Skip to main content
Version: 0.5.4

Elasticsearch on Aruba Cloud

Deploy Elasticsearch 8.x — the leading open-source distributed search and analytics engine — on Aruba Cloud using Terraform and cloud-init. Installed from the official Elastic apt repository with x-pack security enabled and the elastic superuser password configured at bootstrap time.

Provider version: arubacloud/arubacloud ~> 0.5 | Terraform: ≥ 1.9


Introduction​

Elasticsearch is the core of the Elastic Stack (ELK/ELK+APM), providing full-text search, log analytics, and real-time data exploration at scale. This example provisions a single-node Elasticsearch instance with:

  • Elasticsearch 8.x installed from the official Elastic apt repository
  • x-pack security enabled — all API requests require authentication
  • HTTP TLS disabled for simplicity (terminate TLS at a reverse proxy for production)
  • elastic superuser password set at bootstrap time — no manual post-install steps
  • vm.max_map_count=262144 kernel tuning applied persistently
  • REST API on port 9200, restricted to admin_cidr

OpenSearch note: For new open-source deployments where Elastic's SSPL licence is a concern, consider OpenSearch — the community-driven fork maintained by AWS. Wazuh (in this repository) includes an embedded OpenSearch instance for reference.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectes-prodProject container
arubacloud_vpces-prod-vpcVirtual Private Cloud
arubacloud_subnetes-prod-subnetBasic subnet
arubacloud_securitygroupes-prod-vm-sgSecurity group
arubacloud_securityrulees-prod-vm-sshSSH ingress
arubacloud_securityrulees-prod-vm-apiREST API ingress TCP 9200
arubacloud_elasticipes-prod-vm-eipVM public IP
arubacloud_blockstoragees-prod-boot100 GB boot disk (Performance)
arubacloud_keypaires-prod-keypairSSH public key
arubacloud_cloudserveres-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO4A8 — 4 vCPU / 8 GB~€35
Boot disk100 GB Performance~€15
Elastic IP—~€3
Total~€53/mo

For production workloads, upgrade to CSO8A16 (8 vCPU / 16 GB, ~€95/mo).


Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 0.5
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
elastic_passwordPassword for the elastic superuser (min 6 chars)

Optional​

VariableDefaultDescription
app_name"es"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO4A8"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb100Boot disk size in GB (min 50 GB)
ssh_cidr"0.0.0.0/0"CIDR for SSH
admin_cidr"0.0.0.0/0"CIDR for REST API port 9200 — always restrict
cluster_name"elasticsearch"Elasticsearch cluster name

Outputs​

OutputDescription
elasticsearch_urlElasticsearch REST API URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM
health_checkcurl command to verify the cluster is healthy

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/elasticsearch

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set the password and restrict API access to your application servers:

elastic_password = "your-strong-password"
admin_cidr = "10.0.0.0/8" # your app server CIDR
ssh_cidr = "203.0.113.42/32"

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 3–5 minutes.

4. Verify​

curl -u elastic:<your-password> \
"$(terraform output -raw elasticsearch_url)/_cluster/health?pretty"

Expected output:

{
"cluster_name" : "elasticsearch",
"status" : "green",
"number_of_nodes" : 1,
...
}

Connecting Kibana​

To visualise and query data, deploy Kibana separately and point it at this Elasticsearch instance:

# kibana.yml
elasticsearch.hosts: ["http://<es-ip>:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.password: "<generated-kibana-system-password>"

Create the kibana_system user password from the Elasticsearch VM:

ssh ubuntu@$(terraform output -raw vm_public_ip)
sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password \
-u kibana_system --batch

Security Recommendations​

  1. Always restrict admin_cidr. Elasticsearch has no rate limiting on authentication — open port 9200 to 0.0.0.0/0 exposes your data to credential-stuffing attacks.

  2. Enable HTTP TLS for production. This example disables HTTP TLS for simplicity. For production, terminate TLS at NGINX or Caddy (in this repository), or enable Elasticsearch's built-in TLS using xpack.security.http.ssl.enabled: true with a certificate.

  3. Use dedicated roles. Do not use the elastic superuser for application connections. Create a least-privilege role:

    curl -u elastic:<password> -X POST \
    "http://<ip>:9200/_security/role/app_role" \
    -H "Content-Type: application/json" \
    -d '{"indices":[{"names":["app-*"],"privileges":["read","write","create_index"]}]}'

Troubleshooting​

Elasticsearch not starting​

sudo systemctl status elasticsearch
sudo journalctl -u elasticsearch -n 50
# Common cause: insufficient vm.max_map_count
cat /proc/sys/vm/max_map_count # should be 262144

Password reset failed​

The password reset tool requires the node to be running. Check service status first:

sudo systemctl status elasticsearch
sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password \
-u elastic -p "new-password" --batch

References​