Skip to content

FTR configurable test users - #52431

Merged
rashmivkulkarni merged 187 commits into
elastic:masterfrom
rashmivkulkarni:implement/ftr-configured-users
Mar 17, 2020
Merged

rashmivkulkarni merged 187 commits into
elastic:masterfrom
rashmivkulkarni:implement/ftr-configured-users

Conversation

@rashmivkulkarni

@rashmivkulkarni rashmivkulkarni commented Dec 6, 2019 •

Copy link
Copy Markdown
Contributor

We should run all CI tests with security enabled and with a user who has the minimal documented privileges to allow them to be successful.

Describe a specific use case for the feature:
For example, Management Index Pattern tests should be run with a user with the kibana_user role and a role that gives them only read, and view_index_metadata privileges on logstash-*.

The x-pack tests already do run with security enabled but they currently all run as the elastic superuser.

The OSS tests currently run against an OSS Kibana/Elasticsearch server pair. I guess we should keep that but then also run them against a default distribution Kibana/Elasticsearch server pair.

Of course Kibana should be configured to use the kibana_server role user also and not the elastic superuser. This PR tries to eliminate the usage of superuser in the tests and instead use another user called test_user who has the right set of roles and privileges required to run the tests.

This PR doesn't set the minimal privileges for the x-pack tests. ( except dashboard_only_mode.js as an example) . Future PRs would switch from elastic super user to a lesser role with right set of privileges.

Fixes: #26937

@rashmivkulkarni

Copy link
Copy Markdown
Contributor Author

@elasticmachine merge upstream

@LeeDr

LeeDr commented Dec 11, 2019 •

Copy link
Copy Markdown
  • need to update ftr docs and/or create a specific section on how to use the new test functionality being added.
  • Run the OSS tests (outside of Jenkins) against Cloud and/or a local instance started from x-pack with security enabled. The test_user for the OSS tests has roles for many indices but we need to verify we caught everything.

@rashmivkulkarni

Copy link
Copy Markdown
Contributor Author

jenkins test this

@rashmivkulkarni

Copy link
Copy Markdown
Contributor Author

jenkins, test this

1 similar comment
@rashmivkulkarni

Copy link
Copy Markdown
Contributor Author

jenkins, test this

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger

spalger commented Mar 17, 2020

Copy link
Copy Markdown
Contributor

@elasticmachine merge upstream

@spalger spalger left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, lets merge once this is green!

@rashmivkulkarni

Copy link
Copy Markdown
Contributor Author

Finally! ❤️

@dmlemeshko
dmlemeshko self-requested a review March 17, 2020 17:11

@dmlemeshko dmlemeshko left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the changes

@rashmivkulkarni
rashmivkulkarni merged commit 89f9260 into elastic:master Mar 17, 2020
rashmivkulkarni added a commit to rashmivkulkarni/kibana that referenced this pull request Mar 17, 2020
* initial implementation of configurable test users

* user superuser by default to match master

* referenced the configs in reporting and api integration

* setting the minimum number of default roles

* looking for x-pack tests with users and roles

* add testUserService in dashboard mode tests

* running only ciGroup7

* uncommenting - addign visualization

* re-enabling all CI groups to run on CI

* reinstating Jenkinsfile

* disable Test user for OIDC config

* improved logging and added Roles for OSS tests to get better info on the runs.

* disable test_user for auth tests

* don't fetch enabledPlugins when testuser disabled

* fix es-lint

* running oss tests with x-pack enabled

* [revertme] build default dist for oss tests

* updating NOTICE.txt file as it complained in the kibana intake tests

* changed to pick OSS builds

* trying a license change to trial

* switch back to xpack builds

* created a new sample data role and used it in homepage tests

* revert test/scripts/jenkins_ci_group.sh

* only refresh browser and wait for chrome if we are already on Kibana page

* fix large_string test to use minimum set of roles and privileges

* fix for date nanos custom timestamp with a configured role

* changes to the files with addition of new roles for the test_user

* reverting to OSS changes and few additions to the time_zone test to run as a test_user

* changes to security

* changes to the x-pack test to use elastic superuser

* fix for chart_types test

* fixes to area chart , input control test

* fix for dashboard filtering test and a new config role

* changes to handle the x-pack tests

* additional role for date nanos mixed

* added the logstash role to the accessibility tests

* removed telemetry setting

* docs+few changes to the tests

* removed Page navigation

* removed pageNavigation which was unused

* test/accessibility/apps/management.ts

* update management.ts

* aria label, and other changes

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* reverted

* unloading of logstash data, fixing aria label

* aria-label

* added the required role

* fix for tsvb chart

* fix for sample data test reverted home_page pageobject file

* changes to sample data test and visualize index file to incorporate OSS changes

