Skip to main content

OpenSearch SSO overview

A ClusterNest managed OpenSearch cluster can authenticate users against external identity providers. You configure them as a list of auth_sources. Each source is either OIDC or SAML, and each has a unique name.

The built-in internal user always exists. It is used for API access and credential rotation, and it is always offered on the Dashboards login page next to your sources.

Source types​

OIDCSAML
Identifies the IdP withconnect_urlidp_metadata_url and idp_entity_id
Also needsclient_id, client_secret (Dashboards login only)sp_entity_id
Role claimroles_keyroles_key
Username claimsubject_keysubject_key

Both types accept an optional ca_cert (base64-encoded PEM) for an IdP behind a private CA.

Dashboards login and API access​

Every source can authenticate API requests. Set dashboards_login = true to also offer a source as a button on the OpenSearch Dashboards login page.

  • At most one OIDC source and one SAML source can have dashboards_login enabled.
  • An OIDC source without dashboards_login validates bearer tokens only. It needs no client_secret.
  • An OIDC source with dashboards_login requires a client_secret.

The name of a source becomes the text of its Dashboards button, "Login with" followed by the name.

Secrets are write-only​

The API never returns client_secret. Reads report client_secret_set instead, which tells you whether a secret is stored. The same applies to repo_config.secret_access_key, which reports secret_access_key_set.

Updates replace the whole auth_sources list, and anything you leave out is removed. Sources are matched by name. Leaving out client_secret on an existing source keeps the stored secret, while a new or renamed source must supply one. The Terraform provider resends the secret from your configuration on every apply.

Role mapping​

roles_key names the claim that carries a user's roles. Those values become backend roles in OpenSearch. ClusterNest does not create role mappings. Map backend roles to OpenSearch roles yourself in Dashboards or through the security API.

Provider guides​