Expired API keys in Elasticsearch: rejected on use, but do they linger in the cluster?
0 reputation · 18 Nov 2023, 00:26 UTC
Least-privilege access in Elasticsearch typically combines role-based access control with short-lived API keys: each service holds a role scoped to the indices and cluster actions it needs, and the key carries an expiration so credentials rotate on a schedule.
The documented part is straightforward: a request presenting an expired key is rejected. Less clear is the lifecycle of the key record afterward. Expired keys appear to remain in the internal security index until explicitly invalidated or deleted, and cleanup behavior seems to differ between the 7.x and 8.x release lines, with newer versions adding more automation around invalidation. Exact semantics for a specific minor version deserve verification against current documentation.
This matters for credential hygiene: an audit listing can mix valid, expired, and invalidated keys, and a client that caches its token can keep presenting a stale credential after expiration has already passed.
Assuming an Elasticsearch 8.x cluster with API keys enabled:
- Does the cluster ever remove expired key documents on its own, or is removal always an explicit invalidate-and-delete operation?
- Is there a supported way to list only keys that have expired but not yet been removed?
- Do any 8.x settings govern retention or automatic cleanup of expired API keys?