OpenSearch node-to-node encryption needs review

Encrypt internal node-to-node traffic in Elasticsearch and OpenSearch domains.

Description

Without node-to-node encryption, data can move between nodes in an Elasticsearch or OpenSearch domain without encryption. Client-facing HTTPS and encryption at rest do not replace protection of this internal connection.

Potential impact

  • An attacker with access to the internal communication path may obtain replication or search data.
  • The domain may not meet encryption requirements for sensitive logs or search indexes.

Remediation

  • Set NodeToNodeEncryptionOptions.Enabled to true.
  • Check update support for the existing domain’s version and assess service impact, then verify the applied encryption state.
  • Configure client HTTPS, encryption at rest and access permissions separately.

Examples

These excerpts show domain encryption properties only. Configure the engine version, nodes, storage and access policy for the actual workload.

Before

yaml
Resources:
  OpenSearchDomain:
    Type: AWS::OpenSearchService::Domain
    Properties:
      DomainName: my-domain
      EncryptionAtRestOptions:
        Enabled: true

Only encryption at rest is explicit. Check the actual node-to-node encryption configuration before assessing internal traffic protection.

After

yaml
Resources:
  OpenSearchDomain:
    Type: AWS::OpenSearchService::Domain
    Properties:
      DomainName: my-domain
      NodeToNodeEncryptionOptions:
        Enabled: true
      EncryptionAtRestOptions:
        Enabled: true

Node-to-node encryption is explicit alongside encryption at rest. HTTPS for client connections still needs separate configuration.

References