FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Infrastructure·High

Elastic on Kubernetes Gets a Major Security Upgrade

Elastic on Kubernetes Gets a Major Security Upgrade
Kubernetes logo
Kubernetes news →

TL;DR: The latest Elastic Cloud on Kubernetes (ECK) update adds mutual TLS encryption across the entire stack. This boosts security and simplifies compliance for teams running Elasticsearch on Kubernetes.

By Ashish Kale·just now·3 min read·updated 16m ago
Source

Key facts

Category
Infrastructure
Impact
High
Published
just now
Source
Elastic Blog

Full summary

The latest Elastic on Kubernetes update adds mutual TLS encryption, dynamic namespace management, and safer maintenance windows for easier operations.

Elastic has released version 3.5 of Elastic Cloud on Kubernetes (ECK), its official operator for deploying and managing the Elastic Stack on Kubernetes. According to the announcement on the Elastic Blog, this update introduces several significant features aimed at improving security, operational flexibility, and efficiency. The headline changes include the implementation of mutual TLS (mTLS) for communication between all stack components, dynamic namespace management using label selectors, and a new pause orchestration feature for safer maintenance windows. Additionally, the release brings simplified resource specifications and a reduced memory footprint for the operator itself, making it lighter and easier to manage. These enhancements collectively represent a major step forward in maturing how organizations run data-intensive applications like Elasticsearch within complex, containerized environments, with a clear focus on automating and securing Day 2 operations.

The new features in ECK 3.5 introduce more sophisticated control mechanisms. Mutual TLS, for instance, goes beyond standard encryption for external traffic by requiring every component within the Elastic Stack—from individual Elasticsearch nodes to Kibana and APM servers—to present a valid certificate to communicate with any other component. This creates a zero-trust environment inside the cluster, preventing unauthorized services from interacting with the data layer. The dynamic namespace management feature moves away from static configuration. Administrators can now simply add a specific label to any Kubernetes namespace, and the ECK operator will automatically discover and begin managing Elastic resources within it. Removing the label causes the operator to cease management, providing a highly flexible, API-driven workflow ideal for multi-tenant platforms. Finally, the pause orchestration feature allows operators to temporarily stop ECK from reconciling a resource's state, preventing it from overwriting manual changes during critical maintenance or debugging sessions.

These updates directly impact the daily workflows of several key teams. For developers and DevOps engineers, the changes significantly reduce operational friction. Dynamic namespace management means they can spin up new, fully managed Elastic environments for different projects on the fly without filing a ticket or waiting for a central infrastructure team to reconfigure the operator. The ability to pause orchestration provides a crucial safety valve, giving them the confidence to perform manual interventions on a cluster without fighting against automation. For security teams and CTOs, the introduction of universal mTLS is a critical enhancement. It hardens the internal security posture of the entire data stack, simplifying the process of meeting stringent compliance standards like PCI DSS or HIPAA. This built-in security layer reduces the internal attack surface and shifts the security model from a protected perimeter to intrinsic, component-level trust.

From a business perspective, ECK 3.5 lowers the total cost of ownership for running the Elastic Stack on Kubernetes. The operational efficiencies gained from dynamic management and safer maintenance windows translate directly into saved engineering hours, freeing up teams to focus on building value-added features. The enhanced security posture also reduces organizational risk, potentially preventing costly data breaches and simplifying compliance audits. This update solidifies ECK's position as an enterprise-grade solution, making it a more compelling choice for companies running mission-critical workloads like search and analytics on Kubernetes. The practical takeaway for organizations already using ECK is to plan an upgrade to leverage these benefits. For those evaluating their data infrastructure, this release makes a strong case for adopting a Kubernetes-native approach to managing Elastic.

The evolution of ECK reflects a broader industry trend in the Kubernetes ecosystem: the maturation of operators from simple deployment tools to sophisticated, autonomous service managers. Early operators focused primarily on "Day 1" tasks like installing software. The features in ECK 3.5, however, are squarely focused on "Day 2" operations, which encompass the entire lifecycle of an application, including updates, scaling, and security. This shift is critical as more companies rely on Kubernetes as their standard operating environment. They expect tooling to not only automate deployment but also to intelligently and safely manage complex applications over time. By investing in features like mTLS and dynamic, API-driven controls, Elastic is ensuring its operator keeps pace with the demands of modern cloud-native platforms, where automation and security are paramount.

Related on Notifire

  • ResearchKubernetes security
  • ResearcheBPF
  • CompareKubernetes vs Nomad

✦ Notifire newsletter

Get more Infrastructure intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: Elastic Blog

Part of our research on

  • Kubernetes security →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube