Skip to content

[Remote clusters] Add new security model - #161836

Merged
sabarasaba merged 40 commits into
elastic:mainfrom
sabarasaba:remote_clusters-security_models
Aug 14, 2023
Merged

sabarasaba merged 40 commits into
elastic:mainfrom
sabarasaba:remote_clusters-security_models

Conversation

@sabarasaba

@sabarasaba sabarasaba commented Jul 13, 2023 •

Copy link
Copy Markdown
Member

Fixes: #154312

Summary

This PR takes care of updating the UX for the creation of remote clusters so that after creating a new configuration we show the users the correspondant docs on how to setup authentication for it. Auth can be configured in two ways: either server TLS or mutual TLS, based on what the user selects we need to explain to them how to configure it.

Notes

With this PR I also fixed the EUI deprecations from the List,Edit and Add pages.

How to test
  1. Start elasticsearch with yarn es snapshot --license=trial and serverless search solution with yarn start
  2. Navigate to the remote clusters UI and create a new cluster config
  3. Verify that adding a new config has the two steps wizard
  4. Verify that the config is created after the second step is compleated
  5. Verify that if the user is on at least enterprise license the API Keys method is shown, but if the user is on basic license only certificates should be shown.
  6. Verify that if an error happen when creating the config, the user is sent to the first step of the wizard
Screenshots empty states

Screenshot 2023-07-19 at 08 42 57
Screenshot 2023-07-19 at 08 43 32
Screenshot 2023-07-19 at 08 43 54
Screenshot 2023-08-01 at 17 03 43

Screenshots

// Adding configuration flow
Screenshot 2023-07-19 at 08 44 07
// With local form errors
Screenshot 2023-07-19 at 09 31 28
// With enterprise license
Screenshot 2023-08-01 at 17 01 12
// Without enterprise license
Screenshot 2023-08-01 at 17 02 03
// With API error
Screenshot 2023-07-20 at 09 04 15

Screenshot 2023-08-01 at 17 01 37

Screenshot 2023-07-19 at 08 44 31

// Remote clusters list
Screenshot 2023-07-19 at 08 44 45

// Edit remote cluster config
Screenshot 2023-07-19 at 08 44 51

@sabarasaba sabarasaba added Feature:CCR and Remote Clusters Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more t// release_note:skip Skip the PR/issue when compiling release notes backport:skip This PR does not require backporting v8.10.0 labels Jul 13, 2023
@sabarasaba sabarasaba self-assigned this Jul 13, 2023

@alaudazzi alaudazzi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a few editing suggestions.

@florent-leborgne florent-leborgne left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Content LGTM 🚀, besides the modal title that we agreed to revert @sabarasaba to avoid making it too repetitive.
Thanks for the changes!

@alisonelizabeth alisonelizabeth left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for working on this @sabarasaba! Latest LGTM. Tested locally. I think the copy is much cleaner now too 👍

@@ -1,5 +1,13 @@
# Remote Clusters

## Setting up a remote cluster

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for adding this! I'm still not able to get a remote cluster with a successful connection 🤔. I noticed a few errors in the ES logs related to the license, ...operation due to expired license., so might be related to that.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ohhh thats odd, I was able to connect it consistently using this method 🤔

@alisonelizabeth

Copy link
Copy Markdown
Contributor

@sabarasaba can we also check off the remote_clusters plugin work from #161413 as part of this PR?

@sabarasaba

Copy link
Copy Markdown
Member Author

@sabarasaba can we also check off the remote_clusters plugin work from #161413 as part of this PR?

Yes! This pr addresses the two instances where we were using deprecations in the RC plugin.

@sabarasaba
sabarasaba removed the request for review from alaudazzi August 7, 2023 13:36
@sabarasaba sabarasaba added the ci:cloud-deploy Create or update a Cloud deployment label Aug 7, 2023
@sabarasaba

Copy link
Copy Markdown
Member Author

@elasticmachine merge upstream

@sabarasaba

Copy link
Copy Markdown
Member Author

buildkite test this

@sabarasaba

Copy link
Copy Markdown
Member Author

@elasticmachine merge upstream

@florent-leborgne

Copy link
Copy Markdown
Member

@sabarasaba I've seen on slack that the API key mechanism is only possible if the remote cluster is also at least on 8.10

Should we mention it as well on the API key card?
image

@sabarasaba

Copy link
Copy Markdown
Member Author

@sabarasaba I've seen on slack that the API key mechanism is only possible if the remote cluster is also at least on 8.10

Should we mention it as well on the API key card? image

Just saw that! Do you have any suggestions on how we could update the copy to reflect that? 🤔

@kyrspl

kyrspl commented Aug 8, 2023 •

Copy link
Copy Markdown

Just saw that! Do you have any suggestions on how we could update the copy to reflect that? 🤔

We could use the muted option underneath the CTA to specify which version they work on. It's not the most visible option of course.

Something along these lines:
Screenshot 2023-08-08 at 15 31 54

@florent-leborgne - what do you think?

@florent-leborgne

Copy link
Copy Markdown
Member

@kyrspl LGTM I was about to suggest the same, with simpler wording:
image

@sabarasaba

Copy link
Copy Markdown
Member Author

@florent-leborgne Had a sync with @kyrspl and fixed the copy and visuals to accomodate those last changes:

Screenshot 2023-08-08 at 18 01 14

@sabarasaba
sabarasaba requested a review from a team as a code owner August 11, 2023 12:57
@sabarasaba

Copy link
Copy Markdown
Member Author

@elasticmachine merge upstream

@abdonpijpelink abdonpijpelink left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Doc links look good, but result in a 404 until elastic/elasticsearch#98330 gets merged. I'll set up temporary redirects for them so this PR is unblocked.

@sabarasaba

Copy link
Copy Markdown
Member Author

@elasticmachine merge upstream

@kibana-ci

kibana-ci commented Aug 11, 2023 •

Copy link
Copy Markdown

💛 Build succeeded, but was flaky

Failed CI Steps

Test Failures

  • [job] [logs] FTR Configs #62 / Agents fleet_upgrade_agent "before each" hook for "should respond 400 if trying to upgrade an agent that is unenrolled"

Metrics [docs]

Module Count

Fewer modules leads to a faster build time

id before after diff
remoteClusters 132 136 +4

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
lists 144.6KB 144.9KB +225.0B
remoteClusters 87.6KB 94.0KB +6.4KB
total +6.7KB

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
core 378.2KB 378.4KB +225.0B
remoteClusters 8.0KB 8.5KB +599.0B
total +824.0B

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

cc @sabarasaba

@sabarasaba
sabarasaba merged commit 6e241a8 into elastic:main Aug 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport:skip This PR does not require backporting ci:cloud-deploy Create or update a Cloud deployment Feature:CCR and Remote Clusters release_note:skip Skip the PR/issue when compiling release notes Team:Kibana Management Dev Tools, Index Management, Upgrade Assistant, ILM, Ingest Node Pipelines, and more t// v8.10.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Remote Clusters] UI changes to educate users about how to configure authentication