From b5ce4113f2d6829abebdcc5c9d29a6ac488492c4 Mon Sep 17 00:00:00 2001 From: shainaraskas Date: Fri, 4 Sep 2026 16:16:49 -0400 Subject: [PATCH 1/3] Add remote cluster ports to AWS and GCP private connectivity pages Co-authored-by: Cursor --- deploy-manage/security/_snippets/private-url-struct.md | 2 -- deploy-manage/security/private-connectivity-aws.md | 6 +++++- deploy-manage/security/private-connectivity-azure.md | 4 ++++ deploy-manage/security/private-connectivity-gcp.md | 2 ++ 4 files changed, 11 insertions(+), 3 deletions(-) diff --git a/deploy-manage/security/_snippets/private-url-struct.md b/deploy-manage/security/_snippets/private-url-struct.md index c7c3b788e9..a3eebe2751 100644 --- a/deploy-manage/security/_snippets/private-url-struct.md +++ b/deploy-manage/security/_snippets/private-url-struct.md @@ -18,7 +18,5 @@ Use the following URL structure. Take the alias and product from your Elastic en :::{tip} -{{ech}} supports ports 443 and 9243. - You can also connect to the cluster using the {{es}} cluster ID, for example, https://6b111580caaa4a9e84b18ec7c600155e.{{example-phz-dn}}. ::: diff --git a/deploy-manage/security/private-connectivity-aws.md b/deploy-manage/security/private-connectivity-aws.md index b5a4b7f37f..f6c807fde3 100644 --- a/deploy-manage/security/private-connectivity-aws.md +++ b/deploy-manage/security/private-connectivity-aws.md @@ -202,7 +202,7 @@ This limitation does not apply to [cross-region PrivateLink connections](#ec-aws :screenshot: ::: - The security group for the endpoint should, at minimum, allow for inbound connectivity from your instances' CIDR range on ports 443 and 9243. Security groups for the instances should allow for outbound connectivity to the endpoint on ports 443 and 9243. + The security group for the endpoint should, at minimum, allow for inbound connectivity from your instances' CIDR range on ports 443 and 9243. Security groups for the instances should allow for outbound connectivity to the endpoint on ports 443 and 9243. If you use this endpoint for remote cluster traffic, also allow port `9400` or `9443`, depending on the security model you configure. @@ -249,6 +249,8 @@ After you create your VPC endpoint and DNS entries, check that you are able to r ::::{applies-item} ess: ga :::{include} _snippets/private-url-struct.md ::: + +{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md @@ -437,6 +439,8 @@ Use the alias you’ve set up as CNAME DNS record to access your resource. ::::{applies-item} ess: ga :::{include} _snippets/private-url-struct.md ::: + +{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md diff --git a/deploy-manage/security/private-connectivity-azure.md b/deploy-manage/security/private-connectivity-azure.md index 58b0fab9b8..8943bfbfee 100644 --- a/deploy-manage/security/private-connectivity-azure.md +++ b/deploy-manage/security/private-connectivity-azure.md @@ -267,6 +267,8 @@ After you create your private connection, you can check that you're able to reac ::::{applies-item} ess: ga :::{include} _snippets/private-url-struct.md ::: + +{{ech}} supports ports `443` and `9243`. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md @@ -443,6 +445,8 @@ Use the alias you've set up as an A record to access your resource. ::::{applies-item} ess: ga :::{include} _snippets/private-url-struct.md ::: + +{{ech}} supports ports `443` and `9243`. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md diff --git a/deploy-manage/security/private-connectivity-gcp.md b/deploy-manage/security/private-connectivity-gcp.md index 8d138154a8..834f9e9aea 100644 --- a/deploy-manage/security/private-connectivity-gcp.md +++ b/deploy-manage/security/private-connectivity-gcp.md @@ -256,6 +256,8 @@ Use the alias you’ve set up as CNAME A record to access your deployment. :::{include} _snippets/private-url-struct.md ::: +{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. + To access the deployment: 1. If needed, find the endpoint of an application in your deployment: From 8ee16563c44d7d37374461bbc090d3fdcf8269bc Mon Sep 17 00:00:00 2001 From: shainaraskas <58563081+shainaraskas@users.noreply.github.com> Date: Wed, 16 Sep 2026 15:40:51 -0400 Subject: [PATCH 2/3] Apply batched suggestions from code review Co-authored-by: wajihaparvez Co-authored-by: Alex Chalkias <34575586+alxchalkias@users.noreply.github.com> --- deploy-manage/security/private-connectivity-aws.