Important
New database features are no longer connected to engine versions; features are now enabled independently during scheduled update windows, and “major” and “minor” releases no longer exist in Helios. Please visit the release notes to view the latest features available in your database clusters.
Shared Responsibility
On this page
SingleStore Helios has built in security controls that make it a secure environment to run customer workloads.
Shared Responsibility Model
The following table outlines the responsibilities of the customer and SingleStore for a SingleStore Helios deployment in Managed regions:
Cloud Infrastructure Physical Security
|
Customer
|
SingleStore
|
Customer Data, Accounts, and Identities
|
Customer
|
SingleStore
|
Network Isolation and Connectivity
|
Customer
|
SingleStore
|
SingleStore Database Access
|
Customer
|
SingleStore
|
API Controls/Access
|
Customer
|
SingleStore
|
Data Encryption (in Transit and at Rest)
Customer-Managed Encryption Keys (CMEK) is only supported on Managed regions.
|
Customer
|
SingleStore
|
Granular Auditing
|
Customer
|
SingleStore
|
Performance Monitoring/Alerting
|
Customer
|
SingleStore
|
Security Patches and Maintenance
|
Customer
|
SingleStore
|
High Availability and Disaster Recovery
|
Customer
|
SingleStore
|
Application Security
|
Customer
|
SingleStore
|
Secrets
|
Customer
|
SingleStore
|
Compliance
|
Customer
|
SingleStore
|
AI Usage
|
Customer
|
SingleStore
|
Responsibility Matrix
The following can be used as a quick reference to the shared responsibilities of the customer and SingleStore.
Cloud Management
|
Action |
SingleStore |
Customer |
|
VPC |
✔ |
|
|
EC2 instance management |
✔ |
|
|
Kubernetes management |
✔ |
|
|
S3 buckets management |
✔ |
|
|
SingleStore provisioning |
✔ |
|
Upgrades and Security
|
Action |
SingleStore |
Customer |
|
SingleStore upgrades |
✔ |
|
|
Software vulnerability remediation |
✔ |
|
|
Infrastructure vulnerability remediation |
✔ |
|
|
Scaling |
✔ |
|
Networking
|
Action |
SingleStore |
Customer |
|
External Routing |
✔ |
|
|
K8 internal Routing |
✔ |
|
|
Firewall |
|
✔ |
|
DNS |
✔ |
|
|
Load Balancer |
✔ |
|
Access Control
|
Action |
SingleStore |
Customer |
|
IAM role, service accounts |
✔ |
|
|
Access control and auditing |
✔ |
✔ |
Availability
|
Action |
SingleStore |
Customer |
|
DR |
✔ |
|
|
Availability (SLA) |
✔ |
|
Support
|
Action |
SingleStore |
Customer |
|
Logging |
✔ |
|
|
Audit logging |
✔ |
✔ |
|
Monitoring |
✔ |
|
|
Break glass |
✔ |
|
Last modified: