-
Notifications
You must be signed in to change notification settings - Fork 106
Network sec: rebrand and new cloud UX, IP filters in serverless #1785
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
shainaraskas
wants to merge
53
commits into
main
Choose a base branch
from
network-sec-core
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
53 commits
Select commit
Hold shift + click to select a range
fe63b4c
little start
shainaraskas 25d3e65
more stuff
shainaraskas accbfce
logic pages and ece pages cleanup
shainaraskas 3f704b2
cleanup
shainaraskas d8dac25
ip filtering procedures fixed
shainaraskas 43e9fd8
more
shainaraskas 94637e1
more
shainaraskas 8e2e5ea
more
shainaraskas 76e1375
more
shainaraskas a7e24f1
more
shainaraskas b41dc72
more
shainaraskas 56b2c93
aws done
shainaraskas a4a0bb4
more
shainaraskas 70214f1
gcp
shainaraskas ada20de
more
shainaraskas b1a8263
restore file to quiet ci
shainaraskas 422b7c7
more
shainaraskas a95efe9
checkpoint
shainaraskas 8cb424f
more
shainaraskas 4a6e170
more
shainaraskas f385170
azure
shainaraskas 128c3e4
private connection almost done
shainaraskas 695079b
cleanup
shainaraskas 1c268c6
more
shainaraskas 3e17a59
fix
shainaraskas d85e4e8
fixes
shainaraskas ed383b1
Update deploy-manage/_snippets/ecloud-security.md
shainaraskas 7b7f501
fix title
shainaraskas dc36e5b
title fix
shainaraskas 1512943
fixes
shainaraskas 4734dbe
vcp -> vcpe
shainaraskas bb6a5ca
fixes
shainaraskas 12cf541
fix better
shainaraskas a9f3446
fix curl tests
shainaraskas ca784e5
fix
shainaraskas 2190657
badge fixes
shainaraskas ff60297
fix API content
shainaraskas 5ede8be
Merge branch 'main' into network-sec-core
shainaraskas dc614fa
bad annotation
shainaraskas 0670ccb
Merge branch 'network-sec-core' of github.com:elastic/docs-content in…
shainaraskas 1062b40
fix VPC terminology, clarify optional steps for azure, add policy ben…
shainaraskas b069051
Apply suggestions from code review
shainaraskas cdc507f
feedback changes
shainaraskas d6c2619
Merge branch 'network-sec-core' of github.com:elastic/docs-content in…
shainaraskas a25b042
Apply suggestions from code review
shainaraskas f4be2a9
spelling
shainaraskas c42fd41
term cleanup, review protected resources process, icons
shainaraskas f8f42e2
language second pass
shainaraskas 7bd13af
cleanup
shainaraskas 9603d69
clarify
shainaraskas 5e5d60f
Merge branch 'main' into network-sec-core
shainaraskas e94ab4f
vpc filter
shainaraskas 23e197a
Merge branch 'network-sec-core' of github.com:elastic/docs-content in…
shainaraskas File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,3 +1,5 @@ | ||
1. Go to the deployment. | ||
2. On the **Security** page, in the **Traffic filters** section, select **Apply filter**. | ||
3. Choose the filter you want to apply and select **Apply filter**. | ||
1. Find your deployment on the home page or on the **Hosted deployments** page, then select **Manage** to access its settings menus. | ||
|
||
On the **Hosted deployments** page, you can narrow your deployments by name, ID, or choose from several other filters. To customize your view, use a combination of filters, or change the format from a grid to a list. | ||
2. On the **Security** page, under **Network security**, select **Apply policies** > **{{policy-type}}**. | ||
3. Choose the policy you want to apply and select **Apply**. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1 @@ | ||
1. Log in to the [{{ecloud}} Console](https://cloud.elastic.co?page=docs&placement=docs-body). | ||
2. Find your deployment on the home page and select **Manage**, or select your deployment from the **Hosted deployments** page. | ||
3. From the lower navigation menu, select **Traffic filters**. | ||
4. Select **Create filter**. | ||
% no longer used |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,8 +1 @@ | ||
If you need to remove a rule set, you must first remove any associations with deployments. | ||
|
||
To delete a rule set with all its rules: | ||
|
||
1. [Remove any deployment associations](/deploy-manage/security/gcp-private-service-connect-traffic-filters.md#remove-filter-deployment). | ||
2. From the lower navigation menu, select **Traffic filters**. | ||
3. Find the rule set you want to edit. | ||
4. Select the **Remove** icon. The icon is inactive if there are deployments assigned to the rule set. | ||
