Updated on 2026-09-02 GMT+08:00

Enabling Public Network Access

Function

When an Elasticsearch/OpenSearch cluster has security mode and HTTPS access enabled, you can choose whether to configure public access. After public access is configured, you can obtain a public IP address to access the security cluster from the public network. Additionally, access control can be configured to set the IP addresses or CIDR blocks allowed to access the cluster from the public network.

Public access of an Elasticsearch/OpenSearch cluster is implemented through a shared load balancer, which shares resources with other instances. If your workloads require quicker access, you are advised to use a dedicated load balancer to access the cluster. For configuration details, see "Configuring a Dedicated Load Balancer for an Elasticsearch Cluster."

When public access is enabled and no access control whitelist is configured, all IP addresses are allowed. You are advised to configure an appropriate access control whitelist.

Calling Method

For details, see Calling APIs.

URI

POST /v1.0/{project_id}/clusters/{cluster_id}/public/open

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID. For details about how to obtain the project ID and name, see Obtaining the Project ID and Name.

Constraints

N/A

Range

Project ID of an account. The value contains 32 characters, consisting of lowercase letters and digits.

Default Value

N/A

cluster_id

Yes

String

Definition

ID of the cluster whose public network access you want to enable. For details about how to obtain the cluster ID, see Obtaining the Cluster ID.

Constraints

N/A

Range

The value is a UUID containing 36 characters.

Default Value

N/A

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

eip

Yes

BindPublicReqEip object

Definition:

EIP for public network access.

Constraints:

N/A

Value range:

N/A

Default value:

N/A

white_list

No

String

Definition

Whitelist for public access control. Add the IP addresses or CIDR blocks to be whitelisted, separated by commas (,). Valid examples: 192.168.1.1,10.0.0.0/24.

Constraints

The following are not supported: 0.0.0.0,x.x.x.x/0, non-standard formats such as 192.168.1, or duplicate entries.

Range

IP addresses or CIDR blocks, separated by commas (,). Duplicate entries are not allowed.

Default Value

N/A

Table 3 BindPublicReqEip

Parameter

Mandatory

Type

Description

band_width

Yes

BindPublicReqEipBandWidth object

Definition:

Public network bandwidth.

Constraints:

N/A

Table 4 BindPublicReqEipBandWidth

Parameter

Mandatory

Type

Description

size

Yes

Integer

Definition:

Public network bandwidth, in Mbit/s.

Constraints:

N/A

Value range:

1-200

Default value:

N/A

Response Parameters

Status code: 200

Table 5 Response body parameters

Parameter

Type

Description

action

String

Definition:

A setting required to enable public network access.

Value range:

The fixed value is bindZone, indicating that the binding is successful.

Example Requests

Enable public network access.

POST https://{Endpoint}/v1.0/{project_id}/clusters/4f3deec3-efa8-4598-bf91-560aad1377a3/public/open

{
  "eip" : {
    "band_width" : {
      "size" : 5
    }
  },
  "white_list" : "127.0.0.1"
}

Example Responses

Status code: 200

Request succeeded.

{
  "action" : "bindZone"
}

Status Codes

Status Code

Description

200

Request succeeded.

400

Invalid request.

Modify the request before retry.

409

The request could not be completed due to a conflict with the current state of the resource.

The resource that the client attempts to create already exists, or the update request fails to be processed because of a conflict.

412

The server did not meet one of the preconditions contained in the request.

Error Codes

See Error Codes.