Link Search Menu Expand Document Documentation Menu

Disable security

You might want to temporarily disable the security plugin to make testing or internal usage more straightforward. To disable the plugin, add the following line in opensearch.yml:

plugins.security.disabled: true

A more permanent option is to remove the security plugin entirely:

  1. Delete the plugins/opensearch-security folder on all nodes.
  2. Delete all plugins.security.* configuration entries from opensearch.yml.

To perform these steps on the Docker image, see Customize the Docker image.

Disabling or removing the plugin exposes the configuration index for the security plugin. If the index contains sensitive information, be sure to protect it through some other means. If you no longer need the index, delete it.

Remove OpenSearch Dashboards plugin

The security plugin is actually two plugins: one for OpenSearch and one for OpenSearch Dashboards. You can use the OpenSearch plugin independently, but the OpenSearch Dashboards plugin depends on a secured OpenSearch cluster.

If you disable the security plugin in opensearch.yml (or delete the plugin entirely) and still want to use OpenSearch Dashboards, you must remove the corresponding OpenSearch Dashboards plugin. For more information, see OpenSearch Dashboards remove plugins.

Docker

  1. Create a new Dockerfile:

    FROM opensearchproject/opensearch-dashboards:1.0.0
    RUN /usr/share/opensearch-dashboards/bin/opensearch-dashboards-plugin remove security-dashboards
    COPY --chown=opensearch-dashboards:opensearch-dashboards opensearch_dashboards.yml /usr/share/opensearch-dashboards/config/
    

    In this case, opensearch_dashboards.yml is a “vanilla” version of the file with no entries for the security plugin. It might look like this:

    ---
    server.name: opensearch-dashboards
    server.host: "0"
    opensearch.hosts: http://localhost:9200
    
  2. To build the new Docker image, run the following command:

    docker build --tag=opensearch-dashboards-no-security .
    
  3. In docker-compose.yml, change opensearchproject/opensearch-dashboards:1.0.0 to opensearch-dashboards-no-security.
  4. Change OPENSEARCH_HOSTS or opensearch.hosts to http:// rather than https://.
  5. Enter docker-compose up.