* changes to describe() and some more changes to incorporate in settings_page

* re-adding the after()

* removed unwanted roles

* replaced kibana_user with kibana_admin

* added the check of deprecated kibana_user

* testing with kibana_admin  role

* fix for discover test

* incorporated the review comments

* incorporated the review comments

* incorporate review comments and added restoreDefaults()

* removed describe.only

* reverted the OSS logic change I had here- pulled into seperate PR

* incorporated the review comments

* incorporated review changes

* adding hidden=true to find hidden kibanaChrome

* change field.test.tsx to be same as that of master branch

Co-authored-by: spalger <spalger@users.noreply.github.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
gmmorris added a commit to gmmorris/kibana that referenced this pull request Mar 17, 2020
* master: (51 commits)
  do not update cell background if is label cell (elastic#60308)
  FTR configurable test users (elastic#52431)
  [Reporting] Wholesale moves client to newest-platform (elastic#58945)
  [Ingest] Support `show_user` package registry flag (elastic#60338)
  [SIEM] Adds 'Closes one signal when more than one opened signals are selected' test again (elastic#60380)
  [SIEM][Detections Engine] - Add rule markdown field to rule create, detail, and edit flows (elastic#60108)
  [Fleet] Add config revision to fleet agents (elastic#60292)
  Allow kbn-config-schema to ignore unknown keys (elastic#59560)
  [ML] Functional tests - disable df analytics clone tests
  skip flaky suite (elastic#58643) (elastic#58991)
  [FTR] Add support for --include and --exclude files via tags (elastic#60123)
  [SIEM] Fix link on overview page (elastic#60348)
  skip flaky test (elastic#60369)
  [Endpoint] Adds take action dropdown and tests to alert details flyout (elastic#59242)
  [Lens] Simplify state management from visualization (elastic#58279)
  Changing default type to start and allowing it to be configured by the event category (elastic#60323)
  [ML] Adds the class_assignment_objective to classification (elastic#60358)
  [TSVB] fix text color when using custom background color (elastic#60261)
  Fix import to timefilter from in TSVB (elastic#60296)
  [NP] Get rid of usage redirectWhenMissing service (elastic#59777)
  ...
gmmorris added a commit to gmmorris/kibana that referenced this pull request Mar 17, 2020
* alerting/view-in-app: (53 commits)
  fixed typo
  handle optional alerting plugin
  do not update cell background if is label cell (elastic#60308)
  FTR configurable test users (elastic#52431)
  [Reporting] Wholesale moves client to newest-platform (elastic#58945)
  [Ingest] Support `show_user` package registry flag (elastic#60338)
  [SIEM] Adds 'Closes one signal when more than one opened signals are selected' test again (elastic#60380)
  [SIEM][Detections Engine] - Add rule markdown field to rule create, detail, and edit flows (elastic#60108)
  [Fleet] Add config revision to fleet agents (elastic#60292)
  Allow kbn-config-schema to ignore unknown keys (elastic#59560)
  [ML] Functional tests - disable df analytics clone tests
  skip flaky suite (elastic#58643) (elastic#58991)
  [FTR] Add support for --include and --exclude files via tags (elastic#60123)
  [SIEM] Fix link on overview page (elastic#60348)
  skip flaky test (elastic#60369)
  [Endpoint] Adds take action dropdown and tests to alert details flyout (elastic#59242)
  [Lens] Simplify state management from visualization (elastic#58279)
  Changing default type to start and allowing it to be configured by the event category (elastic#60323)
  [ML] Adds the class_assignment_objective to classification (elastic#60358)
  [TSVB] fix text color when using custom background color (elastic#60261)
  ...
rashmivkulkarni added a commit that referenced this pull request Mar 18, 2020
* FTR configurable test users (#52431)

* initial implementation of configurable test users

* user superuser by default to match master

* referenced the configs in reporting and api integration

* setting the minimum number of default roles

* looking for x-pack tests with users and roles

* add testUserService in dashboard mode tests

* running only ciGroup7

* uncommenting - addign visualization

* re-enabling all CI groups to run on CI

* reinstating Jenkinsfile

* disable Test user for OIDC config

* improved logging and added Roles for OSS tests to get better info on the runs.

