Skip to content

[xpack/encryptionKeys] use default keys when running from source - #36452

Merged
spalger merged 8 commits into
elastic:masterfrom
spalger:implement/default-encryption-keys
May 10, 2019
Merged

spalger merged 8 commits into
elastic:masterfrom
spalger:implement/default-encryption-keys

Conversation

@spalger

@spalger spalger commented May 10, 2019

Copy link
Copy Markdown
Contributor

Part of #36446

Now that security is on by default, I think we might have worsened the developer experience a little bit as described by #36446 (comment)

I think we should aim for automatic behavior of the server during development to be as friendly as possible, and automatically logging users out every time they change server-side code doesn't seem very friendly to me.

I think we should default the different encryptionKey configs in x-pack based on the dist flag in the config context. This flag is true in built versions of Kibana and false when running from source.

cc: @elastic/kibana-security @elastic/kibana-platform

@elasticmachine

Copy link
Copy Markdown
Contributor

Pinging @elastic/kibana-operations

@epixa

epixa commented May 10, 2019

Copy link
Copy Markdown
Contributor

Would it be possible to add a test that ensures the encryptionKey is not set in a distribution?

@spalger

spalger commented May 10, 2019 •

Copy link
Copy Markdown
Contributor Author

Yeah, I think I can unit test the config schema. It's not a perfect test but as long as we don't change the name of the dist context it'll work.

@spalger
spalger marked this pull request as ready for review May 10, 2019 15:58
@spalger
spalger requested a review from a team as a code owner May 10, 2019 15:58
@spalger spalger added review and removed discuss labels May 10, 2019
@elasticmachine

This comment has been minimized.

@kobelb

kobelb commented May 10, 2019

Copy link
Copy Markdown
Contributor

Quick question/confirmation: $dist is true when running from a built version of Kibana, and false when running from source. Where-as $dev is true when running with the --dev flag which does the automatic watching/reloading; and is false when the --dev flag isn't used?

@spalger

spalger commented May 10, 2019 •

Copy link
Copy Markdown
Contributor Author

$dist is true when running from a built version of Kibana, and false when running from source.

Correct

Where-as $dev is true when running with the --dev flag which does the automatic watching/reloading; and is false when the --dev flag isn't used?

Not quite, $dev is based on the environment config, which is set by --dev but can also be set when not using watching and in the distributable by passing --env.name=development.

I think it might even be possible to pass --env.name=production when using --dev... Basically though, --dev mode is separate from the development environment, and $dev represents the environment.

@elasticmachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

@kobelb

kobelb commented May 10, 2019

Copy link
Copy Markdown
Contributor

Thanks for the clarification @spalger! My LGTM stands 😄

@spalger
spalger merged commit 31ce503 into elastic:master May 10, 2019
spalger pushed a commit to spalger/kibana that referenced this pull request May 10, 2019
…stic#36452)

* [xpack/encryptionKeys] use default keys when running from source

* add tests for the config schema with different contexts

* share the getConfigSchema helper

* await promises returned by expect().resolves

* tweak test naming

* use data-driven tests

* fix type error

* hide platform dependent config from snapshot
spalger pushed a commit that referenced this pull request May 10, 2019
#36452) (#36461)

* [xpack/encryptionKeys] use default keys when running from source

* add tests for the config schema with different contexts

* share the getConfigSchema helper

* await promises returned by expect().resolves

* tweak test naming

* use data-driven tests

* fix type error

* hide platform dependent config from snapshot
@spalger

spalger commented May 10, 2019

Copy link
Copy Markdown
Contributor Author

7.x/7.2: f7a8b33

@spalger
spalger deleted the implement/default-encryption-keys branch May 10, 2019 20:22
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
…stic#36452)

* [xpack/encryptionKeys] use default keys when running from source

* add tests for the config schema with different contexts

* share the getConfigSchema helper

* await promises returned by expect().resolves

* tweak test naming

* use data-driven tests

* fix type error

* hide platform dependent config from snapshot
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants