Stack management

Users, roles, role mappings and API keys on Elasticsearch; internal users, roles and tenants with the OpenSearch Security plugin; plus lifecycle, snapshots, pipelines, nodes and tasks.

Stack management works on the active connection. The sidebar has three groups — Security, Data and Cluster — and shows who you’re signed in as.

kabanos talks to the right API for each engine: _security on Elasticsearch and the Security plugin’s _plugins/_security/api on OpenSearch. If security isn’t enabled (or the OpenSearch plugin isn’t installed), you’ll see Security is not available with the reason — the Data and Cluster pages still work.

Users

The list shows each user’s username, full name, roles and whether they’re enabled. On OpenSearch, backend roles are shown too.

  • Create user — username, password (at least 6 characters), full name, email and roles (with suggestions). On OpenSearch you can also set backend roles.
  • Edit a user to change their details or set a New password (leave it blank to keep the current one).
  • Enable / Disable — Elasticsearch only. OpenSearch internal users can’t be disabled; remove their roles instead.
  • Delete — not offered for built-in (reserved) users.

Roles

Hide built-in filters out reserved roles. The list shows cluster and index privileges and marks roles that use FLS (field-level security) or DLS (document-level security).

The role editor has:

  • Cluster privileges.
  • One or more Index privileges blocks: index patterns, privileges, Field-level security (fields to grant or to exclude — on OpenSearch, one or the other), a Document-level query (JSON) and, on OpenSearch, Masked fields.

Privilege names are suggested from the cluster. On Elasticsearch, field- and document-level security need a Platinum or Enterprise license (or a trial). Built-in roles are read-only.

Role mappings

Map users to roles automatically.

  • Elasticsearch — a name, the roles to grant, Enabled, and the mapping Rules as JSON (for example {"field": {"username": "*"}}).
  • OpenSearch — pick a role, then list the Users, Backend roles and Hosts that get it.

API keys (Elasticsearch)

The list shows each key’s name, owner, creation and expiry date; Show invalidated includes revoked keys.

Create API key takes a name and an optional expiration such as 30d (leave it empty for a key that never expires). The key gets the privileges of the user you’re signed in as. The new key is shown once — copy it right away; Elasticsearch never shows it again. Invalidate revokes a key.

Tenants (OpenSearch)

List, add (name and description) and delete OpenSearch Dashboards tenants. Built-in tenants can’t be deleted.

Data

These pages are read-only overviews:

  • Index lifecycle — ILM policies on Elasticsearch (with the indices using them), ISM policies on OpenSearch, with their JSON.
  • Snapshots — repositories and their snapshots.
  • Ingest pipelines — every pipeline and its processors.
  • Index templates — click one to open it in the Explorer, where it can be edited.

Cluster

  • Nodes — every node with its roles, heap, CPU, load, disk and version.
  • Settings — persistent and transient cluster settings that differ from the defaults. Change them from the workspace with PUT _cluster/settings.
  • Tasks — live, refreshing every 3 seconds. By default it shows the tasks you care about — searches, reindexes, update/delete-by-query, bulk, snapshots and force merges; tick Include internal tasks to see everything. Cancellable tasks have a Cancel button. Requests sent by kabanos carry an opaque id (kabanos-…), shown in the list, so you can tell your own tasks apart.

All writes on these pages go through the same production confirmation and read-only rules as everywhere else.