Skip to content

Conversation

@kunisen kunisen requested a review from a team as a code owner October 17, 2025 06:18
@kunisen
Copy link
Contributor Author

kunisen commented Oct 17, 2025

Hi @eedugon @AlexP-Elastic @dtuck9 @maggieghamry

I requested your kind review from doc, dev and support perspective.
Please refer to this comment about the change details and thank you!

@kunisen kunisen self-assigned this Oct 17, 2025
@kunisen kunisen added documentation Improvements or additions to documentation supportability ability enable self-service or support of product Team:Admin Issues owned by the Admin Docs Team labels Oct 17, 2025
Copy link
Contributor

@eedugon eedugon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awesome improvements in my opinion.
Really worthy.

In some way I think we shouldn't even mention (or support) the possibility of certificates with static SAN entries, but I'm ok with this text.

Copy link

@AlexP-Elastic AlexP-Elastic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks fine to me, had a few minor comments but nothing blocking


For this reason, using a wildcard DNS certificate is recommended over a certificate with static SAN entries, as it provides a more scalable, performant, and operationally safe solution.

### Operational cost perspective

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we really need 3 sections here to expand on the sentence above?

Who are you trying to convince - pretty sure everyone who is allowed to use a wildcard cert will do so :)

I think I'd probably just add

a static SAN certificate requires reissuing the certificate whenever a new deployment is created and updating the SAN list for all clusters and applications (Elasticsearch, Kibana, etc.), which increases operational overhead.

and

We suggest configuring your wildcard DNS certificate as a subdomain (e.g., *.ece.mycompany.com). Doing so significantly reduces security risks associated with certificate misconfigurations.

to the section above

I don't feel super strongly about this though

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @AlexP-Elastic!

The request comes from past cases from customers and the discussion with @eedugon that we felt it doesn't harm to make it super clear that "why in specific do we highly recommend wildcard DNS certs". We had multiple customers / users asking details about security risk, operational cost related questions, and Edu shared the insights about the performance considerations too, which eventually and logically it split into 3 sections.

I will leave this to @eedugon and @maggieghamry to make the decision :) If they could help confirm that the simplified content is easily and visibly understandable enough for customers, then I am perfectly fine with we remove the headings and describe the context in one paragraph.

@eedugon @maggieghamry please help provide your kind insights on this 🙏 and thanks again!

@eedugon
Copy link
Contributor

eedugon commented Oct 18, 2025

@kunisen , I think there's a middle point, as in some way we don't need to highlight all this that much with a big H2 section and 3 x H3.

On Monday I will quickly prepare a proposal through a suggestion so you can take a look and evaluate. The suggestion will:

  • Change the name of Wildcard DNS certificate vs static SAN certificate H2 section and convert it to H3.
  • Convert the final 3 sections Operational cost perspective, Performance perspective, and Security perspective to bullets with a bit shorter explanations on each, but keeping the esence.

I agree the 3 big sub-sections at the end don't add value and it makes the doc scope to not be totally clear.

@kunisen
Copy link
Contributor Author

kunisen commented Oct 27, 2025

Hi @eedugon may I trouble you to take a look at this when you have time please? thank you! 🙏

Copy link

@dtuck9 dtuck9 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you for doing this

Copy link
Contributor

@eedugon eedugon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, I've suggested a change in the comparison between wildcard certs and static SAN entries certs.

@kunisen kunisen merged commit b928643 into main Oct 28, 2025
7 checks passed
@kunisen kunisen deleted the kunisen-docpr-stl-1660 branch October 28, 2025 08:29
naemono pushed a commit to naemono/docs-content that referenced this pull request Oct 28, 2025
## Description 

This doc PR is to address [this internal
ticket](elastic/support-tech-lead#1660).
Change detail: [this
comment](elastic/support-tech-lead#1660 (comment)).


## Preview before PR merge

-
[deploy-manage/deploy/cloud-enterprise/change-endpoint-urls.md](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3513/deploy-manage/deploy/cloud-enterprise/change-endpoint-urls)
-
[deploy-manage/deploy/cloud-enterprise/ece-wildcard-dns.md](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3513/deploy-manage/deploy/cloud-enterprise/ece-wildcard-dns)
-
[deploy-manage/deploy/cloud-enterprise/enable-custom-endpoint-aliases.md](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3513/deploy-manage/deploy/cloud-enterprise/enable-custom-endpoint-aliases)
-
[deploy-manage/security/secure-your-elastic-cloud-enterprise-installation/manage-security-certificates.md](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/3513/deploy-manage/security/secure-your-elastic-cloud-enterprise-installation/manage-security-certificates)

## Preview after PR merge

*
https://www.elastic.co/docs/deploy-manage/deploy/cloud-enterprise/ece-wildcard-dns
*
https://www.elastic.co/docs/deploy-manage/deploy/cloud-enterprise/change-endpoint-urls
*
https://www.elastic.co/docs/deploy-manage/deploy/cloud-enterprise/enable-custom-endpoint-aliases
*
https://www.elastic.co/docs/deploy-manage/security/secure-your-elastic-cloud-enterprise-installation/manage-security-certificates

---------

Co-authored-by: Edu González de la Herrán <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation supportability ability enable self-service or support of product Team:Admin Issues owned by the Admin Docs Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants