Skip to content

[Encryption] Add encryption password to auto-configuration and gradle run - #151522

Merged
jfreden merged 6 commits into
elastic:mainfrom
jfreden:encryption/improve_local_dev
Jun 30, 2026
Merged

jfreden merged 6 commits into
elastic:mainfrom
jfreden:encryption/improve_local_dev

Conversation

@jfreden

@jfreden jfreden commented Jun 17, 2026 •

Copy link
Copy Markdown
Contributor

This PR makes two improvements to reduce friction when working with cluster state encryption.

Auto-configuration of the encryption password

AutoConfigureNode now generates a unique random encryption password for each node during first-boot security auto-configuration and writes it to the keystore under cluster.state.encryption.password.autoconfigured, with cluster.state.encryption.active_password_id set to autoconfigured. The same happens when a node enrolls into an existing cluster. If either setting is already present (user-managed keys), auto-configuration is skipped.

When a node is reconfigured to join a different cluster, the autoconfigured keys are replaced with fresh ones as part of the reconfiguration. Any datasource credentials from the old cluster live in cluster state, which is overwritten once the node joins the new cluster - this is inherent to the operation itself, not a consequence of the key replacement. For multi-node clusters, other nodes retain their copies.

A banner line is added to the startup console output alongside the existing security auto-configuration messages when the password has been auto-configured.

Each node intentionally gets its own distinct password. This is safe because the PEK travels in plaintext over TLS-protected transport between nodes; password wrapping and unwrapping happen only during on-disk serialization and deserialization. Each node reads and writes its own local cluster state, so there is no requirement for nodes to share a keystore or agree on a password. This also means no changes to the enrollment API are needed to propagate the password to joining nodes.

Gradle run task

The runTask cluster in elasticsearch.run.gradle is wired with a static encryption password and active id so that ./gradlew run works out of the box without any manual keystore setup.

@jfreden
jfreden force-pushed the encryption/improve_local_dev branch 4 times, most recently from ddd2a7b to f10e810 Compare June 17, 2026 14:34
@jfreden
jfreden force-pushed the encryption/improve_local_dev branch from f10e810 to 81be5df Compare June 25, 2026 12:36
@github-actions

github-actions Bot commented Jun 25, 2026 •

Copy link
Copy Markdown
Contributor

🔍 Preview links for changed docs

⏳ Building and deploying preview... View progress

This comment will be updated with preview links when the build is complete.

@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Important: Docs version tagging

👋 Thanks for updating the docs! Just a friendly reminder that our docs are now cumulative. This means all 9.x versions are documented on the same page and published off of the main branch, instead of creating separate pages for each minor version.

We use applies_to tags to mark version-specific features and changes.

Expand for a quick overview

When to use applies_to tags:

✅ At the page level to indicate which products/deployments the content applies to (mandatory)
✅ When features change state (e.g. preview, ga) in a specific version
✅ When availability differs across deployments and environments

What NOT to do:

❌ Don't remove or replace information that applies to an older version
❌ Don't add new information that applies to a specific version without an applies_to tag
❌ Don't forget that applies_to tags can be used at the page, section, and inline level

🤔 Need help?

@jfreden
jfreden force-pushed the encryption/improve_local_dev branch 2 times, most recently from eef5ec0 to 8e91405 Compare June 29, 2026 06:54
@jfreden
jfreden force-pushed the encryption/improve_local_dev branch from 997d1f3 to 7952edb Compare June 29, 2026 08:40
@jfreden jfreden changed the title [Encryption] Add encryption password to gradle run and local-distro [Encryption] Add encryption password to gradle run and auto-configuration Jun 29, 2026
@jfreden jfreden changed the title [Encryption] Add encryption password to gradle run and auto-configuration [Encryption] Add encryption password to auto-configuration and gradle run Jun 29, 2026
@jfreden jfreden added :Security/Security Security issues without another label >enhancement labels Jun 29, 2026
@jfreden
jfreden marked this pull request as ready for review June 29, 2026 09:54
@jfreden
jfreden requested a review from a team as a code owner June 29, 2026 09:54
@jfreden
jfreden requested a review from rjernst June 29, 2026 09:54
@elasticsearchmachine elasticsearchmachine added the Team:Security Meta label for security team label Jun 29, 2026
@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Pinging @elastic/es-security (Team:Security)

@elasticsearchmachine

Copy link
Copy Markdown
Collaborator

Hi @jfreden, I've created a changelog YAML for you.

@jfreden
jfreden requested a review from a team June 29, 2026 09:55
Comment thread docs/changelog/151522.yaml
@jfreden
jfreden enabled auto-merge (squash) June 30, 2026 11:21
@jfreden
jfreden merged commit d243551 into elastic:main Jun 30, 2026
43 checks passed
tveasey pushed a commit that referenced this pull request Jun 30, 2026
… run (#151522)

* [Encryption] Add encryption pw to gradle run and auto config security
smalyshev pushed a commit to smalyshev/elasticsearch that referenced this pull request Jul 1, 2026
… run (elastic#151522)

* [Encryption] Add encryption pw to gradle run and auto config security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>enhancement :Security/Security Security issues without another label Team:Security Meta label for security team v9.5.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants