Skip to content

Plan connectivity

Before deployment, decide:

  • whether to enable public access;
  • whether to use the platform-provided DNS domain or a company-owned DNS domain.

Detailed network, DNS, and certificate configuration is completed after deployment under Next Steps.

Choose public access

Public access enabled

Enable public access when Elasticsearch and Kibana can be reached through internet-accessible HTTPS endpoints.

Public access still requires:

  • TLS;
  • authentication and authorization;
  • organization-approved access restrictions.

After deployment, verify the public endpoint and complete any required DNS and certificate configuration.

Public access disabled

Disable public access when the platform must be reachable only through private network paths.

After deployment, configure:

  • an Azure Private Endpoint;
  • network routing to the Private Endpoint;
  • private DNS;
  • TLS certificate trust where required.

Private connectivity configuration begins after the platform publishes its authoritative Private Link and endpoint information.

Choose the DNS domain

Select one of the supported DNS domain options during deployment.

Platform-provided DNS domain

Use the default DNS domain and service hostnames provided by the platform.

Choose this option when:

  • you do not require a company-owned hostname;
  • you want the simplest DNS configuration;
  • the provided domain is acceptable for your users and integrations.

The platform provides the authoritative service hostnames.

Company-owned DNS domain

Use a domain or subdomain owned by your organization.

Choose this option when:

  • Elasticsearch and Kibana must use company-standard hostnames;
  • corporate DNS ownership and naming standards apply;
  • users or applications require a company-owned domain.

Before deployment, confirm that your DNS administrator can create the required records.

The exact DNS targets are published after deployment. Do not create records based on assumed hostnames or internal Azure resource names.

Public access and DNS domain are separate choices

The DNS domain does not determine whether access is public or private.

For example:

  • public access can use the platform-provided DNS domain;
  • public access can use a company-owned DNS domain;
  • private access can use the platform-provided domain when supported;
  • private access can use a company-owned DNS domain when supported.

The deployed Marketplace plan determines which combinations are available.

What happens after deployment

After the managed application is ready, continue under Next Steps:

  1. Reset the administrator password.
  2. Configure public or private network access.
  3. Configure DNS.
  4. Configure TLS certificates where required.
  5. Verify Elasticsearch and Kibana access.

The deployment details provide the authoritative endpoint hostnames, DNS targets, and Private Link information required for these steps.

Return to the planning overview, or continue to the deployment checklist.