Script types unrestricted

All script types can run: script.allowed_types is unset or allows both inline and stored scripts. Unrestricted types increase the chance of costly or unexpected scripts.

Note

For a complete list of insights, refer to AutoOps insights.

Field Value
Component Elasticsearch
Severity Medium
Scope Cluster
Domains performance, security-safety

The following is an example of what you might see when this insight is triggered. Real insights use live data and links from your deployment or cluster.

script.allowed_types is unset or allows all types (inline and stored). Current value: inline, stored.

Note

AutoOps shows different recommendations depending on how their conditions match your deployment or cluster.

script.allowed_types controls whether inline scripts, stored scripts, both, or none might run. When the setting is unset, Elasticsearch allows all types.

Unrestricted types let any client that can run scripts submit inline or stored scripts in search, update, or ingest. That can raise CPU and heap use.

Many applications need some script types. Kibana requires inline scripts for some features. none blocks all script types and breaks those features. Prefer inline (or stored only) over leaving the default open.

Scripting and security in Painless