Product overview

Eliatra Cloud Tresor is presented by Eliatra as a plugin that enables encryption at rest for OpenSearch. It encrypts all OpenSearch data that resides on disk and was made available as a technology preview. Eliatra positions it as a way to retain control over data in OpenSearch deployments, particularly on public clouds, and notes that it can equally be used in private clouds or on-premises installations. The plugin ships with a command line tool called earctl, used to initialise the plugin and manage the encryption keys.

  • OpenSearch plugin for encryption at rest (EAR)
  • Encrypts OpenSearch data stored on disk
  • Released initially as a technology preview
  • Bundled earctl command line tool for initialisation and key management

Source: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

How it works

The plugin is installed in the same way as any other OpenSearch plugin and requires almost no configuration. Once installed and initialised, users can create encrypted indices; all data residing in an encrypted index is stored encrypted on disk. Data in encrypted indices cannot be read or modified without the correct decryption key, which is held only in memory on the cluster nodes and never written to the server's disk. Eliatra states that the plugin works in all environments, including OpenSearch running on Docker, Kubernetes, EC2 or a user's own data centre.

  • Installed like any standard OpenSearch plugin
  • Encrypted indices store data encrypted on disk
  • Decryption key kept in memory only, never on disk
  • Supported on Docker, Kubernetes, EC2 and self-hosted data centres

Source: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

Encrypted snapshots

Alongside encrypted indices, the plugin can encrypt snapshots, which are typically used to back up data. An encrypted snapshot may contain both encrypted and non-encrypted indices, so the feature is independent of whether encrypted indices are in use. This allows a cluster holding only regular indices to store backups in encrypted form on targets such as S3 or NFS.

  • Encryption of OpenSearch snapshots (backups)
  • Snapshots may mix encrypted and non-encrypted indices
  • Usable with S3 or NFS snapshot repositories

Source: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

Preconditions and limitations

Eliatra lists a small number of preconditions and limitations that apply to encrypted indices. Realtime get actions are executed as non-realtime actions, and there is a slight performance impact when indexing and searching in encrypted indices. The index mapping must include a metadata field named _encrypted_tl_content of type binary; this field never appears in search results and can otherwise be ignored. After a full cluster restart, in which all nodes are shut down at once, the plugin must be initialised again before encrypted indices can be accessed; apart from these points, an encrypted index behaves like any other index and supports all queries and mappings.

  • Realtime get actions run as non-realtime actions
  • Slight performance impact on indexing and searching
  • Mapping must include binary field _encrypted_tl_content
  • Re-initialisation required after a full cluster restart

Sources: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor, Eliatra Cloud Lock - Encryption at Rest for OpenSearch

Documentation and naming

The announcement of Eliatra Cloud Tresor is published on the Eliatra blog and authored by co-founder Jochen Kressin. The original post is marked as outdated and states that the feature was released as generally available, with the download link on that page no longer current. A later post on the same site describes the GA release under the name Eliatra Cloud Lock, where the accompanying command line tool is called clctl. Both posts include a walkthrough covering preparation, installation, initialisation, creating an encrypted index, creating and restoring an encrypted snapshot, and simplifying setup with index templates.

  • Announcement posts published on the Eliatra blog
  • Authored by Jochen Kressin, co-founder of Eliatra
  • Original technology preview post marked as outdated
  • GA release documented as Eliatra Cloud Lock with the clctl tool
  • Step-by-step walkthrough for indices, snapshots and index templates

Sources: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor, Eliatra Cloud Lock - Encryption at Rest for OpenSearch

Sources

  1. Encryption at Rest for OpenSearch: Eliatra Cloud Tresor https://eliatra.com/blog/opensearch-encryption-at-rest-snapshots/ Verified 02 Oct 2026
  2. Eliatra Cloud Lock - Encryption at Rest for OpenSearch https://eliatra.com/blog/eliatra-cloud-lock-encryption-at-rest-for-opensearch/ Verified 17 Sep 2026

Last verified 17 Sep 2026. This entry is compiled from the public web pages listed above. Nothing here is stated that those pages do not, and each of them was read on the date shown.