[DO NOT MERGE] Azure: multiple private link case #2840
Closed
+16
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
this issue indicates that our DNS instructions make a bad assumption about creating a DNS A record for the private endpoint (that everyone will want to use a wildcard because they don't need to maintain a bunch of private endpoints in this zone)
Updates the azure private connectivity doc, taking the information in this issue at face value
made a couple of logical leaps I am hoping can be confirmed by dev:
does the user need to create a DNS A record for each cluster ID they will access over private link? I am assuming yes
is this explanation clear enough? would you word this a different way (i.e. what is the appropriate condition to use a wildcard)?
Wonder if this change also needs to be made to the GCP and AWS instructions, which also use wildcards
👀 link to the edited procedure: https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/2840/deploy-manage/security/private-connectivity-azure#ec-private-link-azure-dns
before
after