User Tools

Site Tools


big_data_service:big_data_service_advanced_configuration

Big Data Service Advanced Configuration

The Big Data Service ships with App Store Connect. It is composed of a stand-alone Elasticsearch node configured for local data storage. Keeping it on-premises guarantees data sovereignty, but introduces certain maintenance overheads.

Like any database installation, managing upgrades requires planning for downtime, data migration, software upgrades and rollback. As a consequence, Big Data Service upgrades are infrequent, meaning a dependency on legacy software is inevitable. The Big Data Service mitigates this by running on an isolated Elasticsearch instance accessible only to local processes, significantly reducing the potential attack surface.

Configuration

Technical Advisories

The following technical advisories cover vulnerability findings that apply to the incumbent Big Data Service and the mitigations available. Whilst running end-of-life components is not ideal, practical risk is considerably lower in this architecture than in a regular internet-facing database deployment.

Component Advisory Description
Java Runtime Engine TA-001: Outdated JRE The installer bundles a cut-down JRE that is not updated with product releases. Upgrade the JRE to address outdated scanner findings.
Log4j 1.2.17 TA-002: Log4j 1.2.17 in Elasticsearch 2.4 Remediation of Log4j 1.x vulnerability findings using the Reload4j drop-in replacement. Covers CVE-2022-23302, CVE-2022-23305, and CVE-2022-23307.

Upcoming Release

Preparation for a new major release is underway. Customers will be given an opportunity to phase in the new database and will be provided with tools to aid data migration. Intelligent Plant are also available to assist with migration.

No firm release date is set, but we are aiming for 2027 Q1.

big_data_service/big_data_service_advanced_configuration.txt · Last modified: 2026/07/31 10:20 by su