12:33:06Z")

</div>

You can use a script (python for example) to pull the config from a json file (with the settings you want) and fire it at the api in opendistro (for the section you want to update).

---

<div class="post-metadata">

**Author:** ![bonwier](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/bonwier/32/798_2.png) [@bonwier](https://forum.opensearch.org/u/bonwier)\
**Post date:** [September 11, 2020, 12:49pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/6 "2020-09-11T12:49:39Z")

</div>

Interesting concept - -I LOVE IT  
Is there a particular JSON that I should look for - specifically where my addition of logstash-writer was placed (for formatting, placement etc)  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![GSmith](https://avatars.discourse-cdn.com/v4/letter/g/bbe5ce/32.png) [@GSmith](https://forum.opensearch.org/u/GSmith)\
**Post date:** [September 13, 2020, 8:57pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/7 "2020-09-13T20:57:48Z")

</div>

As you have discovered, re-running the securityadmin.sh script re-initializes all of the security configuration files…and, thus, wipes out any/all security changes you’ve made via Kibana or via API calls. You could add your new user to the roles.yml and roles-mapping.yml files that are part of the security configuration. This would mean it would be re-created whenever you run the securityadmin.sh script (since the definition is part of the initialization files). But, you will still lose any/all security changes made via Kibana (or API calls) if you later re-run the securityadmin.sh script.

The other option is to never run the securityadmin.sh script (other than letting it run the first time) and do everything security-related via Kibana and/or API calls after that. I believe this is the “recommended” approach based on the following quote from the [Users and roles](https://opendistro.github.io/for-elasticsearch-docs/docs/security/access-control/users-roles/) section of the doc where is is presented in a highlighted box:

> Unless you need to create new [read-only or hidden users](https://opendistro.github.io/for-elasticsearch-docs/docs/security/access-control/api/#read-only-and-hidden-resources), we **highly** recommend using Kibana or the REST API to create new users, roles, and role mappings. The `.yml` files are for initial setup, not ongoing use.

---

<div class="post-metadata">

**Author:** ![stmx38](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/stmx38/32/4354_2.png) [@stmx38](https://forum.opensearch.org/u/stmx38)\
**Post date:** [September 14, 2020, 7:01am UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/8 "2020-09-14T07:01:34Z")

</div>

It probably may depends on the you configuration management. In our case, with lees then 50 users it is easier to store all of them in the configuration files and in case of the restore all of them will be ready for the usage.  
We probably can store users creation scripts via API in IAC as well but we should think about their passwords and with configs we store just password hashes.

---

<div class="post-metadata">

**Author:** ![tony](https://avatars.discourse-cdn.com/v4/letter/t/ee7513/32.png) [@tony](https://forum.opensearch.org/u/tony)\
**Post date:** [September 14, 2020, 7:13am UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/9 "2020-09-14T07:13:05Z")

</div>

The simplest way is to dump a config using the api and then adjust to your needs, you then load them back in with curl through the api.You can then keep all your config in a repo that you back up and keep building it up. We keep passwords in AWS SSM and the script pre-populates the password before it loads the configs back in.

---

<div class="post-metadata">

**Author:** ![bonwier](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/bonwier/32/798_2.png) [@bonwier](https://forum.opensearch.org/u/bonwier)\
**Post date:** [September 14, 2020, 9:59pm UTC](https://forum.opensearch.org/t/best-option-for-automating-role-creation-in-kibana/3438/10 "2020-09-14T21:59:42Z")

</div>

Thank you ALL for your replies – these are REALLY good thoughts that extend my thinking and they are much appreciated. The API - - that is an interesting thought and I will speak to your API guru but for right now - we have VERY little in Kibana changes to manually do so it would be easiest to just go manual for the time being.

Thanks again for taking your time to comment and I appreciate them all

cwc
