Agent skill

Elasticsearch Authz

by aspectrr in aspectrr/deer

Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

MITAuto-check passedBackend & APIs

Install Elasticsearch Authz

skills CLI
$ npx skills add aspectrr/deer --skill elasticsearch-authz -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer elasticsearch-authz --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/elasticsearch-authz .claude/skills/elasticsearch-authz && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-authz
GitHub stars
405
Token cost
~1.8k tokens
SKILL.md length
399 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

  • Assigning privileges
  • SKILL.md covers Jobs to Be Done, Prerequisites, Manage Native Users and Manage Roles, plus 4 more sections
  • Calls curl; needs NEW_PASSWORD
  • Mapping external realms like LDAP/SAML

What it does

Elasticsearch Authz is an agent skill from aspectrr/deer. Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation and Authorization and RBAC. It works with Elasticsearch. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • Assigning privileges
  • Mapping external realms like LDAP/SAML

Example prompts

  • “/elasticsearch-authz”

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NEW_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Elasticsearch Authz loads about 1.8k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 399 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 399 words, ~1,810 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-authz/SKILL.md (or your agent's skills folder).
name
elasticsearch-authz
description
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.
metadata.author
elastic
metadata.version
0.1.1
metadata.source
elastic/agent-skills//skills/elasticsearch/elasticsearch-authz

Elasticsearch Authorization

Manage Elasticsearch role-based access control: native users, roles, role assignment, and role mappings for external realms.

For authentication methods and API key management, see the elasticsearch-authn skill.

For detailed API endpoints, see references/api-reference.md.

Jobs to Be Done

  • Create a native user with a specific set of privileges
  • Define a custom role with least-privilege index and cluster access
  • Assign one or more roles to an existing user
  • Create a role with Kibana feature or space privileges
  • Configure a role mapping for external realm users (SAML, LDAP, PKI)
  • Derive role assignments dynamically from user attributes (Mustache templates)
  • Restrict document visibility per user or department (document-level security)
  • Hide sensitive fields like PII from certain roles (field-level security)
  • Implement attribute-based access control (ABAC) using templated role queries
  • Translate a natural-language access request into user, role, and role mapping tasks

Prerequisites

ItemDescription
Elasticsearch URLCluster endpoint (e.g. https://localhost:9200 or a Cloud deployment URL)
Kibana URLRequired only when setting Kibana feature/space privileges
AuthenticationValid credentials (see the elasticsearch-authn skill)
Cluster privilegesmanage_security is required for user and role management operations

Manage Native Users

Create a user
bash
curl -X POST "${ELASTICSEARCH_URL}/_security/user/${USERNAME}" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "password": "'"${PASSWORD}"'",
    "roles": ["'"${ROLE_NAME}"'"],
    "full_name": "'"${FULL_NAME}"'",
    "email": "'"${EMAIL}"'",
    "enabled": true
  }'
Update a user

Use PUT /_security/user/${USERNAME} with the fields to change. Omit password to keep the existing one.

Other user operations
bash
curl -X POST "${ELASTICSEARCH_URL}/_security/user/${USERNAME}/_password" \
  <auth_flags> -H "Content-Type: application/json" \
  -d '{"password": "'"${NEW_PASSWORD}"'"}'
curl -X PUT "${ELASTICSEARCH_URL}/_security/user/${USERNAME}/_disable" <auth_flags>
curl -X PUT "${ELASTICSEARCH_URL}/_security/user/${USERNAME}/_enable" <auth_flags>
curl "${ELASTICSEARCH_URL}/_security/user/${USERNAME}" <auth_flags>
curl -X DELETE "${ELASTICSEARCH_URL}/_security/user/${USERNAME}" <auth_flags>

Manage Roles

Choosing the right API

Use the Elasticsearch API (PUT /_security/role/{name}) when the role only needs cluster and indices privileges. Use the Kibana role API (PUT /api/security/role/{name}) when the role includes any Kibana feature or space privileges.

Show full SKILL.md (156 more words)Show less
Create or update a role (Elasticsearch API)
bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/role/${ROLE_NAME}" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "description": "'"${ROLE_DISPLAY_NAME}"'",
    "cluster": [],
    "indices": [
      {
        "names": ["'"${INDEX_PATTERN}"'"],
        "privileges": ["read", "view_index_metadata"]
      }
    ]
  }'
Create or update a role (Kibana API)
bash
curl -X PUT "${KIBANA_URL}/api/security/role/${ROLE_NAME}" \
  <auth_flags> \
  -H "kbn-xsrf: true" \
  -H "Content-Type: application/json" \
  -d '{
    "description": "'"${ROLE_DISPLAY_NAME}"'",
    "elasticsearch": {
      "cluster": [],
      "indices": [
        {
          "names": ["'"${INDEX_PATTERN}"'"],
          "privileges": ["read", "view_index_metadata"]
        }
      ]
    },
    "kibana": [
      {
        "base": [],
        "feature": {
          "discover": ["read"],
          "dashboard": ["read"]
        },
        "spaces": ["*"]
      }
    ]
  }'

