Skip to content

(short issue d[11.2.15] After automatic update: backend and event processor rejected by OpenSearch with HTTP 401 (user "admin"), console down, no events indexedescription) #2792

Description

@Klenk-IT

Acknowledgements

Describe the bug

Environment

  • Docker Swarm, updated automatically from 11.2.14 to 11.2.15 on 2026-09-30 (around [time] UTC)
  • OpenSearch container recreated during the update; [edition: community ]

Symptoms

  • Backend start check: environment ok, database ok, liquibase ok, then Ping to elasticsearch fail: HTTP 401 (5x) and Fail to establish connection with elasticsearch. The container exits and Swarm restarts it in a loop. Frontend and user-auditor also stay at 0/1.
  • Event processor: bulk request failed ... failed to json unmarshal body: invalid character 'U' looking for beginning of value (OpenSearch returns the plain text "Unauthorized"). No events are indexed.
  • OpenSearch log, several times per second: [o.o.s.a.BackendRegistry] Authentication finally failed for admin from <internal IP>

Before the update

With 11.2.14 the backend check reported "Success" for the Elasticsearch connection.

Not verified

Whether the credentials in the stack environment differ from those OpenSearch expects, and which side changed.

Question

What changed in the credential handling between 11.2.14 and 11.2.15, and how can an affected instance be recovered without losing data?

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

Current Behavior

Reproduction Steps

Possible Solution

Additional Information/Context

UTMStack Version

11.2.15

Operating System and version

Ubuntu 24.04.5 LTS

Hypervisor and Version | Server Vendor and Model

Microsoft HyperV 2019 Datacenter

Browser and version

Chrome 154.0.8037.58

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions