Open dsotirho-ucsc opened 2 years ago
If we need to log reads and writes, this would generate tremendous amounts of logs during a reindex, and cost a lot of money. #4688 put the ES cluster into the private subnet of the VPC which means that it is not directly reachable anymore from the public internet. Before that, the only layer of defense was authentication. Now both layers protect us from unauthorized access, if someone manages to enter the VPC and make requests to ES, we have bigger problems than trying to find out what requests they made against ES.
Marking ticket won't fix
based on the previous comment.
https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-fsbp-controls.html#fsbp-es-5