stack es security oidc-authenticate cli command
Auth required
elastic stack es security oidc-authenticate \
--nonce <nonce> \
--redirect-uri <redirect-uri> \
--state <state> \
[options]
Authenticate OpenID Connect.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--noncestringrequired- Associate a client session with an ID token and mitigate replay attacks.
This value needs to be the same as the one that was provided to the
/_security/oidc/prepareAPI or the one that was generated by Elasticsearch and included in the response to that call. --redirect-uristringrequired- The URL to which the OpenID Connect Provider redirected the User Agent in response to an authentication request after a successful authentication. This URL must be provided as-is (URL encoded), taken from the body of the response or as the value of a location header in the response from the OpenID Connect Provider.
--statestringrequired- Maintain state between the authentication request and the response.
This value needs to be the same as the one that was provided to the
/_security/oidc/prepareAPI or the one that was generated by Elasticsearch and included in the response to that call. --realmstring- The name of the OpenID Connect realm. This property is useful in cases where multiple realms are defined.
--error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON