0Pricing
Elasticsearch & Full Text Search Systems · レッスン

ユーザー認証とロール

ユーザー認証を設定し、ロールを作成して権限を割り当てることで、クラスターへのアクセス者と実行可能な操作を制御します。

「ユーザー認証とロール」はCoddyKit上の無料Elasticsearch & Full Text Search Systemsレッスンです。 これはレッスン1/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはElasticsearch & Full Text Search Systems学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Elasticsearch & Full Text Search Systemsコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

Securing Your Search Data

Imagine your search engine holds sensitive customer data or internal documents. Without proper security, anyone could potentially access, modify, or delete it.

This lesson will show you how to protect your Elasticsearch cluster by controlling who can do what.

Elasticsearch Security Features

Elasticsearch's security features, part of what was formerly X-Pack, provide robust controls for your cluster. They include:

  • Authentication: Verifying user identities.
  • Authorization: Defining what authenticated users can do.
  • Encryption: Securing communication.

We'll focus on authentication and authorization in this lesson.

Activating Security Settings

To enable security, you need to configure your elasticsearch.yml file. This is typically done during the initial setup of your cluster.

Add the following line to enable security features in your configuration:

xpack.security.enabled: true

Built-in Administrator Users

When security is enabled, Elasticsearch creates several built-in users with predefined roles. The most important is the elastic user.

  • elastic: The superuser, with full administrative privileges. Use this for initial setup and critical operations.
  • kibana_system: Used by Kibana to connect to Elasticsearch.
  • logstash_system: Used by Logstash for monitoring.

You'll set passwords for these during the initial setup process.

Creating Your First User

Let's create a new user named dev_user. We'll use the Elasticsearch Users API, which allows you to manage users via REST calls.

This API call creates a user and sets their password. Remember to use strong, unique passwords!

PUT /_security/user/dev_user
{
  "password": "myStrongPassword123",
  "full_name": "Developer User",
  "email": "dev@example.com"
}

Defining User Permissions with Roles

In Elasticsearch, roles are central to authorization. A role is a collection of privileges that define what actions a user can perform.

  • Simplifies Management: Assign a role, not individual permissions, to users.
  • Granular Control: Roles can grant cluster-level and index-level privileges.
  • Cumulative: Users can have multiple roles, and their privileges are combined.

Common Predefined Roles

Elasticsearch comes with several useful built-in roles, providing common sets of permissions:

  • superuser: Grants all privileges across the cluster.
  • viewer: Can read data from all indices.
  • editor: Can read and write data to all indices.
  • kibana_user: Allows access to Kibana features.

These roles are great starting points, but often you'll need more specific control.

Crafting Custom Roles

Let's create a custom role called my_app_reader that can only read data from an index named my_application_data.

This role grants read and view_index_metadata privileges on a specific index. It also includes basic cluster monitoring privileges.

PUT /_security/role/my_app_reader
{
  "cluster": [
    "monitor",
    "read_ilm"
  ],
  "indices": [
    {
      "names": [ "my_application_data" ],
      "privileges": [ "read", "view_index_metadata" ]
    }
  ]
}

Assigning Roles to Users

Now that we have our dev_user and my_app_reader role, let's assign the role to the user. We'll update the dev_user to have this role.

Remember, users can be assigned multiple roles, inheriting all privileges from each one they possess.

PUT /_security/user/dev_user
{
  "password": "myStrongPassword123",
  "full_name": "Developer User",
  "email": "dev@example.com",
  "roles": [ "my_app_reader" ]
}

Understanding Roles & Privileges

Consider a user named analyst. This user has two roles assigned:

  • sales_reader: Grants read privilege on the sales_data index.
  • finance_writer: Grants read and write privileges on the finance_reports index.

Which of the following actions are permitted for the analyst user?

Recap: Secure Your Cluster

You've learned the fundamentals of Elasticsearch security!

  • We discussed why security is crucial for your data.
  • Explored how to enable security and identify built-in users.
  • Understood roles as collections of privileges.
  • Created custom users and roles using the Security API.
  • Assigned roles to users to control access.

Proper authentication and authorization are key to a secure and robust Elasticsearch deployment.

よくある質問

「ユーザー認証とロール」レッスンは無料ですか?

はい。「ユーザー認証とロール」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Elasticsearch & Full Text Search Systemsコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Elasticsearch & Full Text Search Systemsコースには全4レッスンが含まれています。

「ユーザー認証とロール」で何を学びますか?

ユーザー認証を設定し、ロールを作成して権限を割り当てることで、クラスターへのアクセス者と実行可能な操作を制御します。 ブラウザで直接実行するハンズオンコードでElasticsearch & Full Text Search Systemsを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Elasticsearch & Full Text Search Systemsを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのElasticsearch & Full Text Search Systemsは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン1/4です。

「ユーザー認証とロール」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このElasticsearch & Full Text Search Systemsレッスンでコードを書いて実行できますか?

はい。すべてのElasticsearch & Full Text Search Systemsレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. ユーザー認証とロール
  2. フィールドレベルおよびドキュメントレベルのセキュリティ
  3. TLS/SSLとネットワークセキュリティ
  4. APIキーと監査ログ
← Elasticsearch & Full Text Search Systemsに戻る