Script types unrestricted
All script types can run: script.allowed_types is unset or allows both inline and stored scripts. Unrestricted types increase the chance of costly or unexpected scripts.
For a complete list of insights, refer to AutoOps insights.
| Field | Value |
|---|---|
| Component | Elasticsearch |
| Severity | Medium |
| Scope | Cluster |
| Domains | performance, security-safety |
The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.
script.allowed_types is unset or allows all types (inline and stored). Current value: inline, stored.
AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.
Restrict allowed script types
Condition: Always shown for this insight.
Set script.allowed_types to inline if you use Kibana, or stored if you only use stored scripts. Use none only if nothing in the cluster must run scripts. Add the setting in elasticsearch.yml, then restart the node.
script.allowed_types: inline
Do not leave the setting unset. Kibana needs inline.
script.allowed_types controls whether inline scripts, stored scripts, both, or none might run. When the setting is unset, Elasticsearch allows all types.
Unrestricted types let any client that can run scripts submit inline or stored scripts in search, update, or ingest. That can raise CPU and heap use.
Many applications need some script types. Kibana requires inline scripts for some features. none blocks all script types and breaks those features. Prefer inline (or stored only) over leaving the default open.