-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Open
Labels
:Data Management/ILM+SLMIndex and Snapshot lifecycle managementIndex and Snapshot lifecycle management:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACTeam:Data ManagementMeta label for data/management teamMeta label for data/management teamTeam:SecurityMeta label for security teamMeta label for security team
Description
The description from SLM with Security is a bit unclear to me.
The list mentions privileges to create and delete snapshots (cluster:admin/snapshot/*) when working with SLM, but from my reading of the SLM code that is not necessary. The internal client used by the SLM tasks runs under sufficient privileges to create and remove snapshots, irrespective of the users privileges.
I think we should proceed to remove the cluster:admin/snapshot/* mention in the docs.
Maybe someone from @elastic/es-core-features can verify my theory.
Metadata
Metadata
Assignees
Labels
:Data Management/ILM+SLMIndex and Snapshot lifecycle managementIndex and Snapshot lifecycle management:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACTeam:Data ManagementMeta label for data/management teamMeta label for data/management teamTeam:SecurityMeta label for security teamMeta label for security team