* disable test_user for auth tests

* don't fetch enabledPlugins when testuser disabled

* fix es-lint

* running oss tests with x-pack enabled

* [revertme] build default dist for oss tests

* updating NOTICE.txt file as it complained in the kibana intake tests

* changed to pick OSS builds

* trying a license change to trial

* switch back to xpack builds

* created a new sample data role and used it in homepage tests

* revert test/scripts/jenkins_ci_group.sh

* only refresh browser and wait for chrome if we are already on Kibana page

* fix large_string test to use minimum set of roles and privileges

* fix for date nanos custom timestamp with a configured role

* changes to the files with addition of new roles for the test_user

* reverting to OSS changes and few additions to the time_zone test to run as a test_user

* changes to security

* changes to the x-pack test to use elastic superuser

* fix for chart_types test

* fixes to area chart , input control test

* fix for dashboard filtering test and a new config role

* changes to handle the x-pack tests

* additional role for date nanos mixed

* added the logstash role to the accessibility tests

* removed telemetry setting

* docs+few changes to the tests

* removed Page navigation

* removed pageNavigation which was unused

* test/accessibility/apps/management.ts

* update management.ts

* aria label, and other changes

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* reverted

* unloading of logstash data, fixing aria label

* aria-label

* added the required role

* fix for tsvb chart

* fix for sample data test reverted home_page pageobject file

* changes to sample data test and visualize index file to incorporate OSS changes

* changes to describe() and some more changes to incorporate in settings_page

* re-adding the after()

* removed unwanted roles

* replaced kibana_user with kibana_admin

* added the check of deprecated kibana_user

* testing with kibana_admin  role

* fix for discover test

* incorporated the review comments

* incorporated the review comments

* incorporate review comments and added restoreDefaults()

* removed describe.only

* reverted the OSS logic change I had here- pulled into seperate PR

* incorporated the review comments

* incorporated review changes

* adding hidden=true to find hidden kibanaChrome

* change field.test.tsx to be same as that of master branch

Co-authored-by: spalger <spalger@users.noreply.github.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>

* removed the accidentally added file

Co-authored-by: spalger <spalger@users.noreply.github.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
@kibanamachine

Copy link
Copy Markdown
Contributor

💚 Build Succeeded

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request May 6, 2026
* initial implementation of configurable test users

* user superuser by default to match master

* referenced the configs in reporting and api integration

* setting the minimum number of default roles

* looking for x-pack tests with users and roles

* add testUserService in dashboard mode tests

* running only ciGroup7

* uncommenting - addign visualization

* re-enabling all CI groups to run on CI

* reinstating Jenkinsfile

* disable Test user for OIDC config

* improved logging and added Roles for OSS tests to get better info on the runs.

* disable test_user for auth tests

* don't fetch enabledPlugins when testuser disabled

* fix es-lint

* running oss tests with x-pack enabled

* [revertme] build default dist for oss tests

* updating NOTICE.txt file as it complained in the kibana intake tests

* changed to pick OSS builds

* trying a license change to trial

* switch back to xpack builds

* created a new sample data role and used it in homepage tests

* revert test/scripts/jenkins_ci_group.sh

* only refresh browser and wait for chrome if we are already on Kibana page

* fix large_string test to use minimum set of roles and privileges

* fix for date nanos custom timestamp with a configured role

* changes to the files with addition of new roles for the test_user

* reverting to OSS changes and few additions to the time_zone test to run as a test_user

* changes to security

* changes to the x-pack test to use elastic superuser

* fix for chart_types test

* fixes to area chart , input control test

* fix for dashboard filtering test and a new config role

* changes to handle the x-pack tests

* additional role for date nanos mixed

* added the logstash role to the accessibility tests

* removed telemetry setting

* docs+few changes to the tests

* removed Page navigation

* removed pageNavigation which was unused

* test/accessibility/apps/management.ts

* update management.ts

* aria label, and other changes

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* accidentally checked in a piped file with results.

* reverted

* unloading of logstash data, fixing aria label

* aria-label

* added the required role

* fix for tsvb chart

* fix for sample data test reverted home_page pageobject file

* changes to sample data test and visualize index file to incorporate OSS changes

* changes to describe() and some more changes to incorporate in settings_page

* re-adding the after()

* removed unwanted roles

* replaced kibana_user with kibana_admin

* added the check of deprecated kibana_user

* testing with kibana_admin  role

* fix for discover test

* incorporated the review comments

* incorporated the review comments

* incorporate review comments and added restoreDefaults()

* removed describe.only

* reverted the OSS logic change I had here- pulled into seperate PR

* incorporated the review comments

* incorporated review changes

* adding hidden=true to find hidden kibanaChrome

* change field.test.tsx to be same as that of master branch

Co-authored-by: spalger <spalger@users.noreply.github.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
steliosmavro added a commit that referenced this pull request Jun 19, 2026
…tom roles (#273744)

## Summary

When migrating, the agent maps FTR custom roles to Scout custom roles
1:1 instead of using the default Elastic Cloud (SAML)-compatible roles
(`viewer`, `editor`, `admin`) when possible. Custom roles should be a
last resort.

