The Core security contract should expose functionality on its client-side and server-side contracts to allow for the creation of service accounts (e.g. core.security.serviceAccounts.create()) via UIAM. Note this flow is only applicable when running in serverless mode. UIAM is not available for classic (relates: #284464).
Callers supply only { name }. Kibana derives role_assignments and assumable_by, so consumers cannot widen the privileges of an account they create. The incoming request is forwarded so that the caller's own credential bounds the new account.
The client-side contract should call an internal API on the security plugin to accomplish this. The client-side contract should also expose a helper (driven by UI Capabilities) which allows consumers to know whether or not the current user is authorized to create service accounts. The user must have the manage_security cluster privilege. There is prior art in the security plugin for checking based on cluster privileges.
The same API shall be used for creating UIAM and ES-based service accounts. The security plugin shall distinguish which backend to call based on the current runtime.
This issue will be worked on before #284464. We should include a stub in our implementation where we will eventually call ES for classic mode, but the functions should throw errors indicating they are not yet implemented.
Out of scope
The Core security contract should expose functionality on its client-side and server-side contracts to allow for the creation of service accounts (e.g.
core.security.serviceAccounts.create()) via UIAM. Note this flow is only applicable when running in serverless mode. UIAM is not available for classic (relates: #284464).Callers supply only
{ name }. Kibana derivesrole_assignmentsandassumable_by, so consumers cannot widen the privileges of an account they create. The incoming request is forwarded so that the caller's own credential bounds the new account.The client-side contract should call an internal API on the security plugin to accomplish this. The client-side contract should also expose a helper (driven by UI Capabilities) which allows consumers to know whether or not the current user is authorized to create service accounts. The user must have the
manage_securitycluster privilege. There is prior art in the security plugin for checking based on cluster privileges.The same API shall be used for creating UIAM and ES-based service accounts. The security plugin shall distinguish which backend to call based on the current runtime.
This issue will be worked on before #284464. We should include a stub in our implementation where we will eventually call ES for classic mode, but the functions should throw errors indicating they are not yet implemented.
Out of scope
role_assignmentsdefinition. Both are tracked in [Service Accounts] End-to-end validation against a real UIAM deployment #286918.