Stack management
Users, roles, role mappings and API keys on Elasticsearch; internal users, roles and tenants with the OpenSearch Security plugin; plus lifecycle, snapshots, pipelines, nodes and tasks.
Stack management works on the active connection. The sidebar has three groups — Security, Data and Cluster — and shows who you’re signed in as.
kabanos talks to the right API for each engine: _security on Elasticsearch and the Security plugin’s _plugins/_security/api on OpenSearch. If security isn’t enabled (or the OpenSearch plugin isn’t installed), you’ll see Security is not available with the reason — the Data and Cluster pages still work.
Users
The list shows each user’s username, full name, roles and whether they’re enabled. On OpenSearch, backend roles are shown too.
- Create user — username, password (at least 6 characters), full name, email and roles (with suggestions). On OpenSearch you can also set backend roles.
- Edit a user to change their details or set a New password (leave it blank to keep the current one).
- Enable / Disable — Elasticsearch only. OpenSearch internal users can’t be disabled; remove their roles instead.
- Delete — not offered for built-in (reserved) users.
Roles
Hide built-in filters out reserved roles. The list shows cluster and index privileges and marks roles that use FLS (field-level security) or DLS (document-level security).
The role editor has:
- Cluster privileges.
- One or more Index privileges blocks: index patterns, privileges, Field-level security (fields to grant or to exclude — on OpenSearch, one or the other), a Document-level query (JSON) and, on OpenSearch, Masked fields.
Privilege names are suggested from the cluster. On Elasticsearch, field- and document-level security need a Platinum or Enterprise license (or a trial). Built-in roles are read-only.
Role mappings
Map users to roles automatically.
- Elasticsearch — a name, the roles to grant, Enabled, and the mapping Rules as JSON (for example
{"field": {"username": "*"}}). - OpenSearch — pick a role, then list the Users, Backend roles and Hosts that get it.
API keys (Elasticsearch)
The list shows each key’s name, owner, creation and expiry date; Show invalidated includes revoked keys.
Create API key takes a name and an optional expiration such as 30d (leave it empty for a key that never expires). The key gets the privileges of the user you’re signed in as. The new key is shown once — copy it right away; Elasticsearch never shows it again. Invalidate revokes a key.
Tenants (OpenSearch)
List, add (name and description) and delete OpenSearch Dashboards tenants. Built-in tenants can’t be deleted.
Data
These pages are read-only overviews:
- Index lifecycle — ILM policies on Elasticsearch (with the indices using them), ISM policies on OpenSearch, with their JSON.
- Snapshots — repositories and their snapshots.
- Ingest pipelines — every pipeline and its processors.
- Index templates — click one to open it in the Explorer, where it can be edited.
Cluster
- Nodes — every node with its roles, heap, CPU, load, disk and version.
- Settings — persistent and transient cluster settings that differ from the defaults. Change them from the workspace with
PUT _cluster/settings. - Tasks — live, refreshing every 3 seconds. By default it shows the tasks you care about — searches, reindexes, update/delete-by-query, bulk, snapshots and force merges; tick Include internal tasks to see everything. Cancellable tasks have a Cancel button. Requests sent by kabanos carry an opaque id (
kabanos-…), shown in the list, so you can tell your own tasks apart.
All writes on these pages go through the same production confirmation and read-only rules as everywhere else.