Enabling Public Network Access
Function
When an Elasticsearch/OpenSearch cluster has security mode and HTTPS access enabled, you can choose whether to configure public access. After public access is configured, you can obtain a public IP address to access the security cluster from the public network. Additionally, access control can be configured to set the IP addresses or CIDR blocks allowed to access the cluster from the public network.
Public access of an Elasticsearch/OpenSearch cluster is implemented through a shared load balancer, which shares resources with other instances. If your workloads require quicker access, you are advised to use a dedicated load balancer to access the cluster. For configuration details, see "Configuring a Dedicated Load Balancer for an Elasticsearch Cluster."
Calling Method
For details, see Calling APIs.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, the following identity policy-based permissions are required.
URI
POST /v1.0/{project_id}/clusters/{cluster_id}/public/open
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | Definition Project ID. For details about how to obtain the project ID and name, see Obtaining the Project ID and Name. Constraints N/A Range Project ID of an account. The value contains 32 characters, consisting of lowercase letters and digits. Default Value N/A |
| cluster_id | Yes | String | Definition ID of the cluster whose public network access you want to enable. For details about how to obtain the cluster ID, see Obtaining the Cluster ID. Constraints N/A Range The value is a UUID containing 36 characters. Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| eip | Yes | BindPublicReqEip object | Definition: EIP for public network access. Constraints: N/A Value range: N/A Default value: N/A |
| white_list | No | String | Definition Whitelist for public access control. Add the IP addresses or CIDR blocks to be whitelisted, separated by commas (,). Valid examples: 192.168.1.1,10.0.0.0/24. Constraints The following are not supported: 0.0.0.0,x.x.x.x/0, non-standard formats such as 192.168.1, or duplicate entries. Range IP addresses or CIDR blocks, separated by commas (,). Duplicate entries are not allowed. Default Value N/A |
| is_auto_pay | No | Integer | Definition Whether to enable automatic payment from your Huawei Cloud account. Constraints This parameter applies to yearly/monthly clusters. Range
Default Value 0 |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| band_width | Yes | BindPublicReqEipBandWidth object | Definition: Public network bandwidth. Constraints: N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| action | String | Definition: A setting required to enable public network access. Value range: The fixed value is bindZone, indicating that the binding is successful. |
Example Requests
Enable public network access.
POST https://{Endpoint}/v1.0/{project_id}/clusters/4f3deec3-efa8-4598-bf91-560aad1377a3/public/open
{
"eip" : {
"band_width" : {
"size" : 5
}
},
"white_list" : "127.0.0.1"
} Example Responses
Status code: 200
Request succeeded.
{
"action" : "bindZone"
} SDK Sample Code
The SDK sample code is as follows.
Java
Enable public network access.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 | package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.css.v1.region.CssRegion; import com.huaweicloud.sdk.css.v1.*; import com.huaweicloud.sdk.css.v1.model.*; public class CreateBindPublicSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); String projectId = "{project_id}"; ICredential auth = new BasicCredentials() .withProjectId(projectId) .withAk(ak) .withSk(sk); CssClient client = CssClient.newBuilder() .withCredential(auth) .withRegion(CssRegion.valueOf("<YOUR REGION>")) .build(); CreateBindPublicRequest request = new CreateBindPublicRequest(); request.withClusterId("{cluster_id}"); BindPublicReq body = new BindPublicReq(); BindPublicReqEipBandWidth bandWidthEip = new BindPublicReqEipBandWidth(); bandWidthEip.withSize(5); BindPublicReqEip eipbody = new BindPublicReqEip(); eipbody.withBandWidth(bandWidthEip); body.withWhiteList("127.0.0.1"); body.withEip(eipbody); request.withBody(body); try { CreateBindPublicResponse response = client.createBindPublic(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
Python
Enable public network access.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 | # coding: utf-8 import os from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkcss.v1.region.css_region import CssRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkcss.v1 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.environ["CLOUD_SDK_AK"] sk = os.environ["CLOUD_SDK_SK"] projectId = "{project_id}" credentials = BasicCredentials(ak, sk, projectId) client = CssClient.new_builder() \ .with_credentials(credentials) \ .with_region(CssRegion.value_of("<YOUR REGION>")) \ .build() try: request = CreateBindPublicRequest() request.cluster_id = "{cluster_id}" bandWidthEip = BindPublicReqEipBandWidth( size=5 ) eipbody = BindPublicReqEip( band_width=bandWidthEip ) request.body = BindPublicReq( white_list="127.0.0.1", eip=eipbody ) response = client.create_bind_public(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
Go
Enable public network access.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 | package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" css "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/css/v1/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") projectId := "{project_id}" auth, err := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). WithProjectId(projectId). SafeBuild() if err != nil { fmt.Println(err) return } hcClient, err := css.CssClientBuilder(). WithRegion(region.ValueOf("<YOUR REGION>")). WithCredential(auth). SafeBuild() if err != nil { fmt.Println(err) return } client := css.NewCssClient(hcClient) request := &model.CreateBindPublicRequest{} request.ClusterId = "{cluster_id}" bandWidthEip := &model.BindPublicReqEipBandWidth{ Size: int32(5), } eipbody := &model.BindPublicReqEip{ BandWidth: bandWidthEip, } whiteListBindPublicReq:= "127.0.0.1" request.Body = &model.BindPublicReq{ WhiteList: &whiteListBindPublicReq, Eip: eipbody, } response, err := client.CreateBindPublic(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
More
For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.
Status Codes
| Status Code | Description |
|---|---|
| 200 | Request succeeded. |
| 400 | Invalid request. Modify the request before retry. |
| 409 | The request could not be completed due to a conflict with the current state of the resource. The resource that the client attempts to create already exists, or the update request fails to be processed because of a conflict. |
| 412 | The server did not meet one of the preconditions contained in the request. |
Error Codes
See Error Codes.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot