What Encryption at Rest is

Eliatra Encryption at Rest is an OpenSearch plugin that encrypts OpenSearch indices, snapshots and all OpenSearch data that resides on disk. Eliatra describes it as the missing piece for regaining complete control over data in OpenSearch deployments, particularly on public clouds, and it can also be used in private clouds or on-premises installations. The offering appears on the Eliatra homepage under the heading "New from the Eliatra labs" alongside Coretex Axiom, and on the solutions page under "We can also help with".

  • OpenSearch plugin for encryption at rest (EAR)
  • Covers indices, snapshots and on-disk data
  • Suitable for public cloud, private cloud and on-premises

Sources: Eliatra | Support and Services for OpenSearch, Eliatra OpenSearch Solutions | Migration, Hosting & Support Services | Eliatra | Eliatra | Support and Services for OpenSearch, Eliatra Cloud Lock - Encryption at Rest for OpenSearch

Product names and releases

Eliatra first presented the plugin as a technology preview under the name Eliatra Cloud Tresor in a post dated 7 September 2023, which shipped a command line tool called earctl for initialising the plugin and managing encryption keys. That post is marked as outdated and superseded by a later post dated 6 May 2024 announcing the GA release under the name Eliatra Cloud Lock, whose command line tool is called clctl. Both posts are written by Jochen Kressin, Eliatra co-founder.

  • Eliatra Cloud Tresor — technology preview, 2023-09-07, earctl tool
  • Eliatra Cloud Lock — GA release, 2024-05-06, clctl tool

Sources: Encryption at Rest for OpenSearch: Eliatra Cloud Tresor, Eliatra Cloud Lock - Encryption at Rest for OpenSearch

How it works

The plugin installs like any other OpenSearch plugin and works in all environments, whether OpenSearch runs on Docker, Kubernetes, EC2 or in a company's own data centre. Eliatra states that it requires almost no configuration. Once installed and initialised, users can create encrypted indices, and all data in an encrypted index is stored encrypted on disk, so no one without the correct decryption key can read or modify it. The decryption key is held only in memory on the cluster nodes and is never stored on the server disk.

  • Installed as a standard OpenSearch plugin
  • Runs on Docker, Kubernetes, EC2 or own data centre
  • Encrypted indices store data encrypted on disk
  • Decryption key held in memory only

Sources: Eliatra Cloud Lock - Encryption at Rest for OpenSearch, Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

Encrypted snapshots

Alongside encrypted indices, the plugin can encrypt snapshots, which are typically used to back up data. An encrypted snapshot can contain both encrypted and non-encrypted indices, so the feature is independent of whether encrypted indices are in use. Clusters holding only regular non-encrypted indices can therefore still snapshot and store data encrypted on S3 or NFS.

  • Encrypts snapshots used for backups
  • Snapshots may mix encrypted and non-encrypted indices
  • Supports storage on S3 or NFS

Sources: Eliatra Cloud Lock - Encryption at Rest for OpenSearch, Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

Preconditions and limitations

Eliatra lists a small number of preconditions and limitations that apply to encrypted indices. Apart from these, an encrypted index works like any other index and supports all queries and mappings. The blog posts also include a walkthrough covering preparation, installation, initialisation, creating an encrypted index, creating and restoring an encrypted snapshot, and simplifying setup with index templates.

  • Realtime get actions are executed as non-realtime actions
  • Slight performance impact when indexing and searching encrypted indices
  • Mapping must include a binary metadata field _encrypted_tl_content, which never appears in search results
  • After a full cluster restart the plugin must be initialised again before encrypted indices can be accessed

Sources: Eliatra Cloud Lock - Encryption at Rest for OpenSearch, Encryption at Rest for OpenSearch: Eliatra Cloud Tresor

Provider and related offerings

Eliatra provides custom development for OpenSearch and OpenSearch Dashboards and focuses exclusively on the OpenSearch platform, offering expertise, operational support and professional services. The company can set up, configure and run OpenSearch environments, handle migration from the Elastic Stack, and fine-tune features for individual use cases. Encryption at Rest sits within a wider catalogue that also includes OpenSearch support packages, professional services, workshops and Coretex Axiom, an on-premise AI solution for document processing. Eliatra's stated mission is to provide robust, scalable and secure search and analytics solutions built on open-source innovation, and its website includes a "Get in Touch" contact route.

  • OpenSearch support packages
  • Migration and custom development
  • Workshops and operational support
  • Coretex Axiom for document processing

Sources: Eliatra | Support and Services for OpenSearch, Eliatra OpenSearch Solutions | Migration, Hosting & Support Services | Eliatra | Eliatra | Support and Services for OpenSearch, About Eliatra | Open-Source Search & Analytics Experts | Eliatra | Eliatra | Support and Services for OpenSearch

Sources

  1. Eliatra OpenSearch Solutions | Migration, Hosting & Support Services | Eliatra | Eliatra | Support and Services for OpenSearch https://eliatra.com/solutions/ Verified 18 Aug 2026
  2. About Eliatra | Open-Source Search & Analytics Experts | Eliatra | Eliatra | Support and Services for OpenSearch https://eliatra.com/about-us/ Verified 18 Aug 2026
  3. Eliatra | Support and Services for OpenSearch http://eliatra.com/
  4. Encryption at Rest for OpenSearch: Eliatra Cloud Tresor https://eliatra.com/blog/opensearch-encryption-at-rest-snapshots/ Verified 02 Oct 2026
  5. Eliatra Cloud Lock - Encryption at Rest for OpenSearch https://eliatra.com/blog/eliatra-cloud-lock-encryption-at-rest-for-opensearch/ Verified 17 Sep 2026

Last verified 17 Sep 2026. This entry is compiled from the public web pages listed above. Nothing here is stated that those pages do not, and each of them was read on the date shown.