Skip to content

[Actions] Global certificate authority setting for connectors (usable on ECE / Elastic Cloud) #295848

Description

@imrekaposi-elastic

What?

Describe the feature

Add a global, deployment-wide setting to configure trusted certificate authorities for all
connector (action) TLS connections, in addition to the existing per-host customHostSettings.

Proposed settings (naming aligned with existing customHostSettings[n].ssl.*):

xpack.actions.ssl.certificateAuthoritiesData: |
  -----BEGIN CERTIFICATE-----
  ...intermediate...
  -----END CERTIFICATE-----
  -----BEGIN CERTIFICATE-----
  ...root...
  -----END CERTIFICATE-----
# and for self-managed:
xpack.actions.ssl.certificateAuthoritiesFiles: ["/path/to/ca-chain.pem"]

Why?

My customer runs Kibana on Elastic Cloud Enterprise (ECE). Alerting rules send webhooks to
dozens of internal HTTPS endpoints, all signed by the internal (private) CA chain.

Current options and why they don't scale for us:

pack.actions.customHostSettings[n].ssl.certificateAuthoritiesData

Requires one entry per host:port (no wildcards). With dozens of endpoints the user settings become huge and must be updated for every new endpoint.

customHostSettings[n].ssl.certificateAuthoritiesFiles

Not supported on ECE / Elastic Cloud (self-managed only).

NODE_EXTRA_CA_CERTS (documented via #75870 / #84578)

Not possible on ECE: no way to set env vars for the Kibana process.

Custom Kibana Docker image

We don't want to maintain a modified version of the official image.

CA per webhook connector (config.ca, #160812 / #161894)

Has to be set on every connector; easy to forget and hard to rotate when the CA changes.

verificationMode: none

Not acceptable

Acceptance Criteria

A single global CA setting would solve this with one entry in the Kibana user settings, and
make CA rotation a single change.

Priority

Important (workaround exists)

Blocked By

No response

Additional Context

On premise, security aware environment. All external webhooks use Custom CA.

Activity

  1. added
    Team:ResponseOpsPlatform ResponseOps team (formerly the Cases and Alerting teams) t//
    on Oct 6, 2026
  2. kibanamachine commented on Oct 6, 2026

    @kibanamachine
    Contributor

    🤖 Automated triage

    This issue has been automatically assigned the Team:ResponseOps team label.

    Reason

    The issue requests a global certificate authority setting for all connectors within the Actions framework. The ResponseOps team owns the core Actions and Connectors plugins (xpack.actions, xpack.stack_connectors), which are directly affected by this proposed configuration. Alerting rules, a primary consumer of connectors, are also owned by the ResponseOps team.


    This team label was applied automatically by the Kibana automated triage system. If incorrect, remove it and apply the correct team label. To improve future triaging accuracy, consider updating the team description file. Feedback and questions → #kibana-automated-triage Slack channel.

  3. infra-vault-gh-plugin-prod commented on Oct 6, 2026

    @infra-vault-gh-plugin-prod
    Contributor

    Pinging @elastic/response-ops (Team:ResponseOps)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Team:ResponseOpsPlatform ResponseOps team (formerly the Cases and Alerting teams) t//

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions