Files
nexus/sreweekly/articles/142/08-a-brief-history-of-high-availability.html
2026-09-12 17:23:01 +08:00

5 lines
415 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="preload" as="image" href="/images/icons/copy-icon.svg"/><link rel="stylesheet" href="/_next/static/css/88295a675380e144.css" data-precedence="next"/><link rel="stylesheet" href="/_next/static/css/dc1197790a7221a6.css" data-precedence="next"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack-83edb66965ac3e69.js"/><script src="/_next/static/chunks/fd9d1056-01a3f02082479fa1.js" async=""></script><script src="/_next/static/chunks/2117-194f44714cd3ebce.js" async=""></script><script src="/_next/static/chunks/main-app-1033a728aa28fe33.js" async=""></script><script src="/_next/static/chunks/2941-ea6fdd90a456b354.js" async=""></script><script src="/_next/static/chunks/7878-4acaa52979fada4f.js" async=""></script><script src="/_next/static/chunks/app/layout-1dec2751509bb5fe.js" async=""></script><script src="/_next/static/chunks/4767-3be12bccc3485fef.js" async=""></script><script src="/_next/static/chunks/5902-b023fdecad77ece9.js" async=""></script><script src="/_next/static/chunks/5181-a7292807635098af.js" async=""></script><script src="/_next/static/chunks/1166-3e5e918f62c8a9c5.js" async=""></script><script src="/_next/static/chunks/7518-f6cc01f2368b270a.js" async=""></script><script src="/_next/static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js" async=""></script><link rel="preload" href="https://www.googletagmanager.com/gtm.js?id=GTM-NR8LC4" as="script"/><link rel="preload" href="https://boards.greenhouse.io/embed/job_board/js?for=cockroachlabs" as="script"/><title>A brief history of high availability</title><meta name="description" content="The perennial question of homo sapiens is, &#x27;How did we get here?&#x27; Today we&#x27;re going to take a crack at answering that: where &#x27;here&#x27; is defined as &#x27;high availability for web services&#x27;."/><meta name="robots" content="index, follow"/><link rel="canonical" href="https://www.cockroachlabs.com/blog/brief-history-high-availability/"/><meta property="og:title" content="A brief history of high availability"/><meta property="og:description" content="The perennial question of homo sapiens is, &#x27;How did we get here?&#x27; Today we&#x27;re going to take a crack at answering that: where &#x27;here&#x27; is defined as &#x27;high availability for web services&#x27;."/><meta property="og:url" content="https://www.cockroachlabs.com/blog/brief-history-high-availability/"/><meta property="og:image" content="https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg"/><meta property="og:image:alt" content="DataReplication ChristinaChung-1"/><meta name="twitter:card" content="summary_large_image"/><meta name="twitter:title" content="A brief history of high availability"/><meta name="twitter:description" content="The perennial question of homo sapiens is, &#x27;How did we get here?&#x27; Today we&#x27;re going to take a crack at answering that: where &#x27;here&#x27; is defined as &#x27;high availability for web services&#x27;."/><meta name="twitter:image" content="https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg"/><meta name="twitter:image:alt" content="DataReplication ChristinaChung-1"/><link rel="icon" href="/icon.png?682d166483111c8f" type="image/png" sizes="48x48"/><script src="/_next/static/chunks/polyfills-42372ed130431b0a.js" noModule=""></script></head><body><div><div style="visibility:hidden;pointer-events:none" aria-hidden="true"><div class="sticky -top-0.5 z-50 -mt-0.5"><div class="relative bg-white shadow-navigation"><div class="m-auto overflow-y-auto p-2 lg:px-2 lg:py-0 xl:max-w-[1140px] 2xl:max-w-[1330px]"><nav class="flex max-h-screen flex-wrap items-center justify-between lg:flex-nowrap"><a href="/"><img alt="cockroachlabs-logo-170" loading="lazy" width="340" height="48" decoding="async" data-nimg="1" class="max-w-[170px]" style="color:transparent" srcSet="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F4L99WneFfQZfEiTbAz7FBY%2Fcde51d5ab34e96fe246fbc8fe4dea72c%2Fcockroachlabs-logo-170.png&amp;w=384&amp;q=75 1x, /_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F4L99WneFfQZfEiTbAz7FBY%2Fcde51d5ab34e96fe246fbc8fe4dea72c%2Fcockroachlabs-logo-170.png&amp;w=750&amp;q=75 2x" src="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F4L99WneFfQZfEiTbAz7FBY%2Fcde51d5ab34e96fe246fbc8fe4dea72c%2Fcockroachlabs-logo-170.png&amp;w=750&amp;q=75"/></a><svg