How to Manage ECK Certificates with Vault and cert-manager

· Original article ↗

Summary

Elastic’s guide shows how to use Vault and cert-manager to issue and renew enterprise PKI certificates for Elasticsearch on Kubernetes, keeping the CA private key outside the cluster and delivering transport certificates directly to pods.

Key points

  • ECK generates self-signed certificates by default; enterprise PKI policies may require centrally controlled certificate issuance and trust.
  • Vault stores the intermediate CA and signs certificates, keeping its private key out of Kubernetes Secrets.
  • cert-manager requests certificates from Vault and automates their renewal and rotation.
  • The example HTTP certificates are valid for seven days and renew one hour before expiry.
  • The cert-manager CSI driver delivers transport certificates directly into Elasticsearch pods, avoiding storage of their private keys in Kubernetes Secrets.
  • Vault Kubernetes authentication and a narrowly scoped role and policy authorize certificate requests from a dedicated ServiceAccount.
  • The demonstrated configuration covers Elasticsearch and can be extended to other Elastic Stack components, such as Kibana.

Article Details

Defense Focus
Automate enterprise-PKI certificate issuance and renewal for ECK while keeping CA private keys out of the Kubernetes cluster.
Detection Methods
  • Check that the Elasticsearch HTTP Certificate resource reports READY=True and that its Kubernetes Secret exists.
  • Inspect the issued certificate’s subject, issuer, validity dates, and subject alternative names.
  • Inspect the certificate presented by the Elasticsearch HTTP endpoint and confirm that it matches the expected service name and Vault-managed issuer.
  • Check Elasticsearch cluster health after deployment.
Data Sources
  • Kubernetes Certificate resource status
  • Kubernetes Secret containing the HTTP certificate
  • Issued certificate fields and Elasticsearch HTTP TLS handshake output
  • Kubernetes Elasticsearch resource status
Defensive Actions
  • Keep the Root CA private key outside Vault and the Intermediate CA private key in Vault, rather than storing a CA private key as a Kubernetes Secret.
  • Restrict Vault certificate issuance to the designated ServiceAccount, namespace, signing role, and least-privilege policy.
  • Configure automatic HTTP certificate renewal before expiry and deliver per-pod transport certificates through the CSI driver without persisting their private keys as Kubernetes Secrets.
  • Provide the custom CA trust bundle to ECK and verify the deployed certificates’ identity, issuer, and validity.

Vendors

Products

cert-managerElasticsearch to HashiCorp Vault, which holds the intermediate CA and signs every certificate, and to cert-manager, which requests and renews them. In the example, HTTP certificates last seven days and renew an hourcert-manager CSI driverAutomatic via the cert-manager CSI driverElastic Cloud on Kubernetes (ECK)You can run Elastic Cloud on Kubernetes (ECK) on your own enterprise public key infrastructure (PKI) without your certificate authority’s (CA's) private key ever entering the Kubernetes cluster. By default, ECKElastic StackThe ECK operator generates self-signed certificates for various components of the Elastic Stack. Below is a high-level overview of the different types of self-signed certificates generated by ECK for Elasticsearch andElasticsearchGet hands-on with Elasticsearch: Dive into our sample notebooks in the Elasticsearch Labs repo, start a free cloud trial, or try Elastic on your local machine now.HashiCorp Vaultfor Elasticsearch and Kibana. This post hands ECK certificate management for Elasticsearch to HashiCorp Vault, which holds the intermediate CA and signs every certificate, and to cert-manager, which requests andKibanaentering the Kubernetes cluster. By default, ECK generates self-signed certificates for Elasticsearch and Kibana. This post hands ECK certificate management for Elasticsearch to HashiCorp Vault, which holds theKubernetesYou can run Elastic Cloud on Kubernetes (ECK) on your own enterprise public key infrastructure (PKI) without your certificate authority’s (CA's) private key ever entering the Kubernetes cluster. By default, ECKtrust-managerSync the CA automatically with trust-manager

Tools

Related Articles