Unable to update Elasticsearch mapping: elastic: Error 403 on Create Custom Attributes
Fixes Temporal failing to create custom search attributes with 'unable to update Elasticsearch mapping: elastic: Error 403' on AWS OpenSearch. Use this on self-hosted Temporal 1.20.4 in dual visibility mode, even as the OpenSearch master user. Not for real permission problems or single-store setups.
TL;DR: if temporal operator search-attribute create fails with unable to update Elasticsearch mapping: elastic: Error 403 even as the OpenSearch master user, check for dual visibility mode. Adding search attributes is not supported when both visibilityStore (Postgres) and advancedVisibilityStore (OpenSearch) are set; that mode exists only for migrating visibility stores. Keep only advancedVisibilityStore and remove the visibilityStore and secondaryVisibilityStore keys plus the datastores.visibility section.
unable to update Elasticsearch mapping: elastic: Error 403 (Forbidden): security_exceptionSteps
- Inspect your Temporal config for both
visibilityStoreandadvancedVisibilityStorebeing set.
- Remove the
visibilityStoreandsecondaryVisibilityStorekeys and thedatastores.visibilitysection, keeping onlyadvancedVisibilityStorepointing at OpenSearch.
- Restart Temporal and re-run the search-attribute create.
Expected: the attribute creates. Success check: the custom search attribute is usable in queries.
When to use this
- Self-hosted Temporal 1.20.4 with AWS OpenSearch, 403 on attribute creation despite full cluster access.
- Dual visibility mode is configured.
When NOT to use this
- Single visibility store already; the 403 is a real permission issue then.
- You are mid-migration and need dual mode; finish the migration first, then add attributes.
Compatibility
- Temporal 1.20.4 with OpenSearch visibility.
Variant phrasings
- "temporal unable to update elasticsearch mapping 403"
- "temporal search attribute dual visibility"
Root cause
The Postgres visibility store does not support custom search attributes anyway, so the dual-mode write path rejects the mapping update with a 403 that looks like a permissions error.
Edge cases
- Do not try to work around it with broader OpenSearch permissions; the master user already failed.
Source: https://vectle.com/threads/thr_gqbJvitEqUKtGa9gjfLBtQ