I can't access the indices tab of my ES domain in the AWS ElasticSearch console. Here is what it looks like in the console:
Even though I added my IAM ARN (arn:aws:iam::NNNNNNNNNNNNN:root) to the access policy of the console, I am still getting this error:
/_stats: {
"error":{
"root_cause":[
{
"type":"security_exception",
"reason":"no permissions for [indices:monitor/stats] and User [name=arn:aws:iam::NNNNNNNNNNNNN:root, backend_roles=[], requestedTenant=null]"
}
],
"type":"security_exception",
"reason":"no permissions for [indices:monitor/stats] and User [name=arn:aws:iam::NNNNNNNNNNNNN:root, backend_roles=[], requestedTenant=null]"
},
"status":403
}
Any idea what went wrong? The domain has access control with a master password as well.
It turns out my access policy setting itself was correct but if you have the master user account configured using the basic auth in your domain, the indices and the cluster health don't work. After I switched to ARN based master account, it worked.
For Googlers:
As of 2020/01, Amazon ES employs a trick way to determine how fine-granularity authorization is done.
The implications are:
This looks very confusing to users who see IAM users / roles mapped but only to find them unauthorized when accessing the domain.
As you can change master user (with down time) for ES domain, you can change it back and forth to avoid integrating with Cognito, but this is a pain.
This should be more clearly stated, or better emphasized in the official docs.
Please go to action dropdown as shown in the below image, there it will show the current access policy attach with your Elasticsearch domain.
In my case, it looks below and I am able to access the indices tab, Please note that Resources key which has /* means allowed access to all the endpoints in my domain and indices is part of it.
Note: once you have access, you can directly hit _cat/indices?v API to get the details of all indices.