Skip to content

Add resource sharing access control docs for alerting, security analytics, and notifications - #12984

Open
DarshitChanpura wants to merge 1 commit into
opensearch-project:mainfrom
DarshitChanpura:rsc-docs-alerting-sa-notifications
Open

Add resource sharing access control docs for alerting, security analytics, and notifications#12984
DarshitChanpura wants to merge 1 commit into
opensearch-project:mainfrom
DarshitChanpura:rsc-docs-alerting-sa-notifications

Conversation

@DarshitChanpura

Copy link
Copy Markdown
Member

Description

Adds resource sharing and access control documentation for the three plugins onboarded to the Security plugin's resource-sharing framework that did not yet have a page: alerting, security analytics, and notifications. The other onboarded plugins (anomaly detection, ml-commons, reporting, flow-framework) already have equivalent pages; these three follow the same structure.

Each page documents:

  • Resource types and system indexes
  • How to enable resource sharing (opensearch.yml and Cluster Settings API)
  • The predefined access levels and their permissions
  • Migration from the legacy filter_by_backend_roles framework via POST _plugins/_security/api/resources/migrate

Plugin-specific notes:

  • Alerting — two types, monitor and alerting-workflow (named to avoid colliding with Flow Framework's workflow), sharing the .opendistro-alerting-config index. Alerts and comments are documented as subordinate resources whose access derives from the monitor.
  • Security Analytics — two types, detector and correlation-rule, in separate indexes; migration is run once per index.
  • Notificationsnotification_config; owner metadata is a backend-role list at metadata.access with no per-user owner, so migration uses default_owner for attribution.

Targets OpenSearch 3.8 (the onboarding release for these three plugins).

Issues Resolved

Follow-up documentation for the alerting resource-sharing onboarding: opensearch-project/alerting#2180

Checklist

For more information on following Developer Certificate of Origin and signing off your commits, please check here.

…tics, and notifications

Document the Security plugin resource-sharing onboarding for the three
remaining plugins (the other onboarded plugins already have pages):

- Alerting: monitor and alerting-workflow resource types, alerting_read_only/
  read_write/full_access levels, alerts and comments as subordinate resources,
  and a per-type migrate example against .opendistro-alerting-config.
- Security Analytics: detector and correlation-rule resource types,
  sa_read_only/read_write/full_access levels, and per-index migrate examples.
- Notifications: notification_config resource type, notifications_read_only/
  read_write/full_access levels, and a migrate example using metadata.access
  for backend roles with default_owner attribution.

Each page follows the existing per-plugin access-control page structure
(resource configuration, enable, access levels, migrate, related docs).

Signed-off-by: Darshit Chanpura <dchanp@amazon.com>
@github-actions

Copy link
Copy Markdown

Thank you for submitting your PR. The PR states are In progress (or Draft) -> Tech review -> Doc review -> Merged.

Before you submit your PR for doc review, make sure the content is technically accurate. If you need help finding a tech reviewer, tag a maintainer.

When you're ready for doc review, tag the assignee of this PR. The doc reviewer may push edits to the PR directly or leave comments and editorial suggestions for you to address (let us know in a comment if you have a preference).

@github-actions github-actions Bot added the Tech review PR: Tech review in progress label Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Tech review PR: Tech review in progress

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants