It's most likely that your instance has been replaced, and therefore the password has been reset. You can check that by going to the tab Instance health -> select an instance -> maximize a graph -> increase the duration to e.g. one week and check for any gaps in the data. Settings like the password are stored on this instance, but I've also noticed it for internal users and index patterns for dashboards. When the instance is replaced, all this is gone. You can prevent this in a couple of ways: - In case you're using an instance in the T range, check if it has high CPU usage. For t3.small, you can run out of CPU credits and the baseline utilization per vCPU is 20% Consider using a non T range instance type. - Use more powerful nodes - Add more nodes

Context: Stack Overflow #79450830 (accepted answer, 5 votes): We are using an AWS stack containing OpenSearch. We have several AWS accounts for different customers, but mainly a similar setup for OpenSearch in all accounts: In each AWS account, there is one PROD and one STAGING OpenSearch domain (PROD and STAGING are our way of configuring and using it, not anything AWS provides). The problem is that from time to time, our master users stop working. Luckily only on the staging domains yet, but who knows? I can't log in to the OpenSearch dashboard with it any more and my app can't via API any more. Our solution is to "create (another?) master user" using...