Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

ECK 3.5: Dynamic namespaces, pause orchestration, and mTLS everywhere

Blog post from Elastic

Post Details
Company
Date Published
Author
-
Word Count
2,019
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Elastic Cloud on Kubernetes (ECK) 3.5 adds operational, security, and resource-management improvements for running Elastic workloads at scale. Its Enterprise-only dynamic namespace feature uses Kubernetes label selectors to onboard or offboard namespaces immediately without changing operator configuration or restarting the operator, while preserving resources when management stops. A new pause-orchestration annotation suspends spec-driven actions such as upgrades, scaling, and configuration rollouts during maintenance, but continues essential tasks including certificate rotation, secret management, and health monitoring, replacing the deprecated full-reconciliation pause option. ECK 3.5 also extends Enterprise mutual TLS support so all Elastic Stack components connecting to Elasticsearch can automatically use ECK-managed client certificates, with optional certificate authentication between Elastic Agents and Fleet Server. StackConfigPolicy now supports declarative Elasticsearch role definitions and reusable configurations populated from ConfigMaps and Secrets. Other changes include a simplified CPU and memory resource field, lower operator cache usage in large clusters, hot-reloadable secure settings for newer Elasticsearch versions, expanded AutoOps and Fleet configuration, cert-manager compatibility, FIPS 140-3 native builds, and more accurate Kibana readiness probes.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 14 3,490 385 112 +26%
Secrets Management 5 2,244 480 132 -13%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.