stack es security update-api-key cli command
Auth required
Idempotent
Scope: global
elastic stack es security update-api-key --id <id> [options]
Update an API key.
Behaviour flags:
--dry-run — validate all inputs and exit without performing any action
--idstringrequired- The ID of the API key to update.
--role-descriptorsstring- The role descriptors to assign to this API key.
The API key's effective permissions are an intersection of its assigned privileges and the point in time snapshot of permissions of the owner user.
You can assign new privileges by specifying them in this parameter.
To remove assigned privileges, you can supply an empty
role_descriptorsparameter, that is to say, an empty object{}. If an API key has no assigned privileges, it inherits the owner user's full permissions. The snapshot of the owner's permissions is always updated, whether you supply therole_descriptorsparameter or not. The structure of a role descriptor is the same as the request for the create API keys API. --metadatastring- Arbitrary metadata that you want to associate with the API key.
It supports a nested data structure.
Within the metadata object, keys beginning with
_are reserved for system usage. When specified, this value fully replaces the metadata previously associated with the API key. --expirationstring- The expiration time for the API key. By default, API keys never expire. This property can be omitted to leave the expiration unchanged.
--error-trace- When set to
trueElasticsearch will include the full stack trace of errors when they occur. --filter-pathstring-
Comma-separated list of filters in dot notation which reduce the response returned by Elasticsearch.
Repeatable: pass
--filter-pathmultiple times to supply more than one value --human- When set to
truewill return statistics in a format suitable for humans. For example"exists_time": "1h"for humans and"exists_time_in_millis": 3600000for computers. When disabled the human readable values will be omitted. This makes sense for responses being consumed only by machines. --pretty- If set to
truethe returned JSON will be "pretty-formatted". Only use this option for debugging only. --input-filestring- path to a JSON file to use as command input
--dry-run- validate all inputs and exit without performing any action (preview changes without applying them)
--json-
output as JSON