Review HTTPS enforcement for Elasticsearch

Require HTTPS at the domain endpoint to protect data in transit.

Description

Without HTTPS enforcement at an Elasticsearch domain endpoint, clients may connect over plaintext HTTP. Unencrypted search requests and responses can expose sensitive information to an attacker with access to the network path.

Potential impact

  • Plaintext requests and responses can expose search data or authentication information.
  • Data in transit can be vulnerable to tampering.

Remediation

Set domainEndpointOptions.enforceHttps to true. Maintain a supported TLS security policy and client certificate verification, and confirm that HTTP connections are rejected.

Examples

These excerpts compare only the HTTPS setting for a Pulumi AWS Elasticsearch domain. Configure the remaining domain settings separately.

Before

yaml
resources:
  my-elasticsearch-domain:
    type: aws:elasticsearch:Domain
    properties:
      domainEndpointOptions:
        enforceHttps: false
        tlsSecurityPolicy: Policy-Min-TLS-1-2-2019-07

After

yaml
resources:
  my-elasticsearch-domain:
    type: aws:elasticsearch:Domain
    properties:
      domainEndpointOptions:
        enforceHttps: true
        tlsSecurityPolicy: Policy-Min-TLS-1-2-2019-07

The after example requires HTTPS. Manage encryption at rest, node-to-node encryption and access permissions separately.

References