@@ -82,7 +82,7 @@ customer_template_rw:
8282 - " indices:data/read/scroll*"
8383 # Required for Dashboards saved objects (bulk writes to .kibana_* tenant indices)
8484 - " indices:data/write/bulk"
85- # Alerting: monitor CRUD, execution, alerts, and destinations
85+ # Alerting: monitor CRUD, execution, alerts, and destinations (legacy endpoints)
8686 - " cluster:admin/opendistro/alerting/monitor/get"
8787 - " cluster:admin/opendistro/alerting/monitor/search"
8888 - " cluster:admin/opendistro/alerting/monitor/write"
@@ -92,6 +92,12 @@ customer_template_rw:
9292 - " cluster:admin/opendistro/alerting/destination/get"
9393 - " cluster:admin/opendistro/alerting/destination/write"
9494 - " cluster:admin/opendistro/alerting/destination/delete"
95+ # Notifications plugin (OpenSearch 2.x): channel features + config CRUD
96+ - " cluster:admin/opensearch/notifications/features"
97+ - " cluster:admin/opensearch/notifications/configs/get"
98+ - " cluster:admin/opensearch/notifications/configs/create"
99+ - " cluster:admin/opensearch/notifications/configs/update"
100+ - " cluster:admin/opensearch/notifications/configs/delete"
95101 index_permissions :
96102 - index_patterns :
97103 - " CUSTOMER_ID_PLACEHOLDER-*"
@@ -102,6 +108,15 @@ customer_template_rw:
102108 - " indices:data/read/*"
103109 - " indices:data/write/*"
104110 - " indices:admin/mapping/put"
111+ - index_patterns :
112+ - " .kibana*"
113+ allowed_actions :
114+ - " read"
115+ - " write"
116+ - " create_index"
117+ - " indices:data/read/*"
118+ - " indices:data/write/*"
119+ - " indices:admin/mapping/put"
105120 tenant_permissions :
106121 - tenant_patterns :
107122 - " CUSTOMER_ID_PLACEHOLDER"
@@ -118,7 +133,7 @@ customer_template_ro:
118133 - " cluster_composite_ops_ro"
119134 # Required for Dashboards saved objects (bulk writes to .kibana_* tenant indices)
120135 - " indices:data/write/bulk"
121- # Alerting: monitor CRUD, execution, alerts, and destinations
136+ # Alerting: monitor CRUD, execution, alerts, and destinations (legacy endpoints)
122137 - " cluster:admin/opendistro/alerting/monitor/get"
123138 - " cluster:admin/opendistro/alerting/monitor/search"
124139 - " cluster:admin/opendistro/alerting/monitor/write"
@@ -128,12 +143,27 @@ customer_template_ro:
128143 - " cluster:admin/opendistro/alerting/destination/get"
129144 - " cluster:admin/opendistro/alerting/destination/write"
130145 - " cluster:admin/opendistro/alerting/destination/delete"
146+ # Notifications plugin (OpenSearch 2.x): channel features + config CRUD
147+ - " cluster:admin/opensearch/notifications/features"
148+ - " cluster:admin/opensearch/notifications/configs/get"
149+ - " cluster:admin/opensearch/notifications/configs/create"
150+ - " cluster:admin/opensearch/notifications/configs/update"
151+ - " cluster:admin/opensearch/notifications/configs/delete"
131152 index_permissions :
132153 - index_patterns :
133154 - " CUSTOMER_ID_PLACEHOLDER-*"
134155 allowed_actions :
135156 - " read"
136157 - " indices:data/read/*"
158+ - index_patterns :
159+ - " .kibana*"
160+ allowed_actions :
161+ - " read"
162+ - " write"
163+ - " create_index"
164+ - " indices:data/read/*"
165+ - " indices:data/write/*"
166+ - " indices:admin/mapping/put"
137167 tenant_permissions :
138168 - tenant_patterns :
139169 - " CUSTOMER_ID_PLACEHOLDER"
0 commit comments