Skip to content

Camunda Elastic Security

  • Camunda Helm Charts comes with Elasticsearch deployment. However, it does not come with any security enabled.

  • This document explains how to enable security for Elasticsearch. We are going to enable Basic Authentication for Elasticsearch. (meaning setting up username and password as authentication for security)

  • Before enabling Security for Elasticsearch, we need to understand which all components interact with Elasticsearch.

camunda-elastic-components

Camunda components that interact with Elasticsearch:

  • Zeebe broker
  • Operate
  • Tasklist
  • Optimize

Other components that interact with Elasticsearch:

  • Kibana

Hence, if we enable Security for Elasticsearch, we need to make sure that all the above components are able to interact with Elasticsearch.


Creating Elasticsearch credentials

  • We need to create a Kubernetes secret to store the Elasticsearch credentials. This secret will be used by all the components to interact with Elasticsearch.

elastic-credentials-secret.yaml file. (located in k8s folder)

apiVersion: v1
kind: Secret
metadata:
  name: elastic-credentials-secret
  namespace: <name-space>
type: Opaque
data:
  elasticUsername: <elastic-username>
  elasticPassword: <elastic-password>

Elasticsearch Security

  • Elasticsearch security is disabled by default in the Helm Chart.

  • To enable security, we need to set the below values in elasticsearch section in the values.yaml file.

  extraEnvs:
    - name: "xpack.security.enabled"
      value: "true"
    - name: ELASTIC_USER
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: ELASTIC_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword

Zeebe Broker with Elasticsearch security

  • Zeebe broker uses Elasticsearch to store the workflow data. Hence, we need to make sure that Zeebe broker is able to interact with Elasticsearch.

  • To enable Zeebe broker to interact with Elasticsearch, we need to set the below values in zeebe section in the values.yaml file.

  env:
    - name: ZEEBE_BROKER_EXPORTERS_ELASTICSEARCH_ARGS_AUTHENTICATION_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: ZEEBE_BROKER_EXPORTERS_ELASTICSEARCH_ARGS_AUTHENTICATION_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword

Operate with Elasticsearch security

  • Operate uses Elasticsearch to read the workflow data for real time monitoring. Hence, we need to make sure that Operate is able to interact with Elasticsearch.

  • To enable Operate to interact with Elasticsearch, we need to set the below values in operate section in the values.yaml file.

  env:
    - name: CAMUNDA_OPERATE_ELASTICSEARCH_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: CAMUNDA_OPERATE_ELASTICSEARCH_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword
    - name: CAMUNDA_OPERATE_ZEEBEELASTICSEARCH_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: CAMUNDA_OPERATE_ZEEBEELASTICSEARCH_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword

Tasklist with Elasticsearch security

  • Tasklist uses Elasticsearch to read the workflow data related to User Tasks. Hence, we need to make sure that Tasklist is able to interact with Elasticsearch.

  • To enable Tasklist to interact with Elasticsearch, we need to set the below values in tasklist section in the values.yaml file.

  env:
    - name: CAMUNDA_TASKLIST_ELASTICSEARCH_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: CAMUNDA_TASKLIST_ELASTICSEARCH_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword
    - name: CAMUNDA_TASKLIST_ZEEBEELASTICSEARCH_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: CAMUNDA_TASKLIST_ZEEBEELASTICSEARCH_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword

Optimize with Elasticsearch security

  • Optimize uses Elasticsearch to read the workflow data for analytics and reporting. Hence, we need to make sure that Optimize is able to interact with Elasticsearch.

  • Enabling security for Optimize is not as simple as other modules like adding the environment variables. We need to create a custom ConfigMap for Optimize with the required environment variables, and mount the ConfigMap to the Optimize pod at a specific path.

Create ConfigMap for Optimize

optimize-env-config.yaml file. (located in k8s folder)

apiVersion: v1
kind: ConfigMap
metadata:
  name: optimize-configmap
  namespace: <name-space>
data:
  environment-config.yaml: |
    es:
      security:
        username: ${CAMUNDA_OPTIMIZE_ELASTICSEARCH_USERNAME}
        password: ${CAMUNDA_OPTIMIZE_ELASTICSEARCH_PASSWORD}

Note

The filename provided in the above ConfigMap should be environment-config.yaml and cannot be changed, as the Optimize pod will look for this specific file only.

Create env variables for Optimize

  • We need to set the below values in optimize section in the values.yaml file.

