Elasticsearch domain policy access needs review

Restrict search-domain data access to the actual callers and operations that are needed.

Description

An overly broad Elasticsearch/OpenSearch domain access policy can let unnecessary principals read or change logs, documents and index data. Domain policies govern subresources such as indexes and data APIs, separately from administrative permissions for the domain configuration API.

Wildcard principals can be used with VPC or fine-grained access controls. Assess actual exposure by reviewing those controls together with policy permissions.

Potential impact

  • Unnecessary read access can expose logs or document contents.
  • Misused write or deletion access can damage indexes and interrupt search services.

Remediation

  • Restrict permissions to required principals, HTTP actions such as es:ESHttpGet, and actual index or API paths.
  • For VPC domains, check security groups; where fine-grained access control is used, review users and role mappings.
  • Retain the intended authentication method and test that necessary searches succeed while unnecessary reads and changes are denied.

Examples

These policy excerpts refer to the same domain. Prepare the referenced domain and index separately and replace the user ARN with the actual value.

Before

hcl
resource "aws_elasticsearch_domain_policy" "example" {
  domain_name = aws_elasticsearch_domain.example2.domain_name

  access_policies = <<POLICIES
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": "es:*",
      "Resource": "${aws_elasticsearch_domain.example2.arn}/*",
      "Principal": "*",
      "Effect": "Allow"
    }
  ]
}
POLICIES
}

This permits HTTP actions on domain subresources for all principals. Here, es:* does not grant administration of the domain configuration API.

After

hcl
resource "aws_elasticsearch_domain_policy" "example" {
  domain_name = aws_elasticsearch_domain.example2.domain_name

  access_policies = <<POLICIES
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": [
          "arn:aws:iam::123456789012:user/test-user"
        ]
      },
      "Action": [
        "es:ESHttpGet"
      ],
      "Resource": "${aws_elasticsearch_domain.example2.arn}/test-index/_search"
    }
  ]
}
POLICIES
}

This statement narrows the grant to the specified user’s GET searches on test-index. Other policies and fine-grained access controls also apply.

References