You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows部署Elasticsearch、Kibana报indices:admin/create权限错误

Windows部署Elasticsearch+Kibana保存对象迁移权限报错问题

问题现象

Windows环境部署Elasticsearch与Kibana,Elasticsearch启动运行正常,启动Kibana服务时,保存对象迁移流程触发持续重试的权限报错。
报错核心逻辑:用户kunal持有monitoring、network、admins、demorole角色,无权限对受限索引.kibana_task_manager_8.3.2_001、.kibana_8.3.2_001执行[indices:admin/create]操作,该操作需要create_index、manage或all索引权限。

核心报错日志

[2022-07-08T17:21:28.195+05:30][INFO ][savedobjects-service] Starting saved objects migrations
[2022-07-08T17:21:28.231+05:30][INFO ][savedobjects-service] [.kibana] INIT -> CREATE_NEW_TARGET. took: 18ms.
[2022-07-08T17:21:28.235+05:30][INFO ][savedobjects-service] [.kibana_task_manager] INIT -> CREATE_NEW_TARGET. took: 20ms.
[2022-07-08T17:21:28.245+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 1 in 2 seconds.
[2022-07-08T17:21:28.246+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 10ms.
[2022-07-08T17:21:28.248+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 1 in 2 seconds.
[2022-07-08T17:21:28.248+05:30][INFO ][savedobjects-service] [.kibana] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 18ms.
[2022-07-08T17:21:30.276+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 2 in 4 seconds.
[2022-07-08T17:21:30.277+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 2031ms.
[2022-07-08T17:21:30.284+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 2 in 4 seconds.
[2022-07-08T17:21:30.285+05:30][INFO ][savedobjects-service] [.kibana] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 2036ms.
[2022-07-08T17:21:34.311+05:30][ERROR][savedobjects-service] [.kibana_task_manager] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_task_manager_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 3 in 8 seconds.
[2022-07-08T17:21:34.313+05:30][INFO ][savedobjects-service] [.kibana_task_manager] CREATE_NEW_TARGET -> CREATE_NEW_TARGET. took: 4035ms.
[2022-07-08T17:21:34.321+05:30][ERROR][savedobjects-service] [.kibana] Action failed with 'security_exception: [security_exception] Reason: action [indices:admin/create] is unauthorized for user [kunal] with roles [monitoring,network,admins,demorole] on restricted indices [.kibana_8.3.2_001], this action is granted by the index privileges [create_index,manage,all]'. Retrying attempt 3 in 8 seconds.

现有权限配置

roles.yml配置

# The default roles file is empty as the preferred method of defining roles is
# through the API/UI. File based roles are useful in error scenarios when the
# API based roles may not be available.
admins:
  cluster:
    - all
  indices:
    - names:
        - "*"
      privileges:
        - all
devs:
  cluster:
    - manage
  indices:
    - names:
        - "*"
      privileges:
        - write
        - delete
        - create_index

users_roles配置

monitoring:kunal
network:kunal
admins:kunal

问题根因

  • Elasticsearch 8.x版本对.kibana*、.kibana_task_manager*这类系统级受限索引做了特殊权限管控,普通的*通配符索引权限默认不会覆盖这类受限索引,必须在权限条目中显式设置allow_restricted_indices: true,权限才会对受限索引生效。当前admins角色虽然配置了所有索引的all权限,但未开启受限索引访问授权,所以创建Kibana系统索引时会被权限拦截。
  • 常见配置误区:Kibana执行保存对象迁移使用的是kibana.yml中elasticsearch.username配置的后台连接账号,不是前端页面登录Kibana的用户账号,如果配置项填错账号,也会触发权限报错。
  • 额外排查点:用户kunal绑定的demorole角色如果配置了针对.kibana*索引的拒绝权限,由于ES权限规则拒绝优先级高于允许,哪怕admins角色给了全权限也会被拦截。

修复步骤

  • 修改Elasticsearch配置目录下的roles.yml文件,调整admins角色配置,推荐采用最小权限原则单独给Kibana系统索引授权,不要全局开启所有受限索引的访问:
admins:
  cluster:
    - all
  indices:
    - names:
        - "*"
      privileges:
        - all
    # 单独授予Kibana相关受限索引的全权限
    - names:
        - ".kibana*"
        - ".kibana_task_manager*"
      privileges:
        - all
      allow_restricted_indices: true
  • 打开Kibana配置目录下的kibana.yml文件,确认elasticsearch.username配置值为kunal,elasticsearch.password对应该用户的正确密码,避免后台连ES用了错误账号。
  • 检查demorole角色的权限配置,删除所有针对.kibana*索引的拒绝规则。
  • 重启所有Elasticsearch节点,让roles.yml的配置生效;如果之前启动失败残留了异常状态的Kibana相关索引,先删除.kibana*、.kibana_task_manager*开头的索引,再重启Kibana服务即可正常完成保存对象迁移。

内容的提问来源于stack exchange,提问作者Kunal Bhangale

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.26 22:57:21