---
title: Charmhub | Deploy OpenSearch using Charmhub - The Open Operator Collection
description: Deploy the latest version of OpenSearch on any cloud.
url: https://charmhub.io/opensearch/libraries/opensearch_relation_provider
---

# OpenSearch

[Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

* [Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")
* [Databases](https://charmhub.io/?filter=databases)

Platform:

24.04

22.04

2/stable 344

```
juju deploy opensearch --channel 2/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#drawer)

## charms.opensearch.v0.opensearch\_relation\_provider

* [*Docstrings*Docstrings](https://charmhub.io/opensearch/libraries/opensearch_relation_provider)
  [*Code*Source code](https://charmhub.io/opensearch/libraries/opensearch_relation_provider/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.opensearch.v0.opensearch_relation_provider
    ```

    [Download opensearch\_relation\_provider.py](https://charmhub.io/opensearch/libraries/opensearch_relation_provider/download)
  + *Last updated* 12 Aug 2024
  + *Revision* Library version 0.1

OpenSearch client relation hooks & helpers.

See this link for a detailed spec:
https://github.com/canonical/charm-relation-interfaces/tree/main/interfaces/opensearch\_client/v0

The read-only-endpoints field of DatabaseProvides is unused in this relation because this concept
is irrelevant to OpenSearch. In this relation, the application charm should have control over node
& index security policies, and therefore differentiating between types of network endpoints is
unnecessary.

A role will be created for the relation with the permissions and action groups applied, and these
roles will be mapped to a dedicated user for the relation, which will be removed with the relation.
Default security values can be found in the opensearch documentation here:
https://opensearch.org/docs/latest/security/access-control/index/.

---

Index

* [class ExtraUserRolePermissions](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#extrauserrolepermissions)
* [class OpenSearchProvider](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider)
* + [def \_\_init\_\_(
    self,
    charm)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-__init__)
* + [def dashboards\_relations(
    self)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-dashboards_relations)
* + [def validate\_index\_name(
    self,
    index\_name)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-validate_index_name)
* + [def create\_opensearch\_users(
    self,
    username,
    hashed\_pwd,
    index,
    extra\_user\_roles)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-create_opensearch_users)
* + [def get\_extra\_user\_role\_permissions(
    self,
    extra\_user\_roles,
    index)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-get_extra_user_role_permissions)
* + [def update\_certs(
    self,
    relation\_id,
    ca\_chain)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-update_certs)
* + [def update\_endpoints(
    self,
    relation,
    omit\_endpoints)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-update_endpoints)
* + [def update\_dashboards\_password(
    self)](https://charmhub.io/opensearch/libraries/opensearch_relation_provider#opensearchprovider-update_dashboards_password)

#### class ExtraUserRolePermissions

Description

An enum of user types and their associated permissions. None

#### class OpenSearchProvider

Defines functionality for the 'provides' side of the 'opensearch-client' relation.

Description

Hook events observed:
- index-requested
- relation-departed
- relation-broken

Methods

OpenSearchProvider.
\_\_init\_\_(

*self*

,
charm
)

Constructor for OpenSearchProvider object.

Arguments

charm

the charm providing the opensearch relation

OpenSearchProvider.
dashboards\_relations(

*self*
)

Description

Return the dashboard relations out of all. None

OpenSearchProvider.
validate\_index\_name(

*self*

,
index\_name: str
)

Description

Validates that the index name provided in the relation is acceptable. None

OpenSearchProvider.
create\_opensearch\_users(

*self*

,
username: str

,
hashed\_pwd: str

,
index: str

,
extra\_user\_roles: str
)

Creates necessary opensearch users and permissions for this relation.

Description

Args:
username: Username to be created
hashed\_pwd: the hash of the password to be assigned to the user
index: the index to which the users must be granted access
extra\_user\_roles: the level of permissions that the user should be given. Can be a
comma-separated list of roles, which should result in a merged list of permissions.

Raises:
OpenSearchUserMgmtError if user creation fails

OpenSearchProvider.
get\_extra\_user\_role\_permissions(

*self*

,
extra\_user\_roles: str

,
index: str
)

Get relation role permissions from the extra\_user\_roles field.

Arguments

extra\_user\_roles

role requested by the requirer unit, provided in relation databag.
This needs to be one of "admin" or "default", or it will be set to "default".
TODO should this fail and raise an error instead so provider charm authors can
guarantee they're getting the perms they expect?

index

if these permissions are index-specific, they will be assigned to this index.

Returns

A dict containing the required permissions for the requested role.

OpenSearchProvider.
update\_certs(

*self*

,
relation\_id

,
ca\_chain
)

Update TLS certs passed into this relation.

Description

If ca\_chain is not provided, it'll get the app-admin CA generated by the TLS charm.

OpenSearchProvider.
update\_endpoints(

*self*

,
relation: Relation

,
omit\_endpoints
)

Description

Updates endpoints in the databag for the given relation. None

OpenSearchProvider.
update\_dashboards\_password(

*self*
)

Description

Update each Opensearch Dashboards relation with the latest kibanaserver. None
