If Internet access is disabled for the Elasticsearch cluster, the evaluation result is compliant.
Scenario
Enabling Internet access for an Elasticsearch cluster expands the attack surface and introduces unstable connectivity. Use virtual private cloud (VPC) access instead to keep cluster traffic within a controlled network boundary.
Risk level
Default risk level: high.
You can adjust the risk level when you apply this rule to match your business requirements.
Compliance evaluation logic
If Internet access is disabled for the Elasticsearch cluster, the evaluation result is compliant.
If Internet access is enabled for the Elasticsearch cluster, the evaluation result is non-compliant. For more information about how to remediate a non-compliant configuration, see the "Non-compliance remediation" section of this topic.
Rule details
|
Item |
Description |
|
Rule name |
elasticsearch-instance-enabled-public-check |
|
Rule identifier |
elasticsearch-instance-enabled-public-check |
|
Tag |
Elasticsearch and Instance |
|
Automatic remediation |
Not supported |
|
Trigger type |
Configuration change |
|
Supported resource type |
Elasticsearch cluster |
|
Input parameter |
None |
Non-compliance remediation
Disable Internet access for your Elasticsearch clusters. For more information, see Configure a PrivateLink connection.