width="30" height="30" role="img" aria-label="burger" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="cursor-pointer fill-electric-purple-500 lg:hidden"><use href="#burger"></use></svg><div class="mt-3 flex max-h-[70vh] w-full flex-col items-center overflow-auto border border-neutral-200 lg:mt-0 lg:flex-row lg:border-none hidden lg:flex"><div class="flex w-full flex-col lg:ml-[40px] lg:w-auto lg:flex-row"><div class="flex items-center border-b md:px-0 lg:h-[84px] lg:border-none lg:px-3 2xl:px-2 h-[84px] group" role="menuitem" tabindex="0"><a class="mx-4 my-1 block rounded-md border-2 border-solid border-transparent px-4 lg:m-0 lg:rounded-none lg:p-0 lg:focus:border-2" href="#"><div class="relative flex items-center justify-between "><span class="relative p-2 font-poppins text-[16px] lg:mt-[5px] group-hover:text-electric-purple-500">Product</span><svg width="13" height="13" role="img" aria-label="chevron-down" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:absolute lg:-bottom-0 lg:left-[40%]"><use href="#chevron-down"></use></svg></div></a></div><div class="flex items-center border-b md:px-0 lg:h-[84px] lg:border-none lg:px-3 2xl:px-2 h-[84px] group" role="menuitem" tabindex="1"><a class="mx-4 my-1 block rounded-md border-2 border-solid border-transparent px-4 lg:m-0 lg:rounded-none lg:p-0 lg:focus:border-2" href="#"><div class="relative flex items-center justify-between "><span class="relative p-2 font-poppins text-[16px] lg:mt-[5px] group-hover:text-electric-purple-500">Solutions</span><svg width="13" height="13" role="img" aria-label="chevron-down" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:absolute lg:-bottom-0 lg:left-[40%]"><use href="#chevron-down"></use></svg></div></a></div><div class="flex items-center border-b md:px-0 lg:h-[84px] lg:border-none lg:px-3 2xl:px-2 h-[84px] group" role="menuitem" tabindex="2"><a class="mx-4 my-1 block rounded-md border-2 border-solid border-transparent px-4 lg:m-0 lg:rounded-none lg:p-0 lg:focus:border-2" href="#"><div class="relative flex items-center justify-between "><span class="relative p-2 font-poppins text-[16px] lg:mt-[5px] group-hover:text-electric-purple-500">Resources</span><svg width="13" height="13" role="img" aria-label="chevron-down" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:absolute lg:-bottom-0 lg:left-[40%]"><use href="#chevron-down"></use></svg></div></a></div><div class="flex items-center border-b md:px-0 lg:h-[84px] lg:border-none lg:px-3 2xl:px-2 h-[84px] group" role="menuitem" tabindex="3"><a class="mx-4 my-1 block rounded-md border-2 border-solid border-transparent px-4 lg:m-0 lg:rounded-none lg:p-0 lg:focus:border-2" href="/pricing/"><div class="relative flex items-center justify-between "><span class="relative p-2 font-poppins text-[16px] lg:mt-[5px] group-hover:text-electric-purple-500">Pricing</span></div></a></div><div class="flex items-center border-b md:px-0 lg:h-[84px] lg:border-none lg:px-3 2xl:px-2 h-[84px] group" role="menuitem" tabindex="4"><a class="mx-4 my-1 block rounded-md border-2 border-solid border-transparent px-4 lg:m-0 lg:rounded-none lg:p-0 lg:focus:border-2" href="#"><div class="relative flex items-center justify-between "><span class="relative p-2 font-poppins text-[16px] lg:mt-[5px] group-hover:text-electric-purple-500"> Company</span><svg width="13" height="13" role="img" aria-label="chevron-down" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:absolute lg:-bottom-0 lg:left-[40%]"><use href="#chevron-down"></use></svg></div></a></div></div><div class="ml-auto w-full lg:w-auto"><ul class="flex flex-col items-center lg:flex-row"><li class="w-full border-b border-neutral-200 lg:w-auto lg:border-none"><a class="mx-4 my-1 block px-4 py-2 hover:text-electric-purple-500 lg:m-0" href="/contact/"><span class="font-poppins text-[16px] lg:hidden xl:block">Contact us</span><svg width="20" height="20" role="img" aria-label="email" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:block xl:hidden"><use href="#email"></use></svg></a></li><li class="w-full border-b border-neutral-200 lg:w-auto lg:border-none"><a href="https://cockroachlabs.cloud/" target="_blank" rel="noreferrer" class="mx-4 my-1 block px-4 py-2 hover:text-electric-purple-500 lg:m-0"><span class="font-poppins text-[16px] lg:hidden xl:block">Sign in</span><svg width="20" height="20" role="img" aria-label="circle-user" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="hidden lg:block xl:hidden"><use href="#circle-user"></use></svg></a></li><li class="w-full border-b border-neutral-200 lg:w-auto lg:border-none"><button type="button" class="mx-4 my-1 flex items-center px-4 hover:text-electric-purple-500 md:py-2 lg:m-0"><svg width="18" height="18" role="img" aria-label="search" xmlns="http://www.w3.org/2000/svg" fill="currentColor"><use href="#search"></use></svg></button></li><li class="hidden lg:block"><a href="https://cockroachlabs.cloud/signup?referralId=cc_nav_global"><button class="inline-flex justify-center items-center gap-2 disabled:cursor-not-allowed border-solid border-electric-purple-500 bg-electric-purple-500 text-white active:border-electric-purple-100 active:bg-electric-purple-100 active:text-white px-4 py-1 text-md leading-5 rounded-full border-2 font-poppins hover:bg-electric-purple-500 hover:text-white lg:mt-[5px]">Try for free</button></a></li></ul></div></div></nav></div></div></div></div><div class="blog-template"><div class="py-3 contain-layout relative bg-no-repeat bg-center bg-cover"><section class="mx-auto px-3 xl:max-w-[1140px] 2xl:max-w-[1320px] py-0 sm:py-0 lg:py-0"><nav class="text-sm false" aria-label="Breadcrumb"><ol class="inline-flex list-none p-0"><li class="flex items-center"><a href="/">Home</a><span class="mx-1">/</span></li><li class="flex items-center"><a href="/resources/">Resources</a><span class="mx-1">/</span></li><li class="flex items-center"><a href="/blog/">Back to Blog</a></li></ol></nav><script type="application/ld+json">{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.cockroachlabs.com/"},{"@type":"ListItem","position":2,"name":"Resources","item":"https://www.cockroachlabs.com/resources/"},{"@type":"ListItem","position":3,"name":"Blog","item":"https://www.cockroachlabs.com/blog/"},{"@type":"ListItem","position":4,"name":"A brief history of high availability","item":"https://www.cockroachlabs.com/blog/brief-history-high-availability"}]}</script></section></div><div class="fixed left-0 top-[45px] z-40 h-[7px] w-full shrink-0 bg-[#F5F5F5] lg:top-[82px]"><div id="progressBar" class="from-yellow-400 via-pink-500 to-purple-500 animate-progress fixed left-0 top-[45px] z-[999] h-[7px] shrink-0 bg-[#000] bg-custom-gradient lg:top-[84px]"></div></div><script id="structured-data-blog" type="application/ld+json">{"@context":"https://schema.org","@type":"TechArticle","headline":"A brief history of high availability","description":"The perennial question of homo sapiens is, 'How did we get here?' Today we're going to take a crack at answering that: where 'here' is defined as 'high availability for web services'.","author":[{"@type":"Person","name":" Jessica Edwards","url":"/author/jessica-edwards","image":{"@type":"ImageObject","url":"https://images.ctfassets.net/00voh0j35590/6tWdomQQHSO4QvtVE47p6o/6b2a82ca2c15076d4736546af8d28dae/jessica_headshot.jpeg"}},{"@type":"Person","name":"Sean Loiselle","url":"/author/sean-loiselle"}],"publisher":{"@type":"Organization","name":"Cockroach Labs","logo":{"@type":"ImageObject","url":"https://www.cockroachlabs.com/favicon.ico"}},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.cockroachlabs.com/blog/brief-history-high-availability"},"datePublished":"2023-03-23T00:00:00.000Z","dateModified":"2025-01-23T00:00:00.000Z"}</script><div class="contain-layout relative bg-no-repeat bg-center bg-cover"><section class="mx-auto px-3 max-w-full lg:pt-16 pt-6 lg:pb-16 pb-6 no-padding relative overflow-hidden bg-gradient-to-b from-[#bea7ffb3] to-white bg-contain bg-top bg-no-repeat"><img alt="blog-banner" loading="lazy" width="2048" height="350" decoding="async" data-nimg="1" class="absolute z-0 size-full object-contain object-top" style="color:transparent" srcSet="/_next/image/?url=%2Fimages%2Fblog-default-wing.png&amp;w=2048&amp;q=75 1x, /_next/image/?url=%2Fimages%2Fblog-default-wing.png&amp;w=3840&amp;q=75 2x" src="/_next/image/?url=%2Fimages%2Fblog-default-wing.png&amp;w=3840&amp;q=75"/><div class="contain-layout relative bg-no-repeat bg-center bg-cover"><section class="xl:max-w-[1140px] 2xl:max-w-[1320px] relative m-auto max-w-screen-xl px-3 py-16 sm:px-3 lg:px-3 lg:py-16"><h1 class="mb-8 text-center text-display-md font-semibold lg:text-display-lg">A brief history of high availability</h1><div class="flex items-center justify-center gap-4 [&amp;&gt;div]:after:ml-4 [&amp;&gt;div]:after:content-[&#x27;|&#x27;] last:[&amp;&gt;div]:after:hidden"><a class="flex items-center" href="/author/jessica-edwards/"><div><img alt="jessica headshot" loading="lazy" width="330" height="330" decoding="async" data-nimg="1" class="mr-4 max-h-[40px] max-w-[40px] rounded-full