Skip to main content

IP Whitelisting

Every cluster defaults to open access (0.0.0.0/0 and ::/0 - any IPv4 or IPv6 address). To restrict access to known networks, set the whitelist field(s) to a list of CIDR ranges (a single IP works too, as a /32 or /128).

An empty result is the same as 0.0.0.0/0/::/0 being absent, not "deny everything" - always include at least one range once you're setting this field at all. Double-check whatever address range your own tooling connects from (a CI runner, a remote-write agent, an office network) is covered before narrowing it, since a mismatched whitelist fails closed with no other signal beyond connection timeouts/refusals at the network layer - it doesn't reach the credential check at all.

ClusterNest Managed OpenSearch Service has two independent whitelists, matching its two hostnames:

  • opensearch_whitelist - the OpenSearch API.
  • opensearch_dashboards_whitelist - OpenSearch Dashboards.

Add IP ranges in the cluster's settings form, at create time or as an update to an existing cluster.