stack es security put-role-mapping cli command
elastic stack es security put-role-mapping --name <name> [options]
Create or update role mappings.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--namestringrequired- The distinct name that identifies the role mapping. The name is used solely as an identifier to facilitate interaction via the API; it does not affect the behavior of the mapping in any way.
--refreshenum-
If
true(the default) then refresh the affected shards to make this operation visible to search, ifwait_forthen wait for a refresh to make this operation visible to search, iffalsethen do nothing with refreshes.Values: true, false, wait_for
--enabled- Mappings that have
enabledset tofalseare ignored when role mapping is performed. --metadatastring- Additional metadata that helps define which roles are assigned to each user.
Within the metadata object, keys beginning with
_are reserved for system usage. --rolesstring[]-
A list of role names that are granted to the users that match the role mapping rules. Exactly one of
rolesorrole_templatesmust be specified.Repeatable: pass
--rolesmultiple times to supply more than one value --role-templatesstring[]-
A list of Mustache templates that will be evaluated to determine the roles names that should granted to the users that match the role mapping rules. Exactly one of
rolesorrole_templatesmust be specified.Repeatable: pass
--role-templatesmultiple times to supply more than one value --rulesstring- The rules that determine which users should be matched by the mapping. A rule is a logical condition that is expressed by using a JSON DSL.
--run-asstring[]-
Repeatable: pass
--run-asmultiple times to supply more than one value --error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON