Create a Private Endpoint
Complete this step when the platform must be accessed through private networking.
The Your deployment is ready notification provides the private endpoints and deployment information required to continue.
Before you begin
You need:
- the Private Link Service resource ID provided for the deployment;
- an Azure subscription and resource group where the Private Endpoint will be created;
- a VNet and subnet that can be reached by the users and applications that need access;
- permission to create a Private Endpoint.
Do not construct the Private Link Service resource ID from Azure resource names or naming conventions.
Create the Private Endpoint
- In the Azure portal, open Private endpoints.
- Select Create.
- Select the subscription, resource group, and region for the Private Endpoint.
- Enter a name that follows your organization's naming standard.
- On the resource-selection step, choose the option to connect using a resource ID or alias.
- Enter the Private Link Service resource ID provided for your deployment.
- Select the VNet and subnet where the Private Endpoint should be created.
- Review the configuration and create the endpoint.
Confirm the connection
After the Private Endpoint is created:
- Open the Private Endpoint.
- Review the Private Link connection status.
- Confirm that the connection reaches Approved state.
- Confirm that the Private Endpoint has been assigned a private IP address.
If the connection remains Pending, contact iVedha support using one of these options:
- AI chat:
https://copilot.ivedha.cloud - Support portal:
https://support.ivedha.com/
Provide the deployment reference from your Your deployment is ready notification.
Verify network reachability
Make sure the client networks that need to access Elasticsearch, Kibana, or Fleet can route to the Private Endpoint.
At this stage, DNS might not resolve correctly yet. That is expected.
The Private Endpoint provides the network path; DNS is configured separately.
Next step
Continue to configure private DNS.
Do not test the services by IP address. Elasticsearch, Kibana, and Fleet should be accessed by their provided hostnames so TLS validation works correctly.