Secondly access control sucks. You can only whitelist by external IP, and you cant access elasticsearch from your VPCs directly, as they sit outside your VPC.
I abandoned it, wrote some chef and terraform and had a much more stable and flexible setup. However at an increased management overhead. If it works for you thats cool, but there are caveats, so beware.