stack es security put-user-managed-service-account cli command
elastic stack es security put-user-managed-service-account \
--roles <roles> \
--namespace <namespace> \
--service <service> \
[options]
Create user-managed service accounts.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--rolesstring[]required-
The names of the roles to grant to the service account, up to a maximum of 1000. The roles are resolved when the account authenticates, so they do not have to exist yet.
Repeatable: pass
--rolesmultiple times to supply more than one value --namespacestringrequired- The namespace, which is a top-level grouping of service accounts.
It must start with a letter or digit and can contain only letters, digits, hyphens, and underscores, up to a maximum of 128 characters.
It cannot be
elastic, which is reserved for built-in service accounts. --servicestringrequired- The service name. It must start with a letter or digit and can contain only letters, digits, hyphens, and underscores, up to a maximum of 128 characters.
--refreshenum-
If
wait_for(the default) then wait for a refresh to make this operation visible to search, iftruethen refresh the affected shards to make this operation visible to search, iffalsethen do nothing with refreshes.Values: true, false, wait_for
--enabled- Whether the account can authenticate. Tokens can still be created for a disabled account; they just cannot be used until the account is enabled.
--error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--no-validate- skip input validation and send the request as-is
--output-fieldsstring- comma-separated list of fields to include in output (dot-notation supported)
--output-templatestring- Mustache-like template for custom text output (e.g. "{{id}}: {{name}}")
--json-
output as JSON