Official CefasDB website

Security And Privacy - CefasDB Docs

Configure TLS or mTLS, validate JWTs through JWKS, and enforce operation and table scopes in CefasDB.

Documentation excerpt

Security in CefasDB has three layers: transport, identity, and operation authorization. Privacy-sensitive audience workflows add a fourth layer: avoid exporting raw member identity when aggregate answers are enough.

Use TLS for production gRPC. Plaintext --insecure is for local development and trusted test networks only.

Configure JWKS, issuer, and audience so requests must present a valid bearer token. Keep clock skew small and monitor auth failures after identity-provider changes.

Use scoped tokens. Separate table read, table write, table admin, plugin, backup, and cluster operations. Do not give broad admin tokens to application services.