  • These values will be used by the above ConfigMap properties, as in the ConfigMap we have provided the placeholders for the actual values.

  env:
    - name: CAMUNDA_OPTIMIZE_ELASTICSEARCH_USERNAME
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticUsername
    - name: CAMUNDA_OPTIMIZE_ELASTICSEARCH_PASSWORD
      valueFrom:
        secretKeyRef:
          name: elastic-credentials-secret
          key: elasticPassword

Mount ConfigMap to Optimize pod

  • We need to set the below values in optimize section in the values.yaml file. These values will be used to mount the ConfigMap to the Optimize pod.
  extraVolumes:
    - name: environment-config
      configMap:
        name: optimize-configmap
        defaultMode: 0777
  extraVolumeMounts:
    - name: environment-config
      mountPath: /optimize/config/environment-config.yaml
      subPath: environment-config.yaml

Note

The mountPath and subPath values should not be changed, as the Optimize pod will look for the file at this specific path only.


Kibana with Elasticsearch security

  • Kibana uses Elasticsearch to visualize the Elastic indices. Kibana is not part of the Camunda Helm Chart, but it is deployed as a separate Deployment in the same namespace.

  • Kibana is also deployed as an Ingress service, so that it can be accessed using URL. However, as the Elasticsearch security is enabled, we need to make sure that Kibana is able to interact with Elasticsearch.

  • The same credentials will be used to Login to Kibana UI.

kibana.yaml file. (located in k8s folder)

---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: kibana-deployment
  namespace: <name-space>
  labels:
    app: kibana
spec:
  replicas: 1
  selector:
    matchLabels:
      app: kibana
  template:
    metadata:
      labels:
        app: kibana
    spec:
      containers:
        - name: kibana
          image: <acr-host>/<acr-registry-name>:kibana-7.17.13
          imagePullPolicy: IfNotPresent
          resources:
            limits:
              cpu: 2000m
              memory: "2048Mi"
            requests:
              cpu: 500m
              memory: "1024Mi"
          env:
            - name: ELASTICSEARCH_URL
              value: http://elasticsearch-master:9200
            - name: ELASTICSEARCH_HOSTS
              value: http://elasticsearch-master:9200
            - name: SERVER_BASEPATH
              value: /<tenant-name>/kibana
            - name: SERVER_PUBLICBASEURL
              value: https://optima-<URL_ENV>tenants.optumrx.com/<tenant-name>/kibana
            - name: SERVER_REWRITEBASEPATH
              value: "true"
            - name: ELASTICSEARCH_USERNAME
              valueFrom:
                secretKeyRef:
                  name: elastic-credentials-secret
                  key: elasticUsername
            - name: ELASTICSEARCH_PASSWORD
              valueFrom:
                secretKeyRef:
                  name: elastic-credentials-secret
                  key: elasticPassword
          ports:
            - containerPort: 5601
---
apiVersion: v1
kind: Service
metadata:
  name: kibana-svc
  namespace: <name-space>
  labels:
    app: kibana
spec:
  ports:
    - port: 80
      targetPort: 5601
  selector:
    app: kibana
  type: ClusterIP
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: kibana-ingress
  namespace: <name-space>
  annotations:
    nginx.ingress.kubernetes.io/force-ssl-redirect: 'true'
    nginx.ingress.kubernetes.io/ssl-redirect: 'true'
    nginx.org/mergeable-ingress-type: minion
spec:
  ingressClassName: nginx
  rules:
    - host: optima-<URL_ENV>tenants.optumrx.com
      http:
        paths:
          - path: /<tenant-name>/kibana
            pathType: Prefix
            backend:
              service:
                name: kibana-svc
                port:
                  number: 80

kibana-login-page


Summary

With these, we have enabled security (Basic Auth) for Elasticsearch and all the components that interact with Elasticsearch.


Automating the Process

  • We can automate the process of enabling security for Elasticsearch and all the components that interact with Elasticsearch.

  • Below are the list of things that we have to automate:

    • Environment variables for Elasticsearch/Zeebe/Operate/Tasklist/Optimize (taken care from the Helm Chart itself)
    • Creating the Kubernetes secret for Elasticsearch credentials (added in the script pre-installation of Camunda Helm Chart)
    • Creating the ConfigMap for Optimize (added in the script pre-installation of Camunda Helm Chart)
    • Mounting the ConfigMap to Optimize pod (taken care from the Helm Chart itself)
    • Creating the Kibana deployment, service and ingress (added in the script post-installation of Camunda Helm Chart)

Summary of Automating the Process

We have followed 3 steps to automate the process:

  • Pre-installation of Camunda Helm Chart
    • Will deploy the Kubernetes secret for Elasticsearch credentials
    • Will deploy the ConfigMap for Optimize
  • Installation of Camunda Helm Chart
    • Will deploy the Camunda Helm Chart with the required environment variables in each component
  • Post-installation of Camunda Helm Chart
    • Will deploy the Kibana deployment, service and ingress