Description
An overly broad Elasticsearch/OpenSearch domain access policy can let unnecessary principals read or change logs, documents and index data. Domain policies govern subresources such as indexes and data APIs, separately from administrative permissions for the domain configuration API.
Wildcard principals can be used with VPC or fine-grained access controls. Assess actual exposure by reviewing those controls together with policy permissions.
Potential impact
- Unnecessary read access can expose logs or document contents.
- Misused write or deletion access can damage indexes and interrupt search services.
Remediation
- Restrict permissions to required principals, HTTP actions such as es:ESHttpGet, and actual index or API paths.
- For VPC domains, check security groups; where fine-grained access control is used, review users and role mappings.
- Retain the intended authentication method and test that necessary searches succeed while unnecessary reads and changes are denied.
Examples
These policy excerpts refer to the same domain. Prepare the referenced domain and index separately and replace the user ARN with the actual value.
Before
resource "aws_elasticsearch_domain_policy" "example" {
domain_name = aws_elasticsearch_domain.example2.domain_name
access_policies = <<POLICIES
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "es:*",
"Resource": "${aws_elasticsearch_domain.example2.arn}/*",
"Principal": "*",
"Effect": "Allow"
}
]
}
POLICIES
}
This permits HTTP actions on domain subresources for all principals. Here, es:* does not grant administration of the domain configuration API.
After
resource "aws_elasticsearch_domain_policy" "example" {
domain_name = aws_elasticsearch_domain.example2.domain_name
access_policies = <<POLICIES
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::123456789012:user/test-user"
]
},
"Action": [
"es:ESHttpGet"
],
"Resource": "${aws_elasticsearch_domain.example2.arn}/test-index/_search"
}
]
}
POLICIES
}
This statement narrows the grant to the specified user’s GET searches on test-index. Other policies and fine-grained access controls also apply.