object-cover" style="color:transparent" srcSet="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F6tWdomQQHSO4QvtVE47p6o%2F6b2a82ca2c15076d4736546af8d28dae%2Fjessica_headshot.jpeg&amp;w=384&amp;q=75 1x, /_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F6tWdomQQHSO4QvtVE47p6o%2F6b2a82ca2c15076d4736546af8d28dae%2Fjessica_headshot.jpeg&amp;w=750&amp;q=75 2x" src="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F6tWdomQQHSO4QvtVE47p6o%2F6b2a82ca2c15076d4736546af8d28dae%2Fjessica_headshot.jpeg&amp;w=750&amp;q=75"/></div><div><p class="text-electric-purple-500"> Jessica Edwards</p></div></a><a class="flex items-center" href="/author/sean-loiselle/"><div><p class="text-electric-purple-500">Sean Loiselle</p></div></a></div><div class="mt-4 flex flex-col items-center justify-center gap-1 sm:flex-row sm:gap-4"><div><p>Last updated on <!-- -->January 23, 2025</p></div><span class="hidden sm:block">|</span><div><p class="flex items-center"><svg width="15" height="15" role="img" aria-label="clock" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="mr-2"><use href="#clock"></use></svg>0<!-- --> minute read</p></div></div></section></div></section></div><div class="contain-layout relative bg-no-repeat bg-center bg-cover"><section class="xl:max-w-[1140px] 2xl:max-w-[1320px] relative m-auto max-w-screen-xl px-3 py-16 sm:px-3 lg:px-3 lg:pb-36 lg:pt-16"><div class="flex flex-col gap-8 lg:flex-row lg:gap-0"><div class="w-full lg:w-1/4"><div class="sticky top-[168px] max-w-full overflow-x-hidden p-4 xl:top-32"><ul></ul></div></div><div class="w-full lg:w-1/2 lg:px-8"><article class="blog-content null"><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/IjA2FGDgYRrhqMEUWr2xk/4fd0665b0db8270245d82c9ff55efcdf/DataReplication_ChristinaChung-1.avif"><img alt="DataReplication ChristinaChung-1" loading="lazy" width="1185" height="413" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/IjA2FGDgYRrhqMEUWr2xk/4fd0665b0db8270245d82c9ff55efcdf/DataReplication_ChristinaChung-1.avif"/></a></div></div><p>I once went to a website that had “hours of operation,” and was only “open” when its brick and mortar counterpart had its lights on. I felt perplexed and a little frustrated; computers are capable of running all day every day, so why shouldn’t they? I’d been habituated to the internet’s incredible availability guarantees.</p><p>However, before the internet, 24/7 high availability wasn’t “a thing.” Availability was desirable, but not something to which we felt fundamentally entitled. We used computers only when we needed them; they weren’t waiting idly by on the off-chance a request came by. As the internet grew, those previously uncommon requests at 3am local time became prime business hours partway across the globe, and making sure that a computer could facilitate the request was important.</p><p>Many systems, though, relied on only one computer to facilitate these requests — a single point of failure — which we all know is a story that doesn’t end well. To keep things up and running, we needed to distribute the load among multiple computers that could fulfill our needs. However, distributed computation, for all its well-known upsides, has sharp edges: in particular, synchronization and tolerating partial failures (fault tolerance) within a system. Each generation of engineers has iterated on these solutions to fit the needs of their time.</p><p>How distribution came to databases is of particular interest because it is a difficult problem that has been much slower to develop than other areas of computer science. Certainly, software tracked the results of some distributed computation in a local database, but the state of the database itself was kept on a single machine. Why? Replicating state across machines is hard.</p><p>In this post, we take a look at how distributed databases have historically handled fault tolerance and—at a high level—what high availability looks like. We also walk through different types of high availability systems and address the <a href="https://www.cockroachlabs.com/guides/do-more-with-less-with-distributed-sql/" target="_blank" rel="noopener noreferrer">operational costs (and financial costs) of architectures that are vulnerable to downtime</a>.</p><h2 id="Fault-Tolerance-vs.-High-Availability">Fault Tolerance vs. High Availability<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p>Before we dive deep into the colorful history of high availability I want to clarify the distinction between these two terms that are often thought of as synonyms. While they are very closely related, they are not the same.