Skip to content

[Service Accounts CP2] Support creating service accounts via UIAM #284463

Description

@legrego

The Core security contract should expose functionality on its client-side and server-side contracts to allow for the creation of service accounts (e.g. core.security.serviceAccounts.create()) via UIAM. Note this flow is only applicable when running in serverless mode. UIAM is not available for classic (relates: #284464).

Callers supply only { name }. Kibana derives role_assignments and assumable_by, so consumers cannot widen the privileges of an account they create. The incoming request is forwarded so that the caller's own credential bounds the new account.

The client-side contract should call an internal API on the security plugin to accomplish this. The client-side contract should also expose a helper (driven by UI Capabilities) which allows consumers to know whether or not the current user is authorized to create service accounts. The user must have the manage_security cluster privilege. There is prior art in the security plugin for checking based on cluster privileges.

The same API shall be used for creating UIAM and ES-based service accounts. The security plugin shall distinguish which backend to call based on the current runtime.

This issue will be worked on before #284464. We should include a stub in our implementation where we will eventually call ES for classic mode, but the functions should throw errors indicating they are not yet implemented.

Out of scope

Activity

  1. self-assigned this
    on Aug 11, 2026
  2. infra-vault-gh-plugin-prod commented on Aug 11, 2026

    @infra-vault-gh-plugin-prod
    Contributor

    Pinging @elastic/kibana-security (Team:Security)

  3. changed the title [-][Service Accounts] Support creating service accounts via UIAM[/-] [+][Service Accounts CP2] Support creating service accounts via UIAM[/+] on Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions