Skip to content

Update privilege model for API keys #40031

@tvernum

Description

@tvernum

The API Key actions are under the cluster:admin/xpack/security namespace.
The only cluster privileges that allow access to those actions are manage_security and all, both of which grant far more access than is actually required to create an API Key.

There should be a specific privilege to allow a user to create/delete their own API keys.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions