You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为特定人员授予AWS-Elasticsearch实例的Kibana访问权限?

Great question—IP whitelisting is such a headache when your team members have dynamic IPs (like working from home or traveling). Let’s break down the most practical, AWS-native ways to lock down your AWS Elasticsearch (now Amazon OpenSearch Service) Kibana access to only specific users, no static IP required:

1. IAM Authentication + Fine-Grained Access Control (FGAC)

This is the go-to native solution if you want to leverage AWS’s existing IAM system:

  • First, enable Fine-Grained Access Control in your OpenSearch domain settings. You’ll set a primary admin user (can be an IAM role or internal user) during setup.
  • Create dedicated IAM users (or use existing ones) for each person who needs Kibana access. Attach a custom IAM policy that grants them basic access to the OpenSearch domain, like this:
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "es:ESHttpGet",
            "es:ESHttpPost",
            "es:ESHttpPut",
            "es:ESHttpDelete"
          ],
          "Resource": "arn:aws:es:your-region:your-account-id:domain/your-domain-name/*"
        },
        {
          "Effect": "Allow",
          "Action": "es:ESHttpHead",
          "Resource": "arn:aws:es:your-region:your-account-id:domain/your-domain-name"
        }
      ]
    }
    
  • Next, in the OpenSearch Dashboard (or via the API), create a custom role (e.g., kibana-team-access) and assign it specific Kibana permissions—like allowing login, viewing dashboards, or editing specific indices.
  • Map your IAM users to this OpenSearch role. When users access the Kibana URL, they can select "IAM Authentication" and use their AWS credentials (pro tip: use AWS IAM Identity Center (formerly SSO) to generate temporary credentials instead of long-term access keys for better security).
2. SAML Single Sign-On (SSO)

Perfect for enterprise teams that already use an identity provider (IdP) like Active Directory, Okta, or Azure AD:

  • Enable SAML authentication in your OpenSearch domain settings, then upload your IdP’s metadata file (or input the IdP’s URL and certificate manually).
  • In your IdP, create a user group and add only the specific people who need Kibana access.
  • Back in OpenSearch, create a role with the desired Kibana permissions and map it to the IdP user group.
  • When users hit the Kibana URL, they’ll be redirected to your company’s IdP login page. Once authenticated, they’ll automatically get access to Kibana—no IP checks or AWS keys needed.
3. Amazon Cognito User Pool Integration

Ideal if you don’t have an existing IdP and want a managed user authentication system:

  • Create an Amazon Cognito user pool, then add individual users (or let users sign up and you approve their accounts). You can even enable multi-factor authentication (MFA) for extra security.
  • In your OpenSearch domain settings, configure Cognito as the identity provider, linking your user pool and a corresponding Cognito identity pool.
  • Create OpenSearch roles with the right Kibana permissions and map them to Cognito users or groups.
  • Users will log into Kibana via a Cognito-hosted login page, and only approved users will get access.
Key Tips
  • If you had an IP whitelist enabled before, narrow it down to only essential IPs (like internal monitoring systems) or disable it entirely once you set up one of these auth methods.
  • Use Fine-Grained Access Control to restrict what users can do in Kibana—for example, give analysts read-only access to dashboards, while admins get full editing rights.
  • Avoid long-term AWS access keys whenever possible; IAM Identity Center or temporary credentials are far more secure.

内容的提问来源于stack exchange,提问作者Manoharsinh Rana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:45:39