Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSearch Security plugin installed but disabled. This can expose your configuration (including passwords) to the public #30242

Open
yanone1 opened this issue Nov 6, 2024 · 2 comments
Assignees
Labels
in-progress opensearch tech-issues The user has a technical issue about an application

Comments

@yanone1
Copy link

yanone1 commented Nov 6, 2024

Name and Version

bitnami/opensearch-1.2.6

What architecture are you using?

None

What steps will reproduce the bug?

  1. in a google cloud environment -gke 1.30.5-gke.1014001
  2. helm install.
  3. using gce-internal ingress -this is not a related issue.

What is the expected behavior?

I need to have the security plugin enabled using the provided certificate files.
at the dashboard under management to see the security plugin UI.
login to the dashboard with username and password.

What do you see instead?

no login prompt for the dashboard.
no security plugin enabled.

@yanone1 yanone1 added the tech-issues The user has a technical issue about an application label Nov 6, 2024
@github-actions github-actions bot added the triage Triage is needed label Nov 6, 2024
@carrodher
Copy link
Member

Could you please describe how are you installing the plugins? Please note there is a plugins parameter you can use to specify the plugins to be installed, see https://github.com/bitnami/charts/tree/main/bitnami/opensearch#opensearch-cluster-parameters

@yanone1
Copy link
Author

yanone1 commented Nov 7, 2024

The plugin will be installed ,with or without specifying with : plugins -tried it already .
at the pod itself i do see it installed ,and it also seen at the logs .
i can also see that at the logs that it installed but disabled .
i did try to specify some : extraConfig for the plugin - that didn't help either .
Documentation are unclear ,between distores and charts , what need to be specify in order to enable the plugin .
I can also see at the pod itself (master) "/opt/bitnami/opensearch/plugins/opensearch-security/tools" - the plugin files "

@github-actions github-actions bot removed the triage Triage is needed label Nov 14, 2024
@github-actions github-actions bot assigned fmulero and unassigned carrodher Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in-progress opensearch tech-issues The user has a technical issue about an application
Projects
None yet
Development

No branches or pull requests

3 participants