ECE Fully Private Installation on AWS - no public endpoints

I have installed ECE on AWS EC2 and while the (latest) installation docs are pretty straightforward it stops there. There are no specifics as to what is required after the installation.

I hope someone can help as I can't find any answers to the following:

  • The documentation insists that the AWS endpoint must be a public IP. Is that the only way? This would break our security requirements which won't allow any access to the public internet either via a NAT or Internet Gateway.
  • Is Kibana installed at the same time? There is no documentation on this.
  • Is the only to access the ECE APIs via the GUI?
  • I get a connection refused when I curl the nodes (except the initial controller which returns the html page). Is this normal behaviour?

Thank you

