IP Whitelisting
Every cluster defaults to open access (0.0.0.0/0 and ::/0 - any IPv4 or IPv6 address). To
restrict access to known networks, set the whitelist field(s) to a list of CIDR ranges (a single
IP works too, as a /32 or /128).
An empty result is the same as 0.0.0.0/0/::/0 being absent, not "deny everything" - always
include at least one range once you're setting this field at all. Double-check whatever address
range your own tooling connects from (a CI runner, a remote-write agent, an office network) is
covered before narrowing it, since a mismatched whitelist fails closed with no other signal
beyond connection timeouts/refusals at the network layer - it doesn't reach the credential check
at all.
- OpenSearch
- Prometheus
ClusterNest Managed OpenSearch Service has two independent whitelists, matching its two hostnames:
opensearch_whitelist- the OpenSearch API.opensearch_dashboards_whitelist- OpenSearch Dashboards.
- Console
- Terraform
- Raw API
Add IP ranges in the cluster's settings form, at create time or as an update to an existing cluster.
resource "clusternest_opensearch" "logs" {
# ...
opensearch_whitelist = ["203.0.113.0/24", "198.51.100.42/32"]
opensearch_dashboards_whitelist = ["203.0.113.0/24"]
}
See the resource reference for every field.
PUT replaces the whole cluster, not just the fields you sendAny field left out of the request body resets to its schema default, not its current value -
GET the cluster first, merge in the change, then PUT the merged result back.
curl "https://api.clusternest.com/cluster/opensearch/$CLUSTER_ID" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
| jq '.opensearch_whitelist = ["203.0.113.0/24", "198.51.100.42/32"]
| .opensearch_dashboards_whitelist = ["203.0.113.0/24"]' \
> cluster.json
curl -X PUT "https://api.clusternest.com/cluster/opensearch/$CLUSTER_ID" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
--data-binary @cluster.json
ClusterNest Managed Prometheus has one whitelist, covering the whole endpoint (query and push paths alike):
prometheus_whitelist
- Console
- Terraform
- Raw API
Add IP ranges in the cluster's settings form, at create time or as an update to an existing cluster.
resource "clusternest_prometheus" "metrics" {
# ...
prometheus_whitelist = ["203.0.113.0/24", "198.51.100.42/32"]
}
See the resource reference for every field.
PUT replaces the whole cluster, not just the fields you sendAny field left out of the request body resets to its schema default, not its current value -
GET the cluster first, merge in the change, then PUT the merged result back.
curl "https://api.clusternest.com/cluster/prometheus/$CLUSTER_ID" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
| jq '.prometheus_whitelist = ["203.0.113.0/24", "198.51.100.42/32"]' \
> cluster.json
curl -X PUT "https://api.clusternest.com/cluster/prometheus/$CLUSTER_ID" \
-H "Authorization: Bearer $ACCESS_TOKEN" \
-H "Content-Type: application/json" \
--data-binary @cluster.json