Book Image

Getting Started with CockroachDB

By : Kishen Das Kondabagilu Rajanna
Book Image

Getting Started with CockroachDB

By: Kishen Das Kondabagilu Rajanna

Overview of this book

Getting Started with CockroachDB will introduce you to the inner workings of CockroachDB and help you to understand how it provides faster access to distributed data through a SQL interface. The book will also uncover how you can use the database to provide solutions where the data is highly available. Starting with CockroachDB's installation, setup, and configuration, this SQL book will familiarize you with the database architecture and database design principles. You'll then discover several options that CockroachDB provides to store multiple copies of your data to ensure fast data access. The book covers the internals of CockroachDB, how to deploy and manage it on the cloud, performance tuning to get the best out of CockroachDB, and how to scale data across continents and serve it locally. In addition to this, you'll get to grips with fault tolerance and auto-rebalancing, how indexes work, and the CockroachDB Admin UI. The book will guide you in building scalable cloud services on top of CockroachDB, covering administrative and security aspects and tips for troubleshooting, performance enhancements, and a brief guideline on migrating from traditional databases. By the end of this book, you'll have gained sufficient knowledge to manage your data on CockroachDB and interact with it from your application layer.
Table of Contents (17 chapters)
1
Section 1: Getting to Know CockroachDB
4
Section 2: Exploring the Important Features of CockroachDB
9
Section 3: Working with CockroachDB
Appendix: Bibliography and Additional Resources

Data encryption at rest and in flight

Encryption is the process of encoding plain text into an alternative unreadable format known as ciphertext. Decryption is the process of decoding the ciphertext back into its original plain text readable format. It is important to encrypt stored data, as well as the data that's being transferred between the client and nodes. In this section, we will learn how to achieve this.

Encryption at rest

Data at rest indicates the data that is stored on a physical storage system, such as a disk. Encryption at rest is an Enterprise-only feature. This feature allows you to encrypt all the files on the physical storage using Advanced Encryption Standard (AES).

Two types of keys are involved:

  • Store keys: These are provided by the user and are used to encrypt data keys.
  • Data keys: These are generated by CockroachDB and are used to encrypt all the files on disk. They are persisted in a registry file and are encrypted using the store...