However, writes to the .kibana_task_manager index are being blocked by block lower down which prevent bulk ingestion on this node. So, why is this index update from kibana not captured by this code block?
.kibana_task_manager index - if I remember correctly - should be handled by Kibana server, not by the browser. So please create a block above this with “auth_key” basic auth credentials to be configured in kibana.yml.
Also please, can you paste the whole ACL when you ask support? I’m only imagining that you did not have the kibana server block…