-
Notifications
You must be signed in to change notification settings - Fork 25.4k
Closed
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACgood first issuelow hanging fruitlow hanging fruit
Description
Describe the feature:
Currently retrieving repository and snapshot metadata from Elasticsearch requires at least the create_snapshot
privilege, which is too permissive for just monitoring the existing repositories and snaphots.
For read-only access to repositories and snapshots metadata (possibly via unauthenticated users) it would be preferable to allow more fine-grained control by adding an additional monitor_snapshot
cluster privilege.
Metadata
Metadata
Assignees
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACgood first issuelow hanging fruitlow hanging fruit