The demo lake cuts corners so its listings stay short. Before real customer data arrives, every row must move from the middle column to the right one:
| Control | Demo lake in this chapter | Production BookNest |
|---|---|---|
| Storage credentials | Root key in every script | One user or role per service (Object Storage IAM) |
| Encryption in transit | HTTP inside the Docker 514 network | TLS on every hop (Encryption) |
| Encryption at rest | None on l1-minio | SSE-KMS with rotated keys |
| Catalog | REST fixture, no authentication | OAuth 2.0 and credential vending |
| Query engine | Password over HTTPS (Securing Catalog and Engines) | Single sign-on via OAuth 2.0 or LDAP |
| Audit logging | None | MinIO 30,943 audit webhook, Trino 403,499 event listener |
| Secrets | In scripts and properties files | A vault and short-lived credentials |
Work top to bottom, since a leaked root key defeats every control below it, and test the way security/iam.sh and security/auth.sh do: try what should fail, check that it fails, and rerun in CI.