مصادقة المستخدمين وأدوارهم
اضبط مصادقة المستخدمين وأنشئ الأدوار وعيّن الأذونات للتحكم في من يمكنه الوصول إلى عنقودك والإجراءات التي يمكنه تنفيذها
مصادقة المستخدمين وأدوارهم درس مجاني في Elasticsearch & Full Text Search Systems على CoddyKit. هذا هو الدرس 1 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Elasticsearch & Full Text Search Systems، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Elasticsearch & Full Text Search Systems 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Securing Your Search Data
Imagine your search engine holds sensitive customer data or internal documents. Without proper security, anyone could potentially access, modify, or delete it.
This lesson will show you how to protect your Elasticsearch cluster by controlling who can do what.
Elasticsearch Security Features
Elasticsearch's security features, part of what was formerly X-Pack, provide robust controls for your cluster. They include:
- Authentication: Verifying user identities.
- Authorization: Defining what authenticated users can do.
- Encryption: Securing communication.
We'll focus on authentication and authorization in this lesson.
Activating Security Settings
To enable security, you need to configure your elasticsearch.yml file. This is typically done during the initial setup of your cluster.
Add the following line to enable security features in your configuration:
xpack.security.enabled: trueBuilt-in Administrator Users
When security is enabled, Elasticsearch creates several built-in users with predefined roles. The most important is the elastic user.
elastic: The superuser, with full administrative privileges. Use this for initial setup and critical operations.kibana_system: Used by Kibana to connect to Elasticsearch.logstash_system: Used by Logstash for monitoring.
You'll set passwords for these during the initial setup process.
Creating Your First User
Let's create a new user named dev_user. We'll use the Elasticsearch Users API, which allows you to manage users via REST calls.
This API call creates a user and sets their password. Remember to use strong, unique passwords!
PUT /_security/user/dev_user
{
"password": "myStrongPassword123",
"full_name": "Developer User",
"email": "dev@example.com"
}Defining User Permissions with Roles
In Elasticsearch, roles are central to authorization. A role is a collection of privileges that define what actions a user can perform.
- Simplifies Management: Assign a role, not individual permissions, to users.
- Granular Control: Roles can grant cluster-level and index-level privileges.
- Cumulative: Users can have multiple roles, and their privileges are combined.
Common Predefined Roles
Elasticsearch comes with several useful built-in roles, providing common sets of permissions:
superuser: Grants all privileges across the cluster.viewer: Can read data from all indices.editor: Can read and write data to all indices.kibana_user: Allows access to Kibana features.
These roles are great starting points, but often you'll need more specific control.
Crafting Custom Roles
Let's create a custom role called my_app_reader that can only read data from an index named my_application_data.
This role grants read and view_index_metadata privileges on a specific index. It also includes basic cluster monitoring privileges.
PUT /_security/role/my_app_reader
{
"cluster": [
"monitor",
"read_ilm"
],
"indices": [
{
"names": [ "my_application_data" ],
"privileges": [ "read", "view_index_metadata" ]
}
]
}Assigning Roles to Users
Now that we have our dev_user and my_app_reader role, let's assign the role to the user. We'll update the dev_user to have this role.
Remember, users can be assigned multiple roles, inheriting all privileges from each one they possess.
PUT /_security/user/dev_user
{
"password": "myStrongPassword123",
"full_name": "Developer User",
"email": "dev@example.com",
"roles": [ "my_app_reader" ]
}Understanding Roles & Privileges
Consider a user named analyst. This user has two roles assigned:
sales_reader: Grantsreadprivilege on thesales_dataindex.finance_writer: Grantsreadandwriteprivileges on thefinance_reportsindex.
Which of the following actions are permitted for the analyst user?
Recap: Secure Your Cluster
You've learned the fundamentals of Elasticsearch security!
- We discussed why security is crucial for your data.
- Explored how to enable security and identify built-in users.
- Understood roles as collections of privileges.
- Created custom users and roles using the Security API.
- Assigned roles to users to control access.
Proper authentication and authorization are key to a secure and robust Elasticsearch deployment.
الأسئلة الشائعة
هل درس «مصادقة المستخدمين وأدوارهم» مجاني؟
نعم — نص درس «مصادقة المستخدمين وأدوارهم» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Elasticsearch & Full Text Search Systems، انتقل إلى CoddyKit PRO. تتضمن دورة Elasticsearch & Full Text Search Systems 4 دروس في المجموع.
ماذا ستتعلم في «مصادقة المستخدمين وأدوارهم»؟
اضبط مصادقة المستخدمين وأنشئ الأدوار وعيّن الأذونات للتحكم في من يمكنه الوصول إلى عنقودك والإجراءات التي يمكنه تنفيذها تتمرن على Elasticsearch & Full Text Search Systems مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ Elasticsearch & Full Text Search Systems؟
لا تُشترط خبرة سابقة. Elasticsearch & Full Text Search Systems على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 1 من أصل 4.
كم من الوقت يستغرق درس «مصادقة المستخدمين وأدوارهم»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس Elasticsearch & Full Text Search Systems هذا؟
نعم. كل درس في Elasticsearch & Full Text Search Systems يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- مصادقة المستخدمين وأدوارهم
- أمان مستوى الحقول والمستندات
- أمان TLS/SSL وأمان الشبكة
- مفاتيح API وتسجيل التدقيق