Acknowledgements
Describe the bug
Environment
- Docker Swarm, updated automatically from 11.2.14 to 11.2.15 on 2026-09-30 (around [time] UTC)
- OpenSearch container recreated during the update; [edition: community ]
Symptoms
- Backend start check: environment ok, database ok, liquibase ok, then
Ping to elasticsearch fail: HTTP 401 (5x) and Fail to establish connection with elasticsearch. The container exits and Swarm restarts it in a loop. Frontend and user-auditor also stay at 0/1.
- Event processor:
bulk request failed ... failed to json unmarshal body: invalid character 'U' looking for beginning of value (OpenSearch returns the plain text "Unauthorized"). No events are indexed.
- OpenSearch log, several times per second:
[o.o.s.a.BackendRegistry] Authentication finally failed for admin from <internal IP>
Before the update
With 11.2.14 the backend check reported "Success" for the Elasticsearch connection.
Not verified
Whether the credentials in the stack environment differ from those OpenSearch expects, and which side changed.
Question
What changed in the credential handling between 11.2.14 and 11.2.15, and how can an affected instance be recovered without losing data?
Regression Issue
Expected Behavior
Current Behavior
Reproduction Steps
Possible Solution
Additional Information/Context
UTMStack Version
11.2.15
Operating System and version
Ubuntu 24.04.5 LTS
Hypervisor and Version | Server Vendor and Model
Microsoft HyperV 2019 Datacenter
Browser and version
Chrome 154.0.8037.58
Acknowledgements
Describe the bug
Environment
Symptoms
Ping to elasticsearch fail: HTTP 401(5x) andFail to establish connection with elasticsearch. The container exits and Swarm restarts it in a loop. Frontend and user-auditor also stay at 0/1.bulk request failed ... failed to json unmarshal body: invalid character 'U' looking for beginning of value(OpenSearch returns the plain text "Unauthorized"). No events are indexed.[o.o.s.a.BackendRegistry] Authentication finally failed for admin from <internal IP>Before the update
With 11.2.14 the backend check reported "Success" for the Elasticsearch connection.
Not verified
Whether the credentials in the stack environment differ from those OpenSearch expects, and which side changed.
Question
What changed in the credential handling between 11.2.14 and 11.2.15, and how can an affected instance be recovered without losing data?
Regression Issue
Expected Behavior
Current Behavior
Reproduction Steps
Possible Solution
Additional Information/Context
UTMStack Version
11.2.15
Operating System and version
Ubuntu 24.04.5 LTS
Hypervisor and Version | Server Vendor and Model
Microsoft HyperV 2019 Datacenter
Browser and version
Chrome 154.0.8037.58