Skip to content

Commit fe88aec

Browse files
authored
Add docs for FRH (#5517)
Docs for FRH offering. Closes: elastic/docs-content-internal#76
1 parent c8b8018 commit fe88aec

3 files changed

Lines changed: 110 additions & 2 deletions

File tree

Lines changed: 106 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,106 @@
1+
---
2+
navigation_title: FedRAMP authorized Cloud offerings
3+
applies_to:
4+
deployment:
5+
ess: ga
6+
products:
7+
- id: cloud-hosted
8+
---
9+
10+
# Elastic FedRAMP authorized Cloud offerings
11+
12+
Elastic users can take advantage of the FedRAMP authorized Cloud offerings to host sensitive data in a secure environment that meets their regulatory and compliance requirements.
13+
14+
{{fedramp-mod}} deployments are available to all users who have a Platinum or Enterprise subscription level. {{fedramp-high}} deployments are available to United States federal, state, and local agencies as well as tribal groups that have an Enterprise subscription level.
15+
16+
All FedRAMP deployments are hosted on AWS GovCloud (U.S.).
17+
18+
Learn about the Elastic FedRAMP offerings:
19+
20+
- [Comparison of available features](#ec-fedramp-comparison)
21+
- [Get started with FedRAMP](#ec-fedramp-get-started)
22+
- [Limitations](#ec-fedramp-limitations)
23+
- [FedRAMP FAQ](#ec-fedramp-faq)
24+
25+
## Comparison of available features [ec-fedramp-comparison]
26+
27+
This table provides a comparison of features and capabilities included in {{ech}} and all FedRAMP authorized Cloud offerings.
28+
29+
| Feature | {{ech}} | {{fedramp-mod}} | {{fedramp-high}} |
30+
|--------------|-----------|--------|-----------|
31+
| Trial period | 14 days | 30 days | none |
32+
| Marketplace offering | AWS/GCP/Azure | AWS GovCloud | AWS GovCloud |
33+
| Cloud service provider | AWS/GCP/Azure | AWS GovCloud | AWS GovCloud |
34+
| [Required subscription level](https://www.elastic.co/pricing) | Standard, Gold, Platinum, Enterprise | Platinum, Enterprise | Enterprise |
35+
| [Available regions](cloud://reference/cloud-hosted/regions.md) | 50+ regions | `us-gov-east-1` | `us-gov-east-1` |
36+
| Allowed users | All | All | U.S. federal, state, and local agencies; tribal groups |
37+
| IPv6 support at the edge | No | Yes | Yes |
38+
| [Bring Your Own Key (BYOK)](/deploy-manage/security/encrypt-deployment-with-customer-managed-encryption-key.md) | Yes | No | No |
39+
| [Support policy](https://www.elastic.co/support/welcome) | Global coverage | Global coverage or optional U.S. persons on U.S. soil support available | U.S. persons on U.S. soil support |
40+
| [{{kib}} connectors](kibana://reference/connectors-kibana.md) | All connector types | Email, Index, Webhook, Gen-AI, Bedrock, Gemini, Inference, Slack, Slack-API, PagerDuty | Email, Index, Webhook, Gen-AI, Bedrock, Gemini, Inference, Slack, Slack-API, PagerDuty |
41+
| [Cross-cluster search](/explore-analyze/cross-cluster-search.md) and [cross-cluster replication](/deploy-manage/tools/cross-cluster-replication.md) | Yes | Yes | Yes |
42+
| [Private connectivity](/deploy-manage/security/private-connectivity.md) | Yes | Yes | No |
43+
| [AutoOps](/deploy-manage/monitor/autoops.md) | Yes | No | No |
44+
| [Synthetic monitoring](/solutions/observability/synthetics/index.md) | Yes | No | No |
45+
| [Elastic Inference Service](/explore-analyze/elastic-inference/eis.md) | Yes | No | No |
46+
| [Managed OTLP Endpoint (mOTLP)](opentelemetry://reference/motlp.md) | Yes | No | No |
47+
| [Custom bundles and plugins](/deploy-manage/deploy/elastic-cloud/upload-custom-plugins-bundles.md) | Yes | Yes | No |
48+
| [Elastic AI Assistant for Observability and Search](/solutions/observability/ai/observability-ai-assistant.md), [Elastic AI Assistant for Security](/solutions/security/ai/ai-assistant.md) | Yes | Elastic Managed LLM not available | Elastic Managed LLM not available |
49+
| [Attack Discovery](/solutions/security/ai/attack-discovery.md) | Yes | Yes | TBD |
50+
| [Universal profiling](/solutions/observability/infra-and-hosts/universal-profiling.md) | Yes | No | No |
51+
52+
## Get started with FedRAMP [ec-fedramp-get-started]
53+
54+
{{fedramp-mod}} deployments are available for self-serve setup. Refer to the [Elastic FedRAMP authorized cloud offerings](https://www.elastic.co/industries/public-sector/fedramp) page to get started with a free trial.
