# Difference between opendistro\_security\_roles and backend\_roles

**URL:** <https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434>\
**Category:** Security\
**Tags:** configure\
**Created:** [January 15, 2024, 9:16pm UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434 "2024-01-15T21:16:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DmitryP](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@DmitryP](https://forum.opensearch.org/u/DmitryP)\
**Post date:** [January 15, 2024, 9:16pm UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/1 "2024-01-15T21:16:28Z")

</div>

Please, explain the differences between “opendistro\_security\_roles” and “backend\_roles” in internal\_users.yml  
And is there documentation explaining all the parameters in internal\_users.yml ?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [January 16, 2024, 12:13am UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/2 "2024-01-16T00:13:42Z")

</div>

@DmitryP When you look at the `Roles` list in OpenSearch Dashboards UI, you’ll find columns `Role` and `Backend roles`

As per documentation, the `opendistro_security_roles` must contain an array of existing role names defined in the `Role` column.

The `backend_roles` must contain a list of backend role names defined in the `Backend roles` column.

> **[API](https://opensearch.org/docs/latest/security/access-control/api/)**
>
> API

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/2/2755d62f252719f49c07fb59ee7f2bf5c686d4db.png)

i.e.

```auto
  opendistro_security_roles: 
  - "kibana_user"
  backend_roles:
  - "kibanauser"

```

---

<div class="post-metadata">

**Author:** ![DmitryP](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@DmitryP](https://forum.opensearch.org/u/DmitryP)\
**Post date:** [January 16, 2024, 7:54am UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/3 "2024-01-16T07:54:02Z")

</div>

@pablo Unfortunately I still don’t understand the meaning of the “opendistro\_security\_roles”.  
As I understand there are roles in OpenSearch. They are mapped to the users based on 3 things ([API - OpenSearch Documentation](https://opensearch.org/docs/latest/security/access-control/api/#role-mappings)):

```auto
GET _plugins/_security/api/rolesmapping
{
  "role_starfleet" : {
    "backend_roles" : ["starfleet", "captains", "defectors", "cn=ldaprole,ou=groups,dc=example,dc=com"],
    "hosts" : ["*.starfleetintranet.com"],
    "users" : ["worf"]
  }
}

```

So the user “wolf”, if he comes from “\*.starfleetintranet.com” and has backend\_role “defectors” gets the role “role\_starfleet”

What do “opendistro\_security\_roles” mean in internal\_users.yml and how are they different from just “roles”? And what are “attributes” and where are they used?

```auto
# Define your internal users here
new-user:
  hash: "$2y$12$88IFVl6IfIwCFh5aQYfOmuXVL9j2hz/GusQb35o.4sdTDAEMTOD.K"
  reserved: false
  hidden: false
  opendistro_security_roles:
  - "specify-some-security-role-here"
  backend_roles:
  - "specify-some-backend-role-here"
  attributes:
    attribute1: "value1"
  static: false

```

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [January 16, 2024, 9:45am UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/4 "2024-01-16T09:45:23Z")

</div>

@DmitryP According to the documentation, `opendistro_security_roles` maps only existing internal roles using their names. You can map any built-in or custom role. It is equivalent to mapping the user in the role.

The `backend roles` are the roles which were sent from IdP during the authorization process (LDAP, SAML, OIDC). You can also define built-in roles using their backend role names i.e., kibanauser, admin, logstash etc.

---

<div class="post-metadata">

**Author:** ![DmitryP](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@DmitryP](https://forum.opensearch.org/u/DmitryP)\
**Post date:** [January 16, 2024, 9:50pm UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/5 "2024-01-16T21:50:02Z")

</div>

Unfortunately official documentation is very unclear for me in this case.  
But as I can understand user’s ‘opendistro\_security\_roles’ property directly set specified roles for that user without any rolemappings.  
And setting ‘backend\_role’ demand rolemapping.  
So if I create user:

```auto
PUT _plugins/_security/api/internalusers/testtest
{
  "password": "aabbccddeeff",
  "opendistro_security_roles": ["security_analytics_ack_alerts"],
  "backend_roles": ["snapshotrestore"],
  "attributes": {
    "attribute1": "value1"
  }
}'

```

and I have rolemapping :

```auto
GET /_plugins/_security/api/rolesmapping/manage_snapshots
{
  "manage_snapshots": {
    "hosts": [],
    "users": [],
    "reserved": false,
    "hidden": false,
    "backend_roles": [
      "snapshotrestore"
    ],
    "and_backend_roles": []
  }
}

```

As a result, the user testtest will have 2 roles: “security\_analytics\_ack\_alerts” and “manage\_snapshots”  
right?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [January 23, 2024, 1:20pm UTC](https://forum.opensearch.org/t/difference-between-opendistro-security-roles-and-backend-roles/17434/6 "2024-01-23T13:20:33Z")

</div>

@DmitryP That is correct. This user will have both roles assigned and backend\_role requires rolemapping.
