Elasticsearch domain without node-to-node encryption

Encrypt communication between nodes within an Elasticsearch domain.

Description

Search clusters exchange index data, logs and documents across nodes. Without node-to-node encryption, this internal communication can travel in plaintext.

Node-to-node TLS protects communication inside the domain. Client HTTPS connections, encryption at rest and access policies require separate configuration.

Potential impact

If the internal communication path is compromised, unencrypted data could be exposed. The domain may also fail requirements to encrypt communication between internal services.

Remediation

  • Set node_to_node_encryption { enabled = true }.
  • New Elasticsearch domains require version 6.0 or later; enabling this on an existing domain requires 6.7 or later. Check version compatibility and the planned change. Once enabled, the setting cannot be disabled on the same domain.
  • Review HTTPS enforcement, encryption at rest and access permissions as well.

Examples

Set var.elasticsearch_version to a version that supports node-to-node encryption and the chosen instance type. These are partial domain configurations.

Before

hcl
resource "aws_elasticsearch_domain" "example" {
  domain_name           = "example"
  elasticsearch_version = var.elasticsearch_version

  cluster_config {
    instance_type = "r4.large.elasticsearch"
  }
}

This does not enable node-to-node encryption.

After

hcl
resource "aws_elasticsearch_domain" "example" {
  domain_name           = "example"
  elasticsearch_version = var.elasticsearch_version

  cluster_config {
    instance_type = "r4.large.elasticsearch"
  }

  node_to_node_encryption {
    enabled = true
  }
}

This encrypts internal node communication. The setting alone neither blocks client HTTP connections nor encrypts stored data.

References