From 3dd934711cabf471e060a55107496f3c9e1ca9a5 Mon Sep 17 00:00:00 2001 From: Tim Scheuermann Date: Mon, 9 Jan 2023 14:34:54 +0100 Subject: [PATCH] [MM-47187] Certificate auth for Elasticsearch (#21958) --- i18n/en.json | 20 ++++++++++++++++++++ model/config.go | 15 +++++++++++++++ services/telemetry/telemetry.go | 3 +++ 3 files changed, 38 insertions(+) diff --git a/i18n/en.json b/i18n/en.json index b0cf93cf7e..6bf836abe8 100644 --- a/i18n/en.json +++ b/i18n/en.json @@ -7351,6 +7351,26 @@ "id": "ent.elasticsearch.aggregator_worker.index_job_failed.error", "translation": "Elasticsearch aggregator worker failed due to the indexing job failing" }, + { + "id": "ent.elasticsearch.create_client.ca_cert_malformed", + "translation": "Decoding of the CA for Elasticsearch failed" + }, + { + "id": "ent.elasticsearch.create_client.ca_cert_missing", + "translation": "Could not open the CA file for Elasticsearch" + }, + { + "id": "ent.elasticsearch.create_client.client_cert_malformed", + "translation": "Decoding of the client certificate for Elasticsearch failed" + }, + { + "id": "ent.elasticsearch.create_client.client_cert_missing", + "translation": "Could not open the client certificate file for Elasticsearch" + }, + { + "id": "ent.elasticsearch.create_client.client_key_missing", + "translation": "Could not open the client key file for Elasticsearch" + }, { "id": "ent.elasticsearch.create_client.connect_failed", "translation": "Setting up Elasticsearch Client Failed" diff --git a/model/config.go b/model/config.go index 7f9c807562..ad169fcbbf 100644 --- a/model/config.go +++ b/model/config.go @@ -2563,6 +2563,9 @@ type ElasticsearchSettings struct { BatchSize *int `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` RequestTimeoutSeconds *int `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` SkipTLSVerification *bool `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` + CA *string `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` + ClientCert *string `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` + ClientKey *string `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` Trace *string `access:"environment_elasticsearch,write_restrictable,cloud_restrictable"` } @@ -2579,6 +2582,18 @@ func (s *ElasticsearchSettings) SetDefaults() { s.Password = NewString(ElasticsearchSettingsDefaultPassword) } + if s.CA == nil { + s.CA = NewString("") + } + + if s.ClientCert == nil { + s.ClientCert = NewString("") + } + + if s.ClientKey == nil { + s.ClientKey = NewString("") + } + if s.EnableIndexing == nil { s.EnableIndexing = NewBool(false) } diff --git a/services/telemetry/telemetry.go b/services/telemetry/telemetry.go index ec88b868c0..860960c379 100644 --- a/services/telemetry/telemetry.go +++ b/services/telemetry/telemetry.go @@ -777,6 +777,9 @@ func (ts *TelemetryService) trackConfig() { "bulk_indexing_batch_size": *cfg.ElasticsearchSettings.BatchSize, "request_timeout_seconds": *cfg.ElasticsearchSettings.RequestTimeoutSeconds, "skip_tls_verification": *cfg.ElasticsearchSettings.SkipTLSVerification, + "isdefault_ca": isDefault(*cfg.ElasticsearchSettings.CA, ""), + "isdefault_client_cert": isDefault(*cfg.ElasticsearchSettings.ClientCert, ""), + "isdefault_client_key": isDefault(*cfg.ElasticsearchSettings.ClientKey, ""), "trace": *cfg.ElasticsearchSettings.Trace, })