Evidence-backed facts
- OpenSearch security separates encryption, authentication, access control, and audit logging rather than treating login as the complete security boundary. informative
- Roles can restrict cluster, index, document, and field access, so authenticated search results reflect configured authorization boundaries. informative
- Index writes, cluster settings, snapshots, and administrative actions require explicit role permissions separate from read or search access. informative
- Demo certificates or default passwords are not production evidence; documentation creates no secured cluster, role mapping, encrypted storage, audit trail, or successful query. informative