# Force index allocation for. opendistro, .opensearch index

**URL:** <https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777>\
**Category:** Security\
**Tags:** configure\
**Created:** [September 5, 2023, 5:13pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777 "2023-09-05T17:13:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 5, 2023, 5:13pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/1 "2023-09-05T17:13:39Z")

</div>

\*\* version 2.2.0\*\*

**Describe the issue** :  
I added 2 new data nodes on in my opensearch Cluster to store the logs of our API-Gateway

I dont want .opensearch\* and .opendistro\* indexes to be created on these 2 new nodes  
So I set a rack id for my existing nodes called applicative\_rack

And i created ( successfully) 2 index templates for these indexes as follow : ( to force allocating these system indexes on the applicative\_rack and not on the new nodes for which rack id is different ) :  
POST /\_index\_template/opendistro { “index\_patterns”: [“.opendistro\*”], “template”: { “settings”: { “index.routing.allocation.require.rack”: “applicative\_rack” } }}  
POST /\_index\_template/opensearch { “index\_patterns”: [“.opensearch\*”], “template”: { “settings”: { “index.routing.allocation.require.rack”: “applicative\_rack” } }}

But when I started my new Opensearch data nodes :  
it seems the .opendistro\* and .opensearch\* indexes are created on them ( the new nodes ) and the index templates are absolutely NOT applied ( issue occurs only for these system indexes, no issue with any others indexes… )

Why can t I force index allocation for : .opendistro\* and .opensearch\* indexes ?  
( mainly:  
.opendistro-job-scheduler-lock  
.opendistro-ism-managed-index-history  
.opendistro-alerting-config  
.opensearch-notifications-config  
)  
Is there any other way to proceed and force allocation for these system indexes ?

Regards

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [September 6, 2023, 8:59am UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/2 "2023-09-06T08:59:03Z")

</div>

> [@kristof.larcher](#):
>
> ( mainly:  
> .opendistro-job-scheduler-lock  
> .opendistro-ism-managed-index-history  
> .opendistro-alerting-config  
> .opensearch-notifications-config  
> )

@kristof.larcher Could you share the settings of these indices?

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:09pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/3 "2023-09-10T19:09:20Z")

</div>

I found out the solution 🙂

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:10pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/4 "2023-09-10T19:10:41Z")

</div>

You cant set configuration for these system indexes aven with user ADMIN  
but

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:14pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/5 "2023-09-10T19:14:14Z")

</div>

if you use the admin\_dn set with security plugin ( confer conf )  
You can do whatever you want…

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:15pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/6 "2023-09-10T19:15:15Z")

</div>

conf in opensearch.yml  
plugins.security.authcz.admin\_dn: CN=kirk,OU=client,O=client,L=test, C=de

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:18pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/7 "2023-09-10T19:18:12Z")

</div>

and curl request to push index template fo system index ( forcing allocation to a rack )  
curl -k --cert ./kirk.pem --key ./kirk-key.pem -X PUT [https://localhost:9200/\_index\_template/opensearch](https://localhost:9200/_index_template/opensearch) -d ‘{ “index\_patterns”: [“.opensearch\*”], “template”: { “settings”: { “index.routing.allocation.require.rack”: “applicative\_rack” }}}’ -H 'Content-Type: application/json

---

<div class="post-metadata">

**Author:** ![kristof.larcher](https://avatars.discourse-cdn.com/v4/letter/k/bb73d2/32.png) [@kristof.larcher](https://forum.opensearch.org/u/kristof.larcher)\
**Post date:** [September 10, 2023, 7:19pm UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/8 "2023-09-10T19:19:04Z")

</div>

it s mentionned i n any documentation

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [October 25, 2023, 10:49am UTC](https://forum.opensearch.org/t/force-index-allocation-for-opendistro-opensearch-index/15777/9 "2023-10-25T10:49:13Z")

</div>

@kristof.larcher As per OpenSearch documentation, the securityadmin.sh script is used to manage the security plugin. The plugin requires admin certificate that is defined in the admin\_dn in opensearch.yml

> **[Applying changes to configuration files](https://opensearch.org/docs/latest/security/configuration/security-admin/#configure-the-admin-certificate)**
>
> Applying changes to configuration files

The secuirtyadmin.sh is using certificate authentication against the HTTP endpoint 9200. Therefore, using the curl command with an admin certificate mimics securityadmin.sh script authentication and allows to access the cluster without basic authentication.
