Repository navigation
[Transform] Behavior is not consistent between PUT and _preview wrt accessing remote index. #95367
Description
Activity
- addedTeam:MLMeta label for the ML teamMeta label for the ML team
on Apr 19, 2023 elasticsearchmachine commented
on Apr 19, 2023 CollaboratorMore actionsPinging @elastic/ml-core (Team:ML)
- added 3 commits that reference this issue
on Feb 12, 2026 - added 2 commits that reference this issue
on Feb 13, 2026 - added a commit that references this issue
on Feb 13, 2026 - added a commit that references this issue
on Feb 23, 2026 I'm reopening this, because #142403 didn't fully address the issue. From the looks of it, the issue was addressed only if the source index is local.
For cross-cluster indexes, the issue persists. The PR did include multicluster tests that look sound, but these were never run, because at that time, the entire test suite was muted (and they still are). If you unmute the tests and run them - you'll get failures - all the cross-cluster tests that expect a "lacks the required permissions" don't match that exception.
It also breaks down if the
allow_partial_search_resultscluster setting is set to false, because in this case, diagnoseSourceAccessFailure will be never triggered - the search will result in an exception instead of storing the failures in the response and we'll jump straight to the failure handler. This feels like an unaccounted side effect.I am also not too sure whether findClusterSecurityFailure is guaranteed to catch anything. This needs a further deep dive, but I see at least two layers where cross-cluster failures can be lost
- During index resolution. Looks like index resolution is intertwined with authorization (src). We send our request with
LENIENT_EXPAND_OPEN, which hasignoreUnavailable=trueandallowNoIndices=trueset. I think as a result the indexes we have no access to would be quietly dropped, but no exception would be produced forSourceAccessDiagnosticsto catch. - If
skip_unavailable=trueis set. I think this also can result in an empty "successful" response in case of auth errors,
What I'm going to do is:
- The top priority is to get the tests unmuted and running. They have been muted since Jan 2025
- I'll let some of the tests succeed when they shouldn't. This essentially means I'll bring them back to the state they were before [Transform] Fix transform validation to reject PUT and _start when user lacks remote index permissions #142403. I'll add TODOs behind the tests that should fail with security exceptions but don't
- I'll add test cases to confirm that the issue was fixed for local indexes.
Maybe the idea behind
SourceAccessDiagnosticsneeds a fresh look. Perhaps instead of trying to solve it here, we should push for the hasPrivilages endpoint to be fixed? I think this would solve the problem:Lines 92 to 95 in 5515465
// TODO: Remove this filter once https://github.com/elastic/elasticsearch/issues/67798 is fixed. String[] sourceIndex = hasLinkedProjects ? Strings.EMPTY_ARRAY : Arrays.stream(config.getSource().getIndex()).filter(not(RemoteClusterLicenseChecker::isRemoteIndex)).toArray(String[]::new); Reacted by Pat Whelan- During index resolution. Looks like index resolution is intertwined with authorization (src). We send our request with
Elasticsearch Version
main
Installed Plugins
No response
Java Version
bundled
OS Version
Darwin Kernel Version 21.6.0
Problem Description
When the user configures remote index in their transform but does not have permissions to access it,
_previewrequest will fail with error message: "Source indices have been deleted or closed.".However, such a transform can be created via
PUTand started via_start. It should not be possible.Reported by @yangwan
Steps to Reproduce
GET _transform/_previewPUT _transform/my-transformwith the same configLogs (if relevant)
No response