Windows部署Elasticsearch、Kibana报indices:admin/create权限错误
Windows部署Elasticsearch+Kibana保存对象迁移权限报错问题
问题现象
Windows环境部署Elasticsearch与Kibana,Elasticsearch启动运行正常,启动Kibana服务时,保存对象迁移流程触发持续重试的权限报错。
报错核心逻辑:用户kunal持有monitoring、network、admins、demorole角色,无权限对受限索引.kibana_task_manager_8.3.2_001、.kibana_8.3.2_001执行[indices:admin/create]操作,该操作需要create_index、manage或all索引权限。
核心报错日志
[2022-07-08T17:21:28.195+05:30][INFO ][savedobjects-service] Starting saved objects migrations [2022-07-08T17:21:28.231+05:30][INFO ][savedobjects-service] [.kibana] INIT -> CREATE_NEW_TARGET. took: 18ms. [2022-07-08T17:21:28.235+05:30][INFO ][savedobjects-service] [.kibana_task_manager] INIT -> CREATE_NEW_TARGET. took: 20ms. [2022-07-08T17:21:28.245+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 1 in 2 seconds. [2022-07-08T17:21:28.246+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 10ms. [2022-07-08T17:21:28.248+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 1 in 2 seconds. [2022-07-08T17:21:28.248+05:30][INFO ][savedobjects-service] [.kibana] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 18ms. [2022-07-08T17:21:30.276+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 2 in 4 seconds. [2022-07-08T17:21:30.277+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 2031ms. [2022-07-08T17:21:30.284+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 2 in 4 seconds. [2022-07-08T17:21:30.285+05:30][INFO ][savedobjects-service] [.kibana] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 2036ms. [2022-07-08T17:21:34.311+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 3 in 8 seconds. [2022-07-08T17:21:34.313+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 4035ms. [2022-07-08T17:21:34.321+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 3 in 8 seconds.
现有权限配置
roles.yml配置
# The default roles file is empty as the preferred method of defining roles is # through the API/UI. File based roles are useful in error scenarios when the # API based roles may not be available. admins: cluster: - all indices: - names: - "*" privileges: - all devs: cluster: - manage indices: - names: - "*" privileges: - write - delete - create_index
users_roles配置
monitoring:kunal network:kunal admins:kunal
问题根因
- Elasticsearch 8.x版本对
.kibana*、.kibana_task_manager*这类系统级受限索引做了特殊权限管控,普通的*通配符索引权限默认不会覆盖这类受限索引,必须在权限条目中显式设置allow_restricted_indices: true,权限才会对受限索引生效。当前admins角色虽然配置了所有索引的all权限,但未开启受限索引访问授权,所以创建Kibana系统索引时会被权限拦截。 - 常见配置误区:Kibana执行保存对象迁移使用的是
kibana.yml中elasticsearch.username配置的后台连接账号,不是前端页面登录Kibana的用户账号,如果配置项填错账号,也会触发权限报错。 - 额外排查点:用户kunal绑定的
demorole角色如果配置了针对.kibana*索引的拒绝权限,由于ES权限规则拒绝优先级高于允许,哪怕admins角色给了全权限也会被拦截。
修复步骤
- 修改Elasticsearch配置目录下的
roles.yml文件,调整admins角色配置,推荐采用最小权限原则单独给Kibana系统索引授权,不要全局开启所有受限索引的访问:
admins: cluster: - all indices: - names: - "*" privileges: - all # 单独授予Kibana相关受限索引的全权限 - names: - ".kibana*" - ".kibana_task_manager*" privileges: - all allow_restricted_indices: true
- 打开Kibana配置目录下的
kibana.yml文件,确认elasticsearch.username配置值为kunal,elasticsearch.password对应该用户的正确密码,避免后台连ES用了错误账号。 - 检查
demorole角色的权限配置,删除所有针对.kibana*索引的拒绝规则。 - 重启所有Elasticsearch节点,让roles.yml的配置生效;如果之前启动失败残留了异常状态的Kibana相关索引,先删除
.kibana*、.kibana_task_manager*开头的索引,再重启Kibana服务即可正常完成保存对象迁移。
内容的提问来源于stack exchange,提问作者Kunal Bhangale
相关产品推荐
相关产品推荐

