Skip to content

Remove read_connector_secrets named privilege #110414

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

navarone-feekery
Copy link
Contributor

  • Remove the read_connector_secrets user-facing named privilege entirely, as it is only required for Enterprise Search.
  • Replace read_connector_secrets privilege for Enterprise Search with the raw action name cluster:admin/xpack/connector/secret/get

Copy link
Contributor

github-actions bot commented Jul 3, 2024

Documentation preview:

@navarone-feekery navarone-feekery marked this pull request as ready for review July 3, 2024 14:31
@navarone-feekery navarone-feekery requested a review from a team as a code owner July 3, 2024 14:31
@elasticsearchmachine elasticsearchmachine added the needs:triage Requires assignment of a team area label label Jul 3, 2024
@navarone-feekery navarone-feekery added Team:Enterprise Search Meta label for Enterprise Search team :EnterpriseSearch/Application Enterprise Search labels Jul 3, 2024
@elasticsearchmachine elasticsearchmachine removed the Team:Enterprise Search Meta label for Enterprise Search team label Jul 3, 2024
@navarone-feekery navarone-feekery added the Team:Enterprise Search Meta label for Enterprise Search team label Jul 3, 2024
@elasticsearchmachine elasticsearchmachine removed the needs:triage Requires assignment of a team area label label Jul 3, 2024
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/ent-search-eng (Team:Enterprise Search)

@navarone-feekery navarone-feekery added >non-issue needs:triage Requires assignment of a team area label labels Jul 3, 2024
@elasticsearchmachine elasticsearchmachine removed the needs:triage Requires assignment of a team area label label Jul 3, 2024
Copy link
Member

@seanstory seanstory left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:rubberstamp:, but real review should be done by security folks

@n1v0lg n1v0lg self-requested a review July 9, 2024 14:13
@n1v0lg
Copy link
Contributor

n1v0lg commented Jul 9, 2024

@elasticmachine update branch

@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/search-eng (Team:Enterprise Search)

@navarone-feekery
Copy link
Contributor Author

Closing because outdated.

@navarone-feekery navarone-feekery deleted the remove-read-connector-secrets branch February 6, 2025 17:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:EnterpriseSearch/Application Enterprise Search >non-issue Team:Enterprise Search Meta label for Enterprise Search team v9.1.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants