Security
Octane adds no authentication and no authorization of its own. Every endpoint below is an ordinary OpenSearch REST route, protected by whatever protects the rest of your cluster — normally the OpenSearch security plugin. Installing Octane does not open a door, and it does not close one either: an unsecured cluster stays unsecured.
The one thing Octane does enforce is licensing, and that is not access control. A licensed cluster is not an authorized caller. See Licensing.
The endpoints, and the action names to grant
Roles are mapped by handler name, so these are the strings a security role references.
| Method | Path | Handler |
|---|---|---|
GET | /_lucenia/license | get_autoscale_license_action |
PUT | /_lucenia/license | put_autoscale_license_action |
POST | /_lucenia/license/_start_trial | start_autoscale_trial_action |
PUT GET DELETE | /_plugins/_compliance/policies/{name} | compliance_policy_action |
GET | /_plugins/_compliance/policies | compliance_policy_action |
GET | /_plugins/_compliance/presets, /presets/{id} | compliance_presets_action |
GET | /_plugins/_compliance/frameworks, /frameworks/{id} | compliance_frameworks_action |
GET | /_plugins/_compliance/governance, /governance/{id} | compliance_governance_action |
POST | /_plugins/_compliance/_convert/presidio | compliance_convert_presidio_action |
POST | /_plugins/_ontology/{vocabulary}/_import | ontology_import_action |
Three of these change what the cluster does and deserve separate treatment from the reads:
PUT /_lucenia/licenseinstalls the commercial terms. It is deliberately not license-gated — an expired cluster must be able to accept its renewal — so the only thing standing in front of it is your authorization layer.PUT/DELETE /_plugins/_compliance/policies/{name}changes what gets redacted. Whoever holds it can stop redaction happening.POST /_plugins/_ontology/{vocabulary}/_importwrites an index and fetches a remote URI.
The controller's indices are hidden, not protected
The autoscale controller keeps its state in five indices:
.octane-autoscale-policies .octane-drains .octane-drain-leases
.octane-rolling-restarts .octane-license
They are created with index.hidden: true, which keeps them out of wildcard expansion. That is
visibility, not authorization. They are not registered system indices, so any principal with index
privileges on their names — or on a pattern that includes them — can read and write them directly.
The contents matter: policies decide scaling, drain records track allocation exclusions, and
.octane-license holds the trial record.
Grant them explicitly, to the controller's principal and to nobody else. A role granting * on
indices includes these.
Who the redaction thinks you are
Query-time compliance redaction is identity-aware, and it reads the caller from the security plugin's own thread-context value rather than linking that plugin's classes.
It fails closed. When no verified identity is present — the security plugin is not installed, the node is acting under its own identity, or the caller is a certificate-authenticated super-admin — the caller is treated as not exempt and the values are redacted. Exemption is something a pipeline grants explicitly; it is never the default and never inferred from an absent identity.
The details of exemption, and of every path a value can leave by, are in Compliance.
Fetching remote content
Several processors fetch a URI named inside a document. That is an SSRF surface, and it is closed by
default: no host is reachable until it is listed in octane.content.source.allowed_hosts.
The setting is dynamic. Change it with a cluster-settings update; it takes effect without a restart, and the allowlist is re-read live. Host matching is exact and redirects are re-checked against the list. See Source access.
The controller's credential
The controller runs outside the cluster and authenticates like any other client: the
octane.clusters.<id>.authorization value is sent verbatim as an Authorization header.
It is a credential in a configuration file. Mount it as a secret — not as a ConfigMap, and not baked
into an image. The controller needs enough privilege to read cluster state and node stats, to write
cluster settings for allocation exclusions, and to read and write its own .octane-* indices. It
does not need anything else. See Configuration.
The license signing key
The public half ships inside octane-license and is safe to ship: it can check a signature and
never make one. Verification is a local check — nothing contacts a Lucenia server at install time or
ever.
The private half never leaves Lucenia's vault. There is deliberately no mechanism to substitute the verification key — not a setting, not a system property, not a test hook. A switch that decides which key makes a license genuine is a way to forge one.
What Octane does not provide
Stated plainly, because assuming otherwise is the expensive mistake:
- No field- or document-level security of its own. Compliance redaction is a content control, not an access control: it rewrites values in responses, and it is configured per pipeline rather than per role.
- No encryption at rest. Accelerated indices, graph edges and vocabulary indices are ordinary Lucene data on disk.
- No audit log of its own. Compliance emits its own findings and read records — see Compliance — and the controller writes an operational log. Neither is a cluster audit trail.
- No secrets store. Provider credentials and the controller's authorization header are supplied by configuration you protect.