OpenSearch migration check for Elasticsearch and Kibana stacks: flags Elastic-licensed images, xpack settings, 7.14+ clients, ILM, dense_vector and Beats that break the cutover, with the OpenSearch replacement. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
25 rules for compose files, elasticsearch.yml, Kibana config, Logstash pipelines, client pins and mappings. The sample docker-compose.yml (Elasticsearch, Kibana, Filebeat 8.15.0) gives 6 fin
Elastic Cloud Hosted Standard starts at $99 per month (elastic.co/pricing/cloud-hosted).
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

Migrate from Elasticsearch to OpenSearch: 6 lines in a sample docker-compose.yml that break the cutover
6 lines in a sample Elasticsearch 8.15.0 docker-compose.yml break an OpenSearch cutover, and platform engineers in teams moving off Elastic find most of them only when the new node refuses to start. Elastic moved Elasticsearch and Kibana from Apache-2.0 to SSPL / Elastic License 2.0 with version 7.11, and Elasticsearch 7.17 reached end of support on 2026-01-15. OpenSearch forked from 7.10.2 and stayed Apache-2.0, so it is where many self-managed clusters go next.
The stack is the one you find in many repositories: one Elasticsearch node, Kibana, and Filebeat shipping container logs, all on 8.15.0.
elasticsearch:
image: docker.elastic.co/elasticsearch/elasticsearch:8.15.0
environment:
- xpack.security.enabled=true
- ELASTIC_PASSWORD=changeme
kibana:
image: docker.elastic.co/kibana/kibana:8.15.0
environment:
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
filebeat:
image: docker.elastic.co/beats/filebeat:8.15.0
| Line that breaks | OpenSearch fix |
|---|---|
| elasticsearch:8.15.0 image | opensearchproject/opensearch:2 |
| xpack.security.enabled=true | plugins.security.* |
| ELASTIC_PASSWORD | OPENSEARCH_INITIAL_ADMIN_PASSWORD |
| kibana:8.15.0 image | opensearch-dashboards:2 |
| ELASTICSEARCH_HOSTS | OPENSEARCH_HOSTS |
| filebeat:8.15.0 image | Fluent Bit or Data Prepper |
Why each one matters:
xpack.security.enabled stops the node at boot.OPENSEARCH_INITIAL_ADMIN_PASSWORD. ELASTIC_PASSWORD is simply ignored.OPENSEARCH_HOSTS, not ELASTICSEARCH_HOSTS, and saved objects from Kibana newer than 7.10.2 do not import.Rewritten for OpenSearch 2.17.0, the same file gives 0 findings.
Search the repository for elasticsearch and you get every service name, volume path and URL. The dangerous hits are in the dependency files. elasticsearch-py 7.14.0 added a product check that raises UnsupportedProductError on any server that is not Elasticsearch, and the Node, Java, Go and Ruby clients do the same. A requirements.txt with elasticsearch==8.15.1 and elasticsearch-dsl==8.15.3 gives 2 findings; the fix is opensearch-py.
Index templates carry their own blockers: dense_vector becomes knn_vector with index.knn: true, flattened becomes flat_object (OpenSearch 2.7 and later), ILM policies become ISM policies under _plugins/_ism, and ES|QL queries on /_query need to be rewritten as PPL or SQL.
OpenSearch Migration Check is a VS Code extension with 25 rules covering images, settings, clients, pipelines, mappings and APIs. Open a file and the findings appear in the Problems panel with the line number and the replacement. For a 7.x image it also counts the days since the 2026-01-15 end of support, from the date you run it. The same engine runs in the free web version in the browser.
Staying on Elastic hosting is a monthly bill: Elastic Cloud Hosted Standard starts at $99 per month. It does not move data; it lists the lines to change first.
It reads a docker-compose.yml, elasticsearch.yml, Kibana config, Logstash pipeline, client dependency file or index mapping and flags every line that breaks a move from Elasticsearch and Kibana to OpenSearch: Elastic images, xpack settings, 7.14+ clients, ILM, dense_vector and Beats. Each finding has the line number and the OpenSearch replacement. It has 25 rules and runs locally.
Platform engineers, SREs and DevOps teams moving a self-managed Elasticsearch 7.x or 8.x stack to OpenSearch or Amazon OpenSearch Service, usually because of the SSPL / Elastic License change in 7.11 or because Elasticsearch 7.17 reached end of support on 2026-01-15. It also helps developers switching application clients to opensearch-py or the OpenSearch JavaScript client.
Grep for elasticsearch hits every service name, volume path and URL, so the real blockers drown. A chatbot rarely knows that Elastic clients from 7.14 on raise UnsupportedProductError against OpenSearch, that OpenSearch refuses to start on an unknown xpack setting, or that OpenSearch 2.12 needs OPENSEARCH_INITIAL_ADMIN_PASSWORD. This check knows those lines and gives the replacement for each.
The free version checks any open file with all 25 rules, with line numbers and fixes, and the web version does the same in the browser. Nothing is cut or time-limited. The paid version, $29 once, scans the whole repository in one pass and exports one Markdown migration checklist per file, ready to attach to the change ticket.
Staying on Elastic's hosted offering costs money every month: Elastic Cloud Hosted Standard starts at $99 per month according to Elastic's pricing page. The free check costs nothing and the repository-wide version is a one-time $29, one licence key per person or team seat. It does not replace migrating the data, it finds the config and code lines to change first.
One question, answered by the person who built it. Your email only if you want the answer sent.