ECK 3.5: Dynamic namespaces, pause orchestration, and mTLS everywhere
Blog post from Elastic
Elastic Cloud on Kubernetes (ECK) 3.5 adds operational, security, and resource-management improvements for running Elastic workloads at scale. Its Enterprise-only dynamic namespace feature uses Kubernetes label selectors to onboard or offboard namespaces immediately without changing operator configuration or restarting the operator, while preserving resources when management stops. A new pause-orchestration annotation suspends spec-driven actions such as upgrades, scaling, and configuration rollouts during maintenance, but continues essential tasks including certificate rotation, secret management, and health monitoring, replacing the deprecated full-reconciliation pause option. ECK 3.5 also extends Enterprise mutual TLS support so all Elastic Stack components connecting to Elasticsearch can automatically use ECK-managed client certificates, with optional certificate authentication between Elastic Agents and Fleet Server. StackConfigPolicy now supports declarative Elasticsearch role definitions and reusable configurations populated from ConfigMaps and Secrets. Other changes include a simplified CPU and memory resource field, lower operator cache usage in large clusters, hot-reloadable secure settings for newer Elasticsearch versions, expanded AutoOps and Fleet configuration, cert-manager compatibility, FIPS 140-3 native builds, and more accurate Kibana readiness probes.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 14 | 3,490 | 385 | 112 | +26% |
| Secrets Management | 5 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.