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/deploy-manage/security/private-connectivity-aws.md b/deploy-manage/security/private-connectivity-aws.md index f6c807fde3..65df564077 100644 --- a/deploy-manage/security/private-connectivity-aws.md +++ b/deploy-manage/security/private-connectivity-aws.md @@ -202,7 +202,7 @@ This limitation does not apply to [cross-region PrivateLink connections](#ec-aws :screenshot: ::: - The security group for the endpoint should, at minimum, allow for inbound connectivity from your instances' CIDR range on ports 443 and 9243. Security groups for the instances should allow for outbound connectivity to the endpoint on ports 443 and 9243. If you use this endpoint for remote cluster traffic, also allow port `9400` or `9443`, depending on the security model you configure. + The security group for the endpoint should, at minimum, allow for inbound connectivity from your instances' CIDR range on ports 443 and 9243. Security groups for the instances should allow for outbound connectivity to the endpoint on ports 443 and 9243. If you use this endpoint for remote cluster traffic to an {{ech}} deployment, also allow port `9443` or `9400`, depending on the security model you configure. @@ -250,7 +250,7 @@ After you create your VPC endpoint and DNS entries, check that you are able to r :::{include} _snippets/private-url-struct.md ::: -{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. +{{ech}} supports ports `443` and `9243` for {{es}} and {{kib}} traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md From 2abbe9df8685ff4bc9c8dddc8bed603810bb3932 Mon Sep 17 00:00:00 2001 From: shainaraskas Date: Wed, 16 Sep 2026 16:01:47 -0400 Subject: [PATCH 3/3] supported for azure, incomplete support for gcp --- .../deploy/elastic-cloud/restrictions-known-problems.md | 1 + deploy-manage/security/private-connectivity-azure.md | 4 ++-- deploy-manage/security/private-connectivity-gcp.md | 4 +++- 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md b/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md index 0ae46cac5b..6aa5399465 100644 --- a/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md +++ b/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md @@ -108,6 +108,7 @@ $$$ec-restrictions-network-security-kibana-sso$$$ ``` ```{include} /deploy-manage/security/_snippets/aws-privatelink-cloud-id-limitation.md ``` +* **Remote clusters with API key authentication over GCP Private Service Connect:** Remote cluster connections that use the API key based security model are not yet supported over GCP Private Service Connect because traffic on port `9443` is not currently allowed. Only the TLS certificate based security model (port `9400`) is currently supported for remote cluster traffic over GCP PSC. ## PDF report generation using Alerts or Watcher webhooks [ec-restrictions-network-security-watcher] diff --git a/deploy-manage/security/private-connectivity-azure.md b/deploy-manage/security/private-connectivity-azure.md index 8943bfbfee..fa3a5b9c87 100644 --- a/deploy-manage/security/private-connectivity-azure.md +++ b/deploy-manage/security/private-connectivity-azure.md @@ -268,7 +268,7 @@ After you create your private connection, you can check that you're able to reac :::{include} _snippets/private-url-struct.md ::: -{{ech}} supports ports `443` and `9243`. +{{ech}} supports ports `443` and `9243` for {{es}} and {{kib}} traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md @@ -446,7 +446,7 @@ Use the alias you've set up as an A record to access your resource. :::{include} _snippets/private-url-struct.md ::: -{{ech}} supports ports `443` and `9243`. +{{ech}} supports ports `443` and `9243` for {{es}} and {{kib}} traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. :::: ::::{applies-item} serverless: ga :::{include} _snippets/private-url-struct-serverless.md diff --git a/deploy-manage/security/private-connectivity-gcp.md b/deploy-manage/security/private-connectivity-gcp.md index 834f9e9aea..11b427c5e2 100644 --- a/deploy-manage/security/private-connectivity-gcp.md +++ b/deploy-manage/security/private-connectivity-gcp.md @@ -47,6 +47,8 @@ When using GCP Private Service Connect, the following limitations apply: ```{include} _snippets/private-connectivity-limitations-ech.md ``` +* **Remote clusters with API key authentication:** Remote cluster connections that use the API key based security model are not yet supported over GCP Private Service Connect because traffic on port `9443` is not currently allowed. Only the TLS certificate based security model (port `9400`) is currently supported for remote cluster traffic. + ## Private Service Connect URIs [ec-private-service-connect-uris] Service Attachments are set up by Elastic in all supported GCP regions under the following URIs: @@ -256,7 +258,7 @@ Use the alias you’ve set up as CNAME A record to access your deployment. :::{include} _snippets/private-url-struct.md ::: -{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication uses port `9400` with the TLS certificate based security model, or `9443` with the API key based model. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for the supported combinations. +{{ech}} supports ports `443` and `9243` for Elasticsearch and Kibana traffic. Remote cluster traffic for cross-cluster search and cross-cluster replication is supported with the TLS certificate based security model (port `9400`). The API key based security model is not yet available over GCP Private Service Connect because traffic on port `9443` is not currently allowed. Refer to [Connection paths and private connectivity](/deploy-manage/remote-clusters.md#remote-clusters-connection-paths) for more information. To access the deployment: