Skip to content
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions deploy-manage/_snippets/ecloud-security.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{{ecloud}} has built-in security. For example, HTTPS communications between {{ecloud}} and the internet, as well as inter-node communications, are secured automatically, and cluster data is encrypted at rest.

In {{ech}}, you can augment these security features in the following ways:
* Configure [traffic filtering](/deploy-manage/security/traffic-filtering.md) to prevent unauthorized access to your deployments.
* Encrypt your deployment with a [customer-managed encryption key](/deploy-manage/security/encrypt-deployment-with-customer-managed-encryption-key.md).
* [Secure your settings](/deploy-manage/security/secure-settings.md) using {{es}} and {{kib}} keystores.
* Use the list of [{{ecloud}} static IPs](/deploy-manage/security/elastic-cloud-static-ips.md) to allow or restrict communications in your infrastructure.

{{ech}} doesn't support custom SSL certificates, which means that a custom CNAME for an {{ech}} endpoint such as *mycluster.mycompanyname.com* also is not supported.

Refer to [{{ecloud}} security](https://www.elastic.co/cloud/security) for more details about Elastic security and privacy programs.
68 changes: 14 additions & 54 deletions deploy-manage/deploy/elastic-cloud/cloud-hosted.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,47 +11,6 @@

# {{ech}}

% What needs to be done: Refine

% GitHub issue: https://github.com/elastic/docs-projects/issues/338

% Use migrated content from existing pages that map to this page:

% - [ ] ./raw-migrated-files/cloud/cloud/ec-getting-started.md
% - [ ] ./raw-migrated-files/cloud/cloud/ec-prepare-production.md
% Notes: link roundup is good but the plan for prod content is not needed here
% - [ ] ./raw-migrated-files/cloud/cloud/ec-faq-getting-started.md
% Notes: extract what we can from faq
% - [ ] ./raw-migrated-files/cloud/cloud/ec-about.md
% Notes: redirect only
% - [ ] ./raw-migrated-files/cloud/cloud-heroku/ech-configure.md

% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):

$$$faq-aws-difference$$$

$$$faq-aws$$$

$$$faq-config$$$

$$$faq-elastic$$$

$$$faq-full-stack$$$

$$$faq-limit$$$

$$$faq-subscriptions$$$

$$$faq-trial$$$

$$$faq-vs-aws$$$

$$$faq-what$$$

$$$faq-where$$$

$$$faq-x-pack$$$

**{{ech}} is the {{stack}}, managed through {{ecloud}} deployments.**

It is also formerly known as {{es}} Service.
Expand All @@ -64,7 +23,6 @@
{{ech}} is one of the two deployment options available on {{ecloud}}. [Depending on your needs](../elastic-cloud.md), you can also run [{{serverless-full}} projects](/deploy-manage/deploy/elastic-cloud/serverless.md).
::::


**Hardware profiles to optimize deployments for your usage.**

You can optimize the configuration and performance of a deployment by selecting a **hardware profile** that matches your usage.
Expand All @@ -91,7 +49,7 @@
Of course, you can choose to follow your own path and use Elastic components available in your deployment to ingest, visualize, and analyze your data independently from solutions.


## How to operate {{ech}}? [ec_how_to_operate_elasticsearch_service]
## How to operate {{ech}} [ec_how_to_operate_elasticsearch_service]

**Where to start?**

Expand All @@ -110,7 +68,13 @@

**Secure your environment**

Control which users and services can access your deployments by [securing your environment](/deploy-manage/security/secure-your-cluster-deployment.md). [Add authentication mechanisms](/deploy-manage/users-roles.md), configure [traffic filtering](/deploy-manage/security/traffic-filtering.md) for private link, encrypt your deployment data and snapshots at rest [with your own key](/deploy-manage/security/encrypt-deployment-with-customer-managed-encryption-key.md), [manage trust](/deploy-manage/remote-clusters.md) with {{es}} clusters from other environments, and more.
:::{include} /deploy-manage/_snippets/ecloud-security.md
:::

Refer to [](/deploy-manage/security.md) for more details.

:::{include} /deploy-manage/security/_snippets/complete-security.md
:::

**Monitor your deployments and keep them healthy**

Expand All @@ -120,13 +84,13 @@

Find more information about {{ech}} on the following pages:

* [Subscription Levels](/deploy-manage/license.md)
* [Version Policy](/deploy-manage/deploy/elastic-cloud/available-stack-versions.md)
* [{{ech}} Hardware](cloud://reference/cloud-hosted/hardware.md)
* [{{ech}} Regions](cloud://reference/cloud-hosted/regions.md)
* [Service Status](/deploy-manage/cloud-organization/service-status.md)
* [](/deploy-manage/license.md)
* [](/deploy-manage/deploy/elastic-cloud/available-stack-versions.md)
* [{{ech}} hardware](cloud://reference/cloud-hosted/hardware.md)
* [{{ech}} regions](cloud://reference/cloud-hosted/regions.md)
* [](/deploy-manage/cloud-organization/service-status.md)
* [Getting help](/troubleshoot/index.md)
* [Restrictions and known problems](/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md)
* [](/deploy-manage/deploy/elastic-cloud/restrictions-known-problems.md)

:::{dropdown} {{ech}} FAQ

Expand All @@ -144,7 +108,7 @@
* [What is the difference between {{ech}} and the Amazon {{es}} Service?](/deploy-manage/deploy/elastic-cloud/cloud-hosted.md#faq-vs-aws)
* [Can I use {{ech}} on platforms other than AWS?](/deploy-manage/deploy/elastic-cloud/cloud-hosted.md#faq-aws)
* [Do you offer Elastic’s commercial products?](/deploy-manage/deploy/elastic-cloud/cloud-hosted.md#faq-elastic)
* [Is my {{es}} cluster protected by X-Pack?](/deploy-manage/deploy/elastic-cloud/cloud-hosted.md#faq-x-pack)

Check failure on line 111 in deploy-manage/deploy/elastic-cloud/cloud-hosted.md

View workflow job for this annotation

GitHub Actions / preview / build

`faq-x-pack` does not exist in deploy-manage/deploy/elastic-cloud/cloud-hosted.md.
* [Is there a limit on the number of documents or indexes I can have in my cluster?](/deploy-manage/deploy/elastic-cloud/cloud-hosted.md#faq-limit)

$$$faq-what$$$**What is {{ech}}?**
Expand Down Expand Up @@ -191,10 +155,6 @@

[Contact us](https://www.elastic.co/cloud/contact) to learn more.


$$$faq-x-pack$$$**Is my {{es}} cluster protected by X-Pack?**
: Yes, X-Pack security features offer the full power to protect your {{ech}} deployment with basic authentication and role-based access control.

$$$faq-limit$$$**Is there a limit on the number of documents or indexes I can have in my cluster?**
: No. We do not enforce any artificial limit on the number of indexes or documents you can store in your cluster.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@
applies_to:
deployment:
ess: ga
serverless: ga
mapped_pages:
- https://www.elastic.co/guide/en/cloud/current/ec-restrictions.html
---
Expand Down
13 changes: 2 additions & 11 deletions deploy-manage/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,22 +32,13 @@ deployment:
serverless: all
```

{{ecloud}} has built-in security. For example, HTTPS communications between {{ecloud}} and the internet, as well as inter-node communications, are secured automatically, and cluster data is encrypted at rest.

In {{ech}}, you can augment these Security features in the following ways:
* Configure [traffic filtering](/deploy-manage/security/traffic-filtering.md) to prevent unauthorized access to your deployments.
* Encrypt your deployment with a [customer-managed encryption key](/deploy-manage/security/encrypt-deployment-with-customer-managed-encryption-key.md).
* [Secure your settings](/deploy-manage/security/secure-settings.md) using {{es}} and {{kib}} keystores.
* Use the list of [{{ecloud}} static IPs](/deploy-manage/security/elastic-cloud-static-ips.md) to allow or restrict communications in your infrastructure.

{{ech}} doesn't support custom SSL certificates, which means that a custom CNAME for an {{ech}} endpoint such as *mycluster.mycompanyname.com* also is not supported.
:::{include} /deploy-manage/_snippets/ecloud-security.md
:::

::::{note}
Serverless projects are fully managed and secured by Elastic, and do not have any configurable Security features at the project level.
::::

Refer to [{{ecloud}} security](https://www.elastic.co/cloud/security) for more details about Elastic security and privacy programs.

## Securing your orchestrator
```yaml {applies_to}
deployment:
Expand Down
2 changes: 1 addition & 1 deletion deploy-manage/toc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,8 +59,8 @@ toc:
- file: deploy/elastic-cloud/change-hardware.md
- file: deploy/elastic-cloud/manage-deployments-using-elastic-cloud-api.md
- file: deploy/elastic-cloud/keep-track-of-deployment-activity.md
- file: deploy/elastic-cloud/restrictions-known-problems.md
- file: deploy/elastic-cloud/tools-apis.md
- file: deploy/elastic-cloud/restrictions-known-problems.md
- file: deploy/cloud-enterprise.md
children:
- file: deploy/cloud-enterprise/ece-architecture.md
Expand Down
Loading