Skip to content

ECH PrivateLink: warn that Cloud ID encodes non-VPCE URL - #8034

Open
kunisen wants to merge 4 commits into
mainfrom
kunisen-docpr-stl-1921
Open

ECH PrivateLink: warn that Cloud ID encodes non-VPCE URL#8034
kunisen wants to merge 4 commits into
mainfrom
kunisen-docpr-stl-1921

Conversation

@kunisen

@kunisen kunisen commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

The Cloud ID always encodes the public (found.io-based) endpoint domain, not the PrivateLink-compatible elastic-cloud.com domain. Customers who derive their PrivateLink URL from the Cloud ID get a TLS cert mismatch.

  • private-connectivity-aws.md: add note in Test the connection (ECH)
  • find-cloud-id.md: add note warning PrivateLink users away from Cloud ID

Related: elastic/support-tech-lead#1921

Summary

Generative AI disclosure

  1. Did you use a generative AI (GenAI) tool to assist in creating this contribution?
  • Yes
  • No

Claude

The Cloud ID always encodes the public (found.io-based) endpoint domain,
not the PrivateLink-compatible elastic-cloud.com domain. Customers who
derive their PrivateLink URL from the Cloud ID get a TLS cert mismatch.

- private-connectivity-aws.md: add note in Test the connection (ECH)
- find-cloud-id.md: add note warning PrivateLink users away from Cloud ID

Related: elastic/support-tech-lead#1921
@kunisen
kunisen requested a review from a team as a code owner August 20, 2026 09:37
@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Elastic Docs AI PR menu

Check the box to run an AI review for this pull request.

Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team.

@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@kunisen kunisen self-assigned this Aug 20, 2026
@kunisen kunisen added supportability ability enable self-service or support of product Team:Admin Issues owned by the Admin Docs Team docs ech Elastic Cloud Hosted labels Aug 20, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Docs review summary

Focus areas

  • Style and clarity: New notes are clear and correctly scoped, but one uses directional language ("as shown above") flagged by Vale — see inline comment. "e.g" and "towards" flagged by Vale in unrelated, pre-existing lines are not part of this diff.
  • Jargon: No unexplained Elastic-internal jargon in the new content; "Cloud ID", "PrivateLink", and "TLS certificate" are used correctly and match established page terminology.
  • Frontmatter and applies_to: No frontmatter changes in this PR; existing applies_to scoping (ess: ga) is preserved and the new notes don't require additional scoping since they apply uniformly within their applies-item blocks.
  • Content type fit: Both files remain how-to/reference style pages; the added notes fit the existing structure and don't disrupt the surrounding content type.
  • Contradictions: No contradictions found between the two changed files or against published docs — the added notes are consistent with each other and reinforce the existing PrivateLink guidance.
  • Parent issue satisfaction: Satisfied. The PR adds a warning in both find-cloud-id.md and private-connectivity-aws.md addressing the reported issue that the Cloud ID encodes the public endpoint domain and shouldn't be used to derive PrivateLink URLs.

Nits

  • private-connectivity-aws.md line 55 and line 65 have pre-existing Vale findings (e.g and towards) outside the diff; not blocking for this PR.

Notes

  • Reviewed only the two eligible changed markdown files per repo-wide-markdown scope.

Generated by Docs review agent for #8034 · sonnet50 · 32.3 AIC · ⌖ 3.95 AIC · ⊞ 17.6K

:::

:::{note}
The Cloud ID for your deployment encodes the public (non-PrivateLink) endpoint domain. Do not use URLs derived from the Cloud ID for PrivateLink connections — they will not match the TLS certificate served at the PrivateLink endpoint and the connection will fail with a certificate hostname mismatch. Always construct your private URL manually as shown above. Review [our KB article](https://ela.st/avoid-using-cloudid-for-privatelink-deployment) for more guidance.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use descriptive link text instead of "our KB article". Text like [Avoid using the Cloud ID for PrivateLink deployments](https://ela.st/avoid-using-cloudid-for-privatelink-deployment) tells readers what the link leads to before they click it, following the accessibility guidance against non-descriptive link text.

Also confirm the KB article is publicly accessible without a support login; if it requires an active support contract, link to a public resource instead or note that support access is required.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

no we may have to change the KB title later due to whatever reason so I want to keep things more generic and flexible.

Comment thread deploy-manage/security/private-connectivity-aws.md Outdated
Comment thread deploy-manage/security/private-connectivity-aws.md Outdated

@rahulranjan22 rahulranjan22 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor comment regarding use of dash.

@rahulranjan22 rahulranjan22 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking good.

@AlexP-Elastic AlexP-Elastic left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - thanks for making the change <3

(now we just have to remember to change it back when we finally do get round to fixing VPCE naming in cloud id :) )

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs ech Elastic Cloud Hosted supportability ability enable self-service or support of product Team:Admin Issues owned by the Admin Docs Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants