OpenSearch on Aruba Cloud
Deploy OpenSearch 2.x — the community-driven open-source search and analytics suite — on Aruba Cloud using Terraform and cloud-init. Deployed via the official Docker image with TLS-secured REST API and the admin superuser password configured at bootstrap time.
Provider version: arubacloud/arubacloud
~> 1.0| Terraform: ≥ 1.9
Introduction
OpenSearch is the Apache-2.0-licensed fork of Elasticsearch maintained by AWS and the open-source community. It provides full-text search, log analytics, and real-time data exploration at scale — with no SSPL licensing concerns. This example provisions a single-node OpenSearch instance with:
- OpenSearch 2.x via the official Docker image
- TLS enabled on the REST API (HTTPS port 9200) — all API requests require credentials
adminsuperuser password set at bootstrap timevm.max_map_count=262144kernel tuning applied persistently- REST API on HTTPS port 9200, restricted to
admin_cidr
Elasticsearch note: If Elastic's SSPL licence is not a concern for your use case, see the Elasticsearch example in this repository.
Architecture Overview
Infrastructure Created
| Resource | Name pattern | Description |
|---|---|---|
arubacloud_project | os-prod | Project container |
arubacloud_vpc | os-prod-vpc | Virtual Private Cloud |
arubacloud_subnet | os-prod-subnet | Basic subnet |
arubacloud_securitygroup | os-prod-vm-sg | Security group |
arubacloud_securityrule | os-prod-vm-ssh | SSH ingress |
arubacloud_securityrule | os-prod-vm-api | REST API ingress TCP 9200 |
arubacloud_elasticip | os-prod-vm-eip | VM public IP |
arubacloud_blockstorage | os-prod-boot | 100 GB boot disk (Performance) |
arubacloud_keypair | os-prod-keypair | SSH public key |
arubacloud_cloudserver | os-prod-vm | CloudServer VM |
Estimated Monthly Cost
| Resource | Spec | Est. cost/mo |
|---|---|---|
| CloudServer VM | CSO8A16 — 8 vCPU / 16 GB | ~€55 |
| Boot disk | 100 GB Performance | ~€15 |
| Elastic IP | — | ~€3 |
| Total | ~€73/mo |
Requirements
- Terraform ≥ 1.9
- ArubaCloud Terraform Provider
~> 1.0 - An ArubaCloud account with OAuth2 API credentials
- An SSH key pair
Variables
Required
| Variable | Description |
|---|---|
arubacloud_client_id | ArubaCloud OAuth2 client ID |
arubacloud_client_secret | ArubaCloud OAuth2 client secret |
ssh_public_key | SSH public key content |
admin_password | Password for the admin user (8+ chars, uppercase + lowercase + digit + special) |
Optional
| Variable | Default | Description |
|---|---|---|
app_name | "os" | Short name used in all resource names |
environment | "prod" | Environment label |
location | "ITBG-Bergamo" | ArubaCloud region |
zone | "ITBG-1" | Availability zone |
billing_period | "Hour" | "Hour" or "Month" |
vm_flavor | "CSO8A16" | CloudServer flavor |
vm_image | "LU22-001" | Boot disk image (Ubuntu 22.04 LTS) |
vm_disk_size_gb | 100 | Boot disk size in GB (min 50 GB) |
ssh_cidr | "0.0.0.0/0" | CIDR for SSH |
admin_cidr | "0.0.0.0/0" | CIDR for REST API port 9200 — always restrict |
cluster_name | "opensearch" | OpenSearch cluster name |
opensearch_version | "2" | OpenSearch Docker image tag |