Elasticsearch
Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.
Overview
Elasticsearch is a distributed search and analytics engine. Clients use its HTTP REST API, normally on port 9200. Port 9300 carries node transport and remote-cluster traffic and is not a normal user application route.
Elasticsearch can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Elasticsearch. Elasticsearch remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose only the selected REST endpoint through the Pomerium route. Keep Elasticsearch security, transport TLS, index authorization, and service credentials active.
Example
Operators use a Pomerium HTTPS route for a private Elasticsearch REST endpoint. Elasticsearch keeps its own users, API keys, roles, index permissions, and TLS settings.
Considerations
- Do not route Elasticsearch node transport or remote-cluster traffic as normal user access.
- API clients, shippers, and automation need a compatible noninteractive authentication flow.