% no longer used |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,3 +1,3 @@ | ||
:::{tip} | ||
Elastic recommends that you use Kubernetes network policies over IP traffic filters for {{eck}}. This is because, in containerized environments like Kubernetes, IP addresses are usually dynamic, making network policies a more robust option. | ||
Elastic recommends that you use Kubernetes network policies over IP filters for {{eck}}. This is because, in containerized environments like Kubernetes, IP addresses are usually dynamic, making network policies a more robust option. | ||
::: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,3 +1 @@ | ||
1. From the lower navigation menu, select **Traffic filters**. | ||
2. Find the rule set you want to edit. | ||
3. Select the **Edit** icon. | ||
% no longer used |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
1. Log in to the [{{ecloud}} Console](https://cloud.elastic.co?page=docs&placement=docs-body). | ||
|
||
2. Under **Hosted deployments**, find your deployment. | ||
|
||
:::{tip} | ||
If you have many deployments, you can instead go to the **Hosted deployments** ({{ech}}) page. On that page, you can narrow your deployments by name, ID, or choose from several other filters. | ||
::: | ||
|
||
3. Select **Manage**. | ||
4. In the deployment overview, under **Applications**, find the application that you want to test. | ||
5. Click **Copy endpoint**. The value looks something like the following: | ||
|
||
```text subs=true | ||
https://my-deployment-d53192.es.{{example-default-dn}} | ||
``` | ||
|
||
In this endpoint, `my-deployment-d53192` is an alias, and `es` is the product you want to access within your deployment. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
1. Log in to the [{{ecloud}} Console](https://cloud.elastic.co?page=docs&placement=docs-body). | ||
2. From any deployment or project on the home page, select **Manage**. | ||
3. From the left navigation menu, select **Access and security** > **Network security**. |
15 changes: 15 additions & 0 deletions
15
deploy-manage/security/_snippets/private-connection-fleet.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
If you are using {{service-name}} together with Fleet, and enrolling the Elastic Agent with a PrivateLink URL, you need to configure Fleet Server to use and propagate the {{service-name}} URL by updating the **Fleet Server hosts** field in the **Fleet settings** section of {{kib}}. Otherwise, Elastic Agent will reset to use a default address instead of the {{service-name}} URL. | ||
|
||
The URL needs to follow this pattern: | ||
|
||
```text | ||
https://{{fleet_component_ID_or_deployment_alias}}.fleet.{{private_hosted_zone_domain_name}}:443` | ||
``` | ||
|
||
Similarly, the {{es}} host needs to be updated to propagate the PrivateLink URL. The {{es}} URL needs to follow this pattern: | ||
|
||
```text | ||
https://elasticsearch_cluster_ID_or_deployment_alias}}.es.{{private_hosted_zone_domain_name}}:443 | ||
``` | ||
|
||
The settings `xpack.fleet.agents.fleet_server.hosts` and `xpack.fleet.outputs` that are needed to enable this configuration in {{kib}} are not available in the {{kib}} settings in {{ecloud}}. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
Use the following URL structure. This URL is built from endpoint information retrieved from your Elastic deployment and the private hosted zone domain name that you registered. | ||
|
||
``` | ||
https://{{alias}}.{{product}}.{{private_hosted_zone_domain_name}} | ||
``` | ||
|
||
For example: | ||
|
||
```text subs=true | ||
https://my-deployment-d53192.es.{{example-phz-dn}} | ||
``` | ||
|
||
|
||
:::{tip} | ||
You can use either 443 or 9243 as a port. | ||
|
||
You can also connect to the cluster using the {{es}} cluster ID, for example, https://6b111580caaa4a9e84b18ec7c600155e.{{example-phz-dn}} | ||
::: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1 @@ | ||
If you want to remove any traffic restrictions from a deployment or delete a rule set, you’ll need to remove any rule set associations first. To remove an association through the UI: | ||
|
||
1. Go to the deployment. | ||
2. On the **Security** page, in the **Traffic filters** section, select **Remove**. | ||
% no longer used |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.