Bug 1829062 - Customer experiencing "[security_exception] no permissions for [indices:data/read/field]" for admin users in 3.11.146
Summary: Customer experiencing "[security_exception] no permissions for [indices:data/...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Logging
Version: 3.11.0
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: ---
: 3.11.z
Assignee: Jeff Cantrill
QA Contact: Anping Li
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-04-28 19:46 UTC by Greg Rodriguez II
Modified: 2024-01-06 04:29 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-06-08 00:04:18 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Greg Rodriguez II 2020-04-28 19:46:11 UTC
Description of problem:
Similar to issue [1] resolved by errata [2] for 3.11.146, except this customer has upgraded to 3.11.146 and is experiencing the issue with ADMIN users.  Oddly enough, cluster-view users are NOT seeing the problem, it's only cluster-admin users.  

As a cluster-admin accessing Kibana, users are attempting to locate indices for a project called "ecpi" however they are not able to view due to "[security_exception] no permissions for [indices:data/read/field]" message at top of screen.

[1]  https://bugzilla.redhat.com/show_bug.cgi?id=1752853
[2]  https://access.redhat.com/errata/RHBA-2019:2816

Version-Release number of selected component (if applicable):
3.11.146

How reproducible:
No change after resetting affected users kibana user indices; verified "ecpi" project index is healthy; verified ES is healthy; no logs in ES master logs are helpful and kibana logs just show "200" results for each line

Steps to Reproduce:
1. As cluster-admin user, open Kibana and attempt to view project logs for "ecpi"
2. Get "no permissions" message at top of screen
3. As cluster-view user, open Kibana and attempt to view project logs for "ecpi"
4. Successful, no issues reported.

Actual results:
Every cluster-admin user tested has this same issue, and it is only affecting the project "ecpi" as the admins are able to see the other project logs without issue.  No cluster-view users affected.

Expected results:
Cluster-admin users should be able to see this project's logs

Additional info:
Privately attaching several logging dump script results and screenshots provided by customer

Comment 11 Greg Rodriguez II 2020-05-18 16:28:11 UTC
Customer has escalated the SFDC ticket requesting workaround.

Comment 13 Jeff Cantrill 2020-06-03 20:53:02 UTC
Please confirm it is not a browser session issue: https://bugzilla.redhat.com/show_bug.cgi?id=1791837#c29

Comment 14 Jeff Cantrill 2020-06-08 00:04:18 UTC
Closing NOTABUG since the customer closed the case  based on #c13

Comment 15 Red Hat Bugzilla 2024-01-06 04:29:05 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days


Note You need to log in before you can comment on or make changes to this bug.