If Internet access is disabled for the Elasticsearch cluster, the evaluation result is Compliant.
Scenario
Enabling Internet access to Elasticsearch reduces network security, and the access is not stable. We recommend that you enable only virtual private cloud (VPC) access.
Risk level
Default risk level: high.
When you apply this rule, you can change the risk level based on your business requirements.
Compliance evaluation logic
- If Internet access is disabled for the Elasticsearch cluster, the evaluation result is Compliant.
- If Internet access is enabled for the Elasticsearch cluster, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see the "Incompliance remediation" section of this topic.
Rule details
Item | Description |
---|---|
Rule name | elasticsearch-instance-enabled-public-check |
Rule identifier | elasticsearch-instance-enabled-public-check |
Tag | Elasticsearch and Instance |
Automatic remediation | Not supported |
Trigger type | Configuration change |
Supported resource type | Elasticsearch cluster |
Input parameter | None |
Incompliance remediation
Disable Internet access for your Elasticsearch clusters. For more information, see Configure a private connection for an Elasticsearch cluster.