Skip to content
Muhammet Şafak
tr

Book I of III The Unreliable Systems Trilogy

The Production Database Access Guide

Identities, credentials, just-in-time access, mediated execution and audit

A practical guide to deciding who and what can reach a production database, how, for how long, and with what record left behind.

  • 329 pages
  • 1st edition
  • Free
Choose a language 3 more coming

Page of the Türkçe edition: /tr/kitaplar/production-database-access-guide/

No sign-up, no email. License: © 2026 Muhammet Şafak — free to download and read

The book's thesis

Not

a credential-distribution problem

But

an authorization, execution and accountability problem

  • 01

    Authorization

    Decide who may do what to which data, where and for how long — decided per request.

  • 02

    Execution

    Inspect each statement before it runs and bound its effect (transaction, row guard, timeout) before it commits.

  • 03

    Accountability

    Keep evidence of who asked, who approved and what actually ran.

About the book

On a Thursday evening, a one-row fix changed a batch of invoices, and the log named only a shared admin role. The scene takes place at Ledgerly, a fictional invoicing and payments company, and no step in it was unreasonable: the password was shared to get the first service running, the client auto-committed by default, and the role could change every table because that was easier than deciding which tables each service needed.

From that scene the book draws one claim: production database access is not a credential-distribution problem but an authorization, execution and accountability problem. The credential in the story was legitimate and did exactly what it was issued to do; what was missing was everything around it. Across five parts and sixteen chapters, the book follows Ledgerly from a shared admin password to an access model that was designed on purpose.

Every control asks something of the people who build and operate it, so each chapter states the cost, the common mistakes and when not to use the control. The book is written from the defender’s side: it does not teach attack techniques, does not interpret compliance regimes and is not a database administration book.

Contents

  1. 01 Preface
  2. 02 The Door Nobody Designed
  3. 03 A Threat Model for Production Data
  4. 04 Identities, Roles and Least Privilege
  5. 05 Credentials and Secrets
  6. 06 Connections as Policy
  7. 07 Reads, Replicas and Data Copies
  8. 08 Paths In: Bastions, Proxies and Access Gateways
  9. 09 Just-in-Time and Break-Glass Access
  10. 10 Mediated Execution: Query Analysis and Dangerous Operations
  11. 11 Ad-hoc Queries and Data Fixes
  12. 12 Schema Changes and Migration Access
  13. 13 Sensitive Data: Classification, Masking and Minimization
  14. 14 Backups, Exports and Other Side Doors
  15. 15 Auditing and Accountability
  16. 16 Access During Incidents
  17. 17 An Access Checklist and Closing Thoughts
  18. 18 Appendix: Glossary, Pattern Quick Reference, Dangerous-Operations Matrix, Compliance Crosswalk, Access Review Template, Post-Incident Review Template

Frequently asked

3 questions

  • Who is this book for?

    Backend and platform engineers who build services that talk to a production database, SRE and DBA roles who operate it, tech leads who decide how access should work, and engineers who have newly become responsible for security. No security background is required.

  • Do I need to know a particular database engine?

    No. Familiarity with an engine helps with the examples but is not required. The book is engine-independent and uses pseudocode, an engine-neutral SQL-like notation and Mermaid diagrams.

  • Is it a compliance handbook?

    No. Regimes such as GDPR, KVKK, PCI DSS, SOC 2 and HIPAA come up only to explain what auditors and customers tend to ask. The book does not interpret any regime, cite its articles or say what is required of you; it aims to give your legal and compliance colleagues an architecture they can reason about.

Search the site

Start typing to search posts, projects and pages.

Esc to close Powered by Pagefind