Upgrading containerised ELK with ROR - changelog detail and upgrade order confusion

Ah! That would explain why it worked ok for us before. Hopefully it’s as simple as that.

Ok that image now patches correctly but we’re back to the KibanaConfigManager issue. Any ideas?

I can cd to node_modules/@kbn/ but in there there's no security-plugin folder. See below

kibana@03b630f2ee11:~/node_modules/@kbn$ pwd
/usr/share/kibana/node_modules/@kbn
kibana@03b630f2ee11:~/node_modules/@kbn$ ls
analytics crypto io-ts-utils securitysolution-io-ts-alerting-types securitysolution-list-constants server-route-repository ui-shared-deps-npm
apm-config-loader es-query legacy-logging securitysolution-io-ts-list-types securitysolution-list-utils std ui-shared-deps-src
apm-utils field-types logging securitysolution-io-ts-types securitysolution-t-grid timelion-grammar utils
config i18n rule-data-utils securitysolution-io-ts-utils securitysolution-utils tinymath
config-schema interpreter securitysolution-es-utils securitysolution-list-api server-http-tools ui-framework
kibana@03b630f2ee11:~/node_modules/@kbn$

Can you run node/glibc-217/bin/node plugins/readonlyrestkbn/ror-tools.js verify And paste a result? (node/glibc-217/bin/node is a command for Linux; for other OS, see docs)

kibana@d5b88e8bb47b:~$ node/glibc-217/bin/node plugins/readonlyrestkbn/ror-tools.js verify

bash: node/glibc-217/bin/node: No such file or directory

kibana@d5b88e8bb47b:~$ node/bin/node plugins/readonlyrestkbn/ror-tools.js verify

[ROR COMPAT] Received command: verify

[ROR COMPAT] Verifying the presence of ROR hooks on Kibana files..

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/authentication_service.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/security/server/authentication/authentication_service.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] authentication_service.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/authorization_mode.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/security/server/authorization/mode.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] mode.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/authorized_user_pre_routing.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/lib/authorized_user_pre_routing.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] authorized_user_pre_routing.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/get_document_payload.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/lib/get_document_payload.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] get_document_payload.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/http_server.js.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../src/core/server/http/http_server.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] http_server.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/job_response_handler.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/lib/job_response_handler.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] job_response_handler.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/jobs_query.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/lib/jobs_query.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] jobs_query.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/management_jobs.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/management/jobs.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] jobs.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/request_handler.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/routes/lib/request_handler.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] request_handler.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/serve.js.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../src/cli/serve/serve.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] serve.js patch status: VERIFIED.

[ROR COMPAT] Found patch file /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/patches_for_kbn_distribution/store.patch

[ROR COMPAT] Verifying patched state…

[ROR COMPAT] /usr/share/kibana/plugins/readonlyrestkbn/kibana/patchers/../../../../x-pack/plugins/reporting/server/lib/store/store.js was patched with the ReadonlyREST plugin version 1.69.1 and Kibana version 7.17.5 on 2026:06:25 13:38:31.

[ROR COMPAT] store.js patch status: VERIFIED.

kibana@d5b88e8bb47b:~$

@DOBs are you sure the ES+ROR pod/s is/are up and running? Are you able to call it and have it respond?

Kibana was patched successfully. Could you send you kibana.yml config and all Kibana logs?

The ES container is showing as healthy but no, the Kibana + ROR containers are all in reboot loops since the attempted upgrade

Just to be clear, Kibana patches successfully, yes, but only with the default kibana.yml which allows me to enter the container’s shell and run the verify command. When I start it with our configuration, I can’t enter the shell to verify that it’s patching correctly but the command baked into the image seems to align with the ROR docs. The command I use to do that is
”docker run -it --entrypoint /bin/bash [REDACTED IMAGE NAME]”

I will get clearance to share those in case of anything sensitive we’d have to redact then revert here.

Hi,

One, additional thing related to the configuration.

Do you have readonlyrest_kbn.cookiePass declared in you kibana.yml? From 1.51.0 version of the plugin, it’s a required parameter.

We have it working now thank you for all the help!

For posterity, I think the main upshots of this were

  1. Per the documents, we need the accept patching switch below. On our old version 1.48, we didn’t need it

node/bin/node plugins/readonlyrestkbn/ror-tools.js patch --I_UNDERSTAND_AND_ACCEPT_KBN_PATCHING=yes # This example applies to Kibana before 8.15.0. Be sure to use the correct Node.js path based on the Kibana version and your operating system.

  1. We need to keep ROR up to date more frequently as a habit or start using ROR’s provided containers. We decided instead of taking the “leap frog” approach to have a brief period of Kibana outage and replace all of our containers using ROR1.48 with containers that instead install ROR1.69

  2. I had set this parameter incorrectly in the YML. I thought it was a string. I just commented it out to get the container started
    WRONG: readonlyrest_kbn.logLevel: ‘trace’
    ??RIGHT?? readonlyrest_kbn.logLevel: trace

1 Like