Elastic Cloud on Kubernetes (ECK) and Elastic Cloud Enterprise (ECE) are Elastic’s two orchestrators for running the Elastic Stack on infrastructure the customer controls. Both are self-managed Software under the Elastic Software Subscription Agreement, which covers Elastic software “licensed for use on Customer’s premises or in Customer’s public cloud account”.[5] They differ from a stand-alone cluster in where the licence sits. For Elastic Cloud, ECE and ECK, “Licenses and subscriptions are controlled at the orchestrator or organization level, and apply to all related deployments.” For self-managed Elasticsearch, licences “are controlled at the cluster level, and apply only to a single cluster”.[4]
A licence manager therefore needs a different evidence trail for each type. On ECK, the operator measures memory and reports it in a ConfigMap. On ECE, one orchestration licence installs cluster licences into every hosted deployment. On a plain cluster, each licence file is checked separately.
Editions
| Deployment type | Licence levels | What happens without a paid licence |
|---|---|---|
| ECK | Basic (free) and Enterprise only[1] | Basic licence for the operator and every managed application[1] |
| ECE | 30-day trial at installation, then a full licence from Elastic[2] | After expiry, clusters cannot be created or changed[2] |
| Self-managed cluster | Basic, Platinum (existing customers), Enterprise[3][6] | Basic, which never expires[3] |
“ECK is only offered in two licensing tiers: Basic and Enterprise.” Basic users get support from GitHub or the community, and “A paid Enterprise subscription is required to engage the Elastic support team.”[1] Full ECE licences “enable all ECE hosted deployments with the same products, features, and support that are available at our Enterprise subscription level on Elastic Cloud”.[2]
The subscriptions page lists the ECK orchestration features under the paid levels. Its footnote 4 adds a condition: “Customers whose Enterprise subscriptions use ECE/ECE Instances as the billing metric must agree to additional terms before they can access the Enterprise-level features listed in this section.” (rule ECE Instances billing metric needs additional terms for Enterprise features)[6] Elastic does not publish a definition of the ECE Instance metric.
Metrics
The contractual metric for a self-managed Enterprise subscription is the Resource Unit. It equals “the total GB of RAM Addressable by all Billable Enterprise Software deployed by Customer in connection with the Enterprise Software Subscription, divided by 64”, with any remainder rounded up. Addressable RAM is “the quantity of RAM that benefits the execution of the Software”.[5] ECK reports the same quantity as Enterprise Resource Units (ERUs).[1]
What counts as Billable Enterprise Software depends on whether the Software runs on ECK (rule Logstash on ECK is Billable Enterprise Software):
| Component | Deployed on ECK | Not deployed on ECK |
|---|---|---|
| Beats, Elastic Agent | Excluded | Excluded |
| Logstash | Not excluded | Excluded |
| Endgame Agent, Elastic Endpoint agent | Not excluded | Excluded |
| Elasticsearch, Kibana and other Software | Billable | Billable |
Source: Software Subscription Agreement section 1, definition of Billable Enterprise Software.[5]
The ECK documentation describes Logstash as “counted for informational purposes only; billable consumption depends on your license terms on a per-customer basis”.[1] Under the published agreement, Logstash on ECK falls inside Billable Enterprise Software. A customer running Logstash on ECK should check its Order Form for how Logstash memory is treated.
Counting / floors
How ECK measures
“ECK automatically tracks the memory capacity of all managed Elastic Stack deployments and reports this information as Enterprise Resource Units (ERUs).” The data is written to a ConfigMap called elastic-licensing in the operator’s namespace “and is updated every 2 minutes”.[1] For each resource, ECK multiplies the memory capacity per node by the number of replicas, and the sum across resource types is the total managed memory. “ECK does not measure actual runtime memory consumption.” It reads configured capacity in this order (rule ECK reports configured memory as Enterprise Resource Units):[1]
- The container memory limit (
resources.limits.memory) on the application container, if set. - Otherwise an application setting: the Elasticsearch
-Xmxheap fromES_JAVA_OPTS, doubled to account for non-heap memory; the Kibana--max-old-space-size; or the Logstash and Enterprise Search-Xmx, doubled. - Otherwise a built-in default for the resource type.
Elastic Agent, Beats and Elastic Maps Server “are not counted towards usage”.[1] The ConfigMap example shows fields such as eck_license_expiry_date, elasticsearch_memory_bytes and total_managed_memory_bytes. If the operator metrics endpoint is enabled, it also exposes elastic_licensing_enterprise_resource_units_max and elastic_licensing_enterprise_resource_units_total.[1] Because the count follows configured limits, raising a memory limit raises the ERU count even if the pods never use the memory.
Excess use and verification
The agreement grants an Enterprise licence “for the number of Resource Units set forth in the applicable Order Form”.[5] If use goes above that number, the customer “shall promptly notify Elastic in writing”, stating the number of Excess Units and the date of first use, and is invoiced pro rata from that date.[5] Elastic may verify use “upon 30 days’ notice”, remotely or, if that is not possible, on site no more than once in 12 months.[5] Support is limited in the same way, “up to the number of Resource Units included in the Subscription”.[5] The elastic-licensing ConfigMap is the natural record to keep for these clauses. See True-up and Software license audit.
Licence keys
The agreement provides that after an Order Form is signed, “Elastic shall deliver to Customer a License Key”, and the Software is deemed delivered when the key is provided.[5] The three deployment types handle the key differently.
ECK. An Enterprise customer downloads the “Orchestration license” as a JSON file. It enables ECK Enterprise features and embeds “Enterprise stack licenses for recent Elasticsearch versions and Platinum licenses for older Elasticsearch versions”.[1] The licence is stored as a Kubernetes secret in the operator’s namespace. Enterprise licences “are container licenses that include multiple licenses for individual Elasticsearch clusters with shorter expiry”, so Kibana and the _license API show a different expiry from the ECK licence. ECK renews the cluster licences until the ECK licence expires.[1] For renewal, Elastic recommends installing the new licence as a second secret beside the old one, to avoid an unintended downgrade of clusters to Basic.[1]
ECE. ECE licences contain “the actual license for Elastic Cloud Enterprise” and the cluster licences that ECE installs into individual clusters. ECE installs cluster licences “with an approximately 3 month window” and updates them as they come within a month of expiration.[2]
Self-managed cluster. Licence files “have an effective date and an expiration date”. A new licence cannot be installed before its effective date, and updates take effect without restarting Elasticsearch.[3]
Trials and expiry
| Situation | ECK | ECE | Self-managed cluster |
|---|---|---|---|
| Trial | 30-day Enterprise trial, started with a Kubernetes secret; only if no trial was activated before[1] | 30-day trial activated at installation; extension requested from Elastic[2] | 30-day trial once per major product version[3] |
| On expiry | Platinum and Enterprise features in degraded mode at the end of a trial[1] | No new or modified clusters; X-Pack features degraded[2] | Level reverts to Basic[3] |
Starting an ECK trial requires an annotation through which the customer is “expressing that you have accepted the Elastic EULA”.[1] An ECK trial can be started “only if a trial has not been previously activated” (rule ECK Enterprise trial: 30 days, once, degraded mode at the end).[1]
When an ECE licence expires, “Users cannot create new clusters or modify existing clusters : They can only delete them.” The clusters remain fully accessible to clients (rule ECE licence expiry blocks creating or changing clusters).[2] On a self-managed cluster, Elasticsearch starts logging warnings 30 days before expiry. “If your license expires, your subscription level reverts to Basic and you will no longer be able to use Platinum or Enterprise features” (rule Self-managed licence expiry reverts the cluster to Basic).[3]
Virtualization & partitioning
Neither orchestrator changes the metric. Resource Units are counted on Addressable RAM, not on hosts, cores or Kubernetes nodes.[5] On ECK the RAM figure is the configured container limit or heap setting multiplied by replicas, so right-sizing pod memory limits is the lever that changes the count.[1] For Cross-Cluster Search and Cross-Cluster Replication, “all connected clusters need to be on the same Subscription Level” (rule Cross-cluster search and replication: all connected clusters on the same Subscription Level).[5] The subscriptions page lists ECK cross-cluster replication and search “within or outside of a Kubernetes cluster” as an orchestration feature.[6]
Out of scope
- The definition and pricing of the ECE Instance billing metric, which Elastic does not publish.[6]
- Elastic Cloud Hosted and Serverless, covered in Elastic Cloud Hosted subscription levels and Elastic Cloud Serverless pricing.
- Source code licences (ELv2, SSPL, AGPLv3), covered in Elastic licensing.
- Order Form terms that override the published agreement for a given customer.