Is there a way to restrict access to a ES instance on ECE? I've played around with IP filtering but due to the design, ES instances only se traffic from the proxies. Usually proxies provide something like an X-Forwarded-For header with the source IP. Is there a similar system I could leverage or do you have an other suggestion for an additional way to restrict access (except username / password)?

Hi @Lafunamor - sorry nobody answered you on this. Currently IP filtering or similar 2FA-type things aren't supported, we are looking at adding this very soon though