opensearch-project / opensearch-project/alerting

Alerts needs stricter ownership

Open
#82 6 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

backlog enhancement
Dominant language
Kotlin
Stars
82
Forks
133
Avg merge
2d 11h
Merged PRs (30d)
9

Description

Issue by oscarkraemer
Thursday Nov 19, 2020 at 10:21 GMT
Originally opened as https://github.com/opendistro-for-elasticsearch/alerting/issues/302


Is your feature request related to a problem? Please describe.
Alerts are hard to managed since the ownership seems to based on all the roles a user belongs to. If a user belongs to many roles then a lot of users will see the alerts that the user creates.

Describe the solution you'd like
Alerts should be owned by tenants and/or alerts should be tightly coupled with a specific role.

Describe alternatives you've considered

  • Only allow users that only have one role.
  • Not using alerting.

Additional context
Assumes that this is configured: “opendistro.alerting.filter_by_backend_roles": "true”

Our example organisation:
network-admins belongs to network-role
database-admins belongs to database-role
Senior-admins - belongs to network-role and database-role

In this kind of setup senior-admins can’t create an alerts that only network-admins have access, since all alerts senior-admin creates both network-admins and database-admins will have access to.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing how the opendistro.alerting.filter_by_backend_roles setting determines alert visibility and how tenants and backend roles are represented. Compare the senior-admins example with the requested tenant- or role-specific ownership; done means alerts created by a user with multiple roles can be restricted to the intended group.

Written by the indexing model from the issue text.

Assessment

Tech stack
kotlin
Domain
authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.