This version of the OpenSearch documentation is no longer maintained. For the latest version, see the current documentation. For information about OpenSearch version maintenance, see Release Schedule and Maintenance Policy.
Default action groups
This page catalogs all default action groups. Often, the most coherent way to create new action groups is to use a combination of these default groups and individual permissions.
|Grants complete access. Can be used on an cluster- or index-level. Equates to
|Grants all cluster permissions. Equates to
|Grants all cluster monitoring permissions. Equates to
|Grants read-only permissions to execute requests like
mtv, plus permissions to query for aliases.
CLUSTER_COMPOSITE_OPS_RO, but also grants
bulk permissions and all aliases permissions.
|Grants permissions to manage snapshots and repositories.
|Grants permissions to manage ingest pipelines.
|Grants permissions to manage index templates.
|Grants all permissions on the index. Equates to
|Grants permissions to use
mget actions only.
|Grants read permissions such as search, get field mappings,
|Grants permissions to create and update documents within existing indices. To create new indices, see
|Grants permissions to delete documents.
delete action groups. Included in the
data_access action group.
|Grants permissions to search documents. Includes
|Grants permissions to use the suggest API. Included in the
read action group.
|Grants permissions to create indices and mappings.
|Grants permissions to execute all index monitoring actions (e.g. recovery, segments info, index stats, and status).
|A more limited version of the
write action group.
crud action group with
|Grants permissions to manage aliases.
|Grants all monitoring and administration permissions for indices.