Database Security

This information is related to the Event Repository.

Install MongoDB with an authorization mode based on a key file. The Event Repository database is not accessed directly and the network firewall rules can be set up to only permit access from the MATRIXX Business API Gateway pods. The Business API Gateway only provides event query APIs and all access is logged within the Web application layer. Events are created as immutable records. Limiting any other database or operating system access to the Event Repository servers ensures records cannot be tampered with and the Mongo database is further secured by the limitation of which services are able to connect to the system.