Security Checklist

BookNest's Lakehouse Security Checklist

The demo lake cuts corners so its listings stay short. Before real customer data arrives, every row must move from the middle column to the right one:

BookNest's lakehouse security checklist
Control Demo lake in this chapter Production BookNest
Storage credentials Root key in every script One user or role per service (Object Storage IAM)
Encryption in transit HTTP inside the Docker 514 network TLS on every hop (Encryption)
Encryption at rest None on l1-minio SSE-KMS with rotated keys
Catalog REST fixture, no authentication OAuth 2.0 and credential vending
Query engine Password over HTTPS (Securing Catalog and Engines) Single sign-on via OAuth 2.0 or LDAP
Audit logging None MinIO 30,943 audit webhook, Trino 403,499 event listener
Secrets In scripts and properties files A vault and short-lived credentials

Work top to bottom, since a leaked root key defeats every control below it, and test the way security/iam.sh and security/auth.sh do: try what should fail, check that it fails, and rerun in CI.