55+
56+
To get started on {{fedramp-high}}, [contact our support team](/troubleshoot/index.md#contact-us).
57+
58+
## Limitations [ec-fedramp-limitations]
59+
60+
There are some limitations to note for using the FedRAMP authorized Cloud offerings.
61+
62+
### TLS
63+
64+
**Applies to:** {{fedramp-mod}}, {{fedramp-high}}
65+
66+
% Copied from https://www.elastic.co/docs/deploy-manage/security/fips-ingest#ingest-limitations-tls
67+
% I'll single-source this if the finalized content is identical to what we have in the security section.
68+
69+
Only FIPS 140-2 compliant TLS protocols, ciphers, and curve types are allowed to be used as listed below.
70+
* The supported TLS versions are `TLS v1.2` and `TLS v1.3`.
71+
* The supported cipher suites are:
72+
* `TLS v1.2`: `ECDHE-RSA-AES-128-GCM-SHA256`, `ECDHE-RSA-AES-256-GCM-SHA384`, `ECDHE-ECDSA-AES-128-GCM-SHA256`, `ECDHE-ECDSA-AES-256-GCM-SHA384`
73+
* `TLS v1.3`: `TLS-AES-128-GCM-SHA256`, `TLS-AES-256-GCM-SHA384`
74+
* The supported curve types are `P-256`, `P-384` and `P-521`.
75+
76+
Support for encrypted private keys is not available, as the cryptographic modules used for decrypting password protected keys are not FIPS validated. If an output or any other component with an SSL key that is password protected is configured, the components will fail to load the key. When running in FIPS mode, you must provide non-encrypted keys.
77+
Be sure to enforce security in your FIPS environments through other means, such as strict file permissions and access controls on the key file itself, for example.
78+
79+
### {{elastic-defend}}
80+
81+
**Applies to:** {{fedramp-mod}}, {{fedramp-high}}
82+
83+
The {{elastic-defend}} integration that runs on hosts being protected has various features that require data to be sent directly to Elastic-managed cloud services. The data sent is not sourced from within the secure enclave on the host. However, you may still want to adjust the configuration for your {{fedramp-mod}} and {{fedramp-high}} environments. You can use the [advanced setting](/reference/security/defend-advanced-settings.md) `[linux,mac,windows].advanced.allow_cloud_features` to activate or deactivate each {{elastic-defend}} feature individually.
84+
85+
### Custom plugins
86+
87+
**Applies to:** {{fedramp-high}}
88+
89+
Custom plugins are currently not supported in {{fedramp-high}} deployments.
90+
91+
## FedRAMP FAQ [ec-fedramp-faq]
92+
93+
Find answers here to some common questions about using the FedRAMP authorized Cloud offerings.
94+
95+
* [Who can use FedRAMP?](#who-can-use-fedramp)
96+
* [Where is FedRAMP hosted?](#where-is-fedramp-hosted)
97+
98+
$$$who-can-use-fedramp$$$**Who can use FedRAMP?**
99+
: The FedRAMP authorized Cloud offerings are intended for users who require their {{ecloud}} services to meet special security and compliance requirements:
100+
101+
- {{fedramp-mod}} is available to all users having a Platinum or Enterprise subscription level.
102+
- {{fedramp-high}} is available to United States federal, state, and local agencies as well as tribal groups. An Enterprise subscription level is required.
103+
104+
$$$where-is-fedramp-hosted$$$**Where is FedRAMP hosted?**
105+
106+
: {{fedramp-mod}} and {{fedramp-high}} {{ecloud}} deployments are hosted on [AWS GovCloud (US)](https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html) in the `us-gov-east-1` region.

deploy-manage/toc.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,7 @@ toc:
6363
- file: deploy/elastic-cloud/manage-deployments-using-elastic-cloud-api.md
6464
- file: deploy/elastic-cloud/keep-track-of-deployment-activity.md
6565
- file: deploy/elastic-cloud/restrictions-known-problems.md
66+
- file: deploy/elastic-cloud/fedramp.md
6667
- file: deploy/elastic-cloud/tools-apis.md
6768
- file: deploy/cloud-enterprise.md
6869
children:

docset.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -294,5 +294,6 @@ subs:
294294
ece-docker-images-8: 8.19.11
295295
ece-docker-images-9: 9.3.0
296296
search-platform: "Search AI Platform"
297-
298-
297+
fedramp-mod: "FedRAMP Moderate"
298+
fedramp-high: "FedRAMP High"
299+
fedramp-il5: "FedRAMP IL5"

0 commit comments

Comments
 (0)