Add resource sharing access control docs for alerting, security analytics, and notifications - #12984
Open
DarshitChanpura wants to merge 1 commit into
Conversation
…tics, and notifications Document the Security plugin resource-sharing onboarding for the three remaining plugins (the other onboarded plugins already have pages): - Alerting: monitor and alerting-workflow resource types, alerting_read_only/ read_write/full_access levels, alerts and comments as subordinate resources, and a per-type migrate example against .opendistro-alerting-config. - Security Analytics: detector and correlation-rule resource types, sa_read_only/read_write/full_access levels, and per-index migrate examples. - Notifications: notification_config resource type, notifications_read_only/ read_write/full_access levels, and a migrate example using metadata.access for backend roles with default_owner attribution. Each page follows the existing per-plugin access-control page structure (resource configuration, enable, access levels, migrate, related docs). Signed-off-by: Darshit Chanpura <dchanp@amazon.com>
DarshitChanpura
requested review from
cwperks,
dlvenable,
epugh,
kolchfa-aws,
mgodwan,
peterzhuamazon and
sumobrian
as code owners
August 26, 2026 19:45
|
Thank you for submitting your PR. The PR states are In progress (or Draft) -> Tech review -> Doc review -> Merged. Before you submit your PR for doc review, make sure the content is technically accurate. If you need help finding a tech reviewer, tag a maintainer. When you're ready for doc review, tag the assignee of this PR. The doc reviewer may push edits to the PR directly or leave comments and editorial suggestions for you to address (let us know in a comment if you have a preference). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds resource sharing and access control documentation for the three plugins onboarded to the Security plugin's resource-sharing framework that did not yet have a page: alerting, security analytics, and notifications. The other onboarded plugins (anomaly detection, ml-commons, reporting, flow-framework) already have equivalent pages; these three follow the same structure.
Each page documents:
opensearch.ymland Cluster Settings API)filter_by_backend_rolesframework viaPOST _plugins/_security/api/resources/migratePlugin-specific notes:
monitorandalerting-workflow(named to avoid colliding with Flow Framework'sworkflow), sharing the.opendistro-alerting-configindex. Alerts and comments are documented as subordinate resources whose access derives from the monitor.detectorandcorrelation-rule, in separate indexes; migration is run once per index.notification_config; owner metadata is a backend-role list atmetadata.accesswith no per-user owner, so migration usesdefault_ownerfor attribution.Targets OpenSearch 3.8 (the onboarding release for these three plugins).
Issues Resolved
Follow-up documentation for the alerting resource-sharing onboarding: opensearch-project/alerting#2180
Checklist
For more information on following Developer Certificate of Origin and signing off your commits, please check here.