Document-Level and Field-Level Security

Field-level security (FLS)

Restrict which fields a role can see:

bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/role/pii-redacted-reader" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "description": "PII Redacted Reader",
    "indices": [
      {
        "names": ["customers-*"],
        "privileges": ["read"],
        "field_security": {
          "grant": ["*"],
          "except": ["ssn", "credit_card", "date_of_birth"]
        }
      }
    ]
  }'
Document-level security (DLS)

Restrict which documents a role can see by attaching a query filter:

bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/role/emea-logs-reader" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "description": "EMEA Logs Reader",
    "indices": [
      {
        "names": ["logs-*"],
        "privileges": ["read"],
        "query": "{\"term\": {\"region\": \"emea\"}}"
      }
    ]
  }'

Assign Roles to Users

bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/user/${USERNAME}" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "roles": ["role-a", "role-b"]
  }'

The roles array is replaced entirely — include all roles the user should have. Fetch the user first to see current roles before updating.

Manage Role Mappings

Static role mapping
bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/role_mapping/saml-default-access" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "roles": ["viewer"],
    "enabled": true,
    "rules": {
      "field": { "realm.name": "saml1" }
    }
  }'
LDAP group-based mapping
bash
curl -X PUT "${ELASTICSEARCH_URL}/_security/role_mapping/ldap-admins" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "roles": ["superuser"],
    "enabled": true,
    "rules": {
      "all": [
        { "field": { "realm.name": "ldap1" } },
        { "field": { "groups": "cn=admins,ou=groups,dc=example,dc=com" } }
      ]
    }
  }'

Guidelines

Least-privilege principles
  • Never use the elastic superuser for day-to-day operations. Create dedicated minimum-privilege roles.
  • Use read and view_index_metadata for read-only data access. Leave cluster empty unless explicitly required.
  • Use DLS (query) and FLS (field_security) to restrict access within an index.
Named privileges only

Never use internal action names (e.g. indices:data/read/search). Always use officially documented named privileges.

Role naming conventions
  • Use short lowercase names with hyphens: logs-reader, apm-data-viewer, metrics-writer.
  • Set description to a short, human-readable display name.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/elasticsearch-authz of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Elasticsearch Authz next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Authz compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Authz this skillaspectrr/deer405—~1.8kAutomated safety check: PassMIT
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
API Authzelastic/kibana21k—~1.6kAutomated safety check: PassCustom licence
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
Elasticsearcholasunkanmi-SE/codebuddy141—~425Automated safety check: PassMIT

Similar skills

  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Authz

    elastic/kibana

    Official

    Kibana API route authorization patterns. An agent skill from elastic/kibana.

    21k GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch

    olasunkanmi-SE/codebuddy

    Interact with Elasticsearch clusters via the API. An agent skill from olasunkanmi-SE/codebuddy.

    141 GitHub stars~425 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Elasticsearch Index Design

    elastic/agent-skills

    Official

    Design and review Elasticsearch index mappings for stated access patterns: correct field types, text+keyword multi-fields, docvalues tuning, mapping-explosion avoidance, and explicit shard settings.

    592 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed
  • Create and manage Kibana alerting rules via REST API or Terraform.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about Elasticsearch Authz

What does Elasticsearch Authz do?

Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Elasticsearch Authz is an agent skill from aspectrr/deer. Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

When should I use Elasticsearch Authz?

Elasticsearch Authz fits situations like: assigning privileges; mapping external realms like LDAP/SAML.

How do I install Elasticsearch Authz in Claude Code?

Run `npx skills add aspectrr/deer --skill elasticsearch-authz -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-authz in aspectrr/deer) into .claude/skills/elasticsearch-authz in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Authz in Codex?

Run `npx skills add aspectrr/deer --skill elasticsearch-authz -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-authz in aspectrr/deer) into .agents/skills/elasticsearch-authz in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Authz in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill elasticsearch-authz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-authz, .gemini/skills/elasticsearch-authz, .github/skills/elasticsearch-authz and .opencode/skills/elasticsearch-authz in your project.

What does Elasticsearch Authz need to run?

Going by SKILL.md and its folder, Elasticsearch Authz needs the command-line tools its instructions call (curl) and credentials named NEW_PASSWORD.

Does Elasticsearch Authz access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Authz safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Authz use?

Elasticsearch Authz is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Authz use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Elasticsearch Authz?

Skills that share tags, products or a category with Elasticsearch Authz: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), API Authz (elastic/kibana, 21k stars) and Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Authz?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.