The role choice depends on what the test focuses on:
- **General e2e user flow** → use a default role: `loginAsViewer()` /
`loginAsPrivilegedUser()` / `loginAsAdmin()` (least-privileged first).
- **Privileges validation** (deployment-agnostic) →
`loginWithCustomRole()`, only when a default role can't express the
limitation under test.
- **Built-in role by name** → `loginAs(role)` is typically stateful-only
(the role may not exist in serverless).

Many FTR suites scoped custom roles needlessly (see the [over-scoping
initiative](#52431) referenced in
the thread); those tests migrate fine to `loginAsViewer` /
`loginAsPrivilegedUser`.

Changes (skill docs only — no code/tests):
- **generate-plan §6**: new step to recommend a target Scout role —
least-privileged Cloud-compatible built-in role unless the test
specifically validates permission-scoped behavior; flag needless custom
roles rather than porting 1:1.
- **plan-template §5**: add a `Scout role target` column to the role
inventory so the recommendation is reviewable in the plan.
- **execute-plan**: guardrail to prefer default roles, reach for
`loginWithCustomRole` only for permission-scoping tests, with the
`loginAs(role)` stateful-only caveat.

---------

Co-authored-by: Cesare de Cal <cesare.decal@elastic.co>
flash1293 pushed a commit to flash1293/kibana that referenced this pull request Jun 23, 2026
…tom roles (elastic#273744)

## Summary

When migrating, the agent maps FTR custom roles to Scout custom roles
1:1 instead of using the default Elastic Cloud (SAML)-compatible roles
(`viewer`, `editor`, `admin`) when possible. Custom roles should be a
last resort.

The role choice depends on what the test focuses on:
- **General e2e user flow** → use a default role: `loginAsViewer()` /
`loginAsPrivilegedUser()` / `loginAsAdmin()` (least-privileged first).
- **Privileges validation** (deployment-agnostic) →
`loginWithCustomRole()`, only when a default role can't express the
limitation under test.
- **Built-in role by name** → `loginAs(role)` is typically stateful-only
(the role may not exist in serverless).

Many FTR suites scoped custom roles needlessly (see the [over-scoping
initiative](elastic#52431) referenced in
the thread); those tests migrate fine to `loginAsViewer` /
`loginAsPrivilegedUser`.

Changes (skill docs only — no code/tests):
- **generate-plan §6**: new step to recommend a target Scout role —
least-privileged Cloud-compatible built-in role unless the test
specifically validates permission-scoped behavior; flag needless custom
roles rather than porting 1:1.
- **plan-template §5**: add a `Scout role target` column to the role
inventory so the recommendation is reviewable in the plan.
- **execute-plan**: guardrail to prefer default roles, reach for
`loginWithCustomRole` only for permission-scoping tests, with the
`loginAs(role)` stateful-only caveat.

---------

Co-authored-by: Cesare de Cal <cesare.decal@elastic.co>
patrykkopycinski pushed a commit to patrykkopycinski/kibana that referenced this pull request Aug 5, 2026
…tom roles (elastic#273744)

## Summary

When migrating, the agent maps FTR custom roles to Scout custom roles
1:1 instead of using the default Elastic Cloud (SAML)-compatible roles
(`viewer`, `editor`, `admin`) when possible. Custom roles should be a
last resort.

The role choice depends on what the test focuses on:
- **General e2e user flow** → use a default role: `loginAsViewer()` /
`loginAsPrivilegedUser()` / `loginAsAdmin()` (least-privileged first).
- **Privileges validation** (deployment-agnostic) →
`loginWithCustomRole()`, only when a default role can't express the
limitation under test.
- **Built-in role by name** → `loginAs(role)` is typically stateful-only
(the role may not exist in serverless).

Many FTR suites scoped custom roles needlessly (see the [over-scoping
initiative](elastic#52431) referenced in
the thread); those tests migrate fine to `loginAsViewer` /
`loginAsPrivilegedUser`.

Changes (skill docs only — no code/tests):
- **generate-plan §6**: new step to recommend a target Scout role —
least-privileged Cloud-compatible built-in role unless the test
specifically validates permission-scoped behavior; flag needless custom
roles rather than porting 1:1.
- **plan-template §5**: add a `Scout role target` column to the role
inventory so the recommendation is reviewable in the plan.
- **execute-plan**: guardrail to prefer default roles, reach for
`loginWithCustomRole` only for permission-scoping tests, with the
`loginAs(role)` stateful-only caveat.

---------

Co-authored-by: Cesare de Cal <cesare.decal@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release_note:skip Skip the PR/issue when compiling release notes Team:Operations Kibana-Operations Team Team:QA Platform QA t// Team:Security Platform Security: Auth, Users, Roles, Spaces, Audit Logging, etc t// test_ui_functional v7.6.2 v7.7.0 v8.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

run all CI tests with security enabled and minimal privileged roles