</p><p>Fault tolerance implies zero service interruptions. If there is a failure somewhere the system will instantly switch to the backup solution and service will continue without interruption. High availability, on the other hand, implies that services are, well, <i>highly available but not always available</i>. <a href="https://www.cockroachlabs.com/blog/what-is-fault-tolerance/" target="_blank" rel="noopener noreferrer">A system can be highly available but not fault tolerant</a>. I generally consider high availability to be an aspect of fault tolerance. In that, it addresses a certain type of “fault” (availability), but doesn’t necessarily talk about other aspects.</p><p>This is somewhat of a contrived example, but basically everyone watches streaming content, so let’s consider a digital rights management service that determines whether a viewer can watch a particular video. The service could be configured to be highly available, in that it will always serve and return queries. However, it may not handle certain backend data correctly and get into a state where it returns errors, or denies all requests. In this case, it would be highly available (it is reachable and is returning an answer), but it is not fault tolerant, because something in the system has caused it to misbehave.</p><p>The caveat with this example is that there’s a fine line between a “bug” and fault tolerance. But the idea of fault tolerance is that the system can handle unexpected events gracefully and continue providing an excellent user experience. (If this example is interesting to you, I recommend taking a look at how <a href="https://netflix.github.io/chaosmonkey/" target="_blank" rel="noopener noreferrer">Netflix’s chaos monkey</a> randomly terminates instances in production to ensure that engineers implement their services to be resilient to instance failures).</p><p>Okay, let’s get into some highly available database examples.</p><h2 id="What-are-the-Types-of-High-Availability-Databases?">What are the Types of High Availability Databases?<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p>High availability databases generally fall into two categories, with a third category becoming more common:</p><ol><li><p><b>Active-passive databases</b>: Where a database has an active node that processes requests with a hot spare that is ready to go in a disaster</p></li><li><p><b>Active-active databases</b>: Where a database has active nodes that shard data and perform writes to the database</p></li><li><p><b>Multi-active databases</b>: Where a database has at least three active nodes, each of which can perform reads and writes for any data in the cluster without generating conflicts.</p></li></ol><h2 id="What-is-Active-Passive-Availability?">What is Active-Passive Availability?<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p><i>Active-passive availability means the database has an active node that processes requests with a hot spare that is ready to go in a disaster. The active-passive availability model works on the two-node concept of one node receiving all requests that it then replicates to its follower.</i></p><p>In the days of yore, databases ran on single machines. There was only one node and it handled all reads and all writes. There was no such thing as a “partial failure”; the database was either up or down.</p><p>Total failure of a single database was a two-fold problem for the internet; first, computers were being accessed around the clock, so downtime was more likely to directly impact users; second, by placing computers under constant demand, they were more likely to fail. The obvious solution to this problem is to have more than one computer that can handle the request, and this is where the story of distributed databases truly begins.</p><p>Living in a single-node world, the most natural solution was to continue letting a single node serve reads and writes and simply sync its state onto a secondary, passive machine—and thus, Active-Passive replication was born.
</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/K7sk3YRaL8wYEtKiITX96/2d1a88cd29b8e87cbba27500793ae863/active-passive.png"><img alt="active-passive" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/K7sk3YRaL8wYEtKiITX96/2d1a88cd29b8e87cbba27500793ae863/active-passive.png"/></a></div></div><p>Active-Passive was an early step towards high availability with an up-to-date backup. In cases where the active node failed, you could simply start directing traffic to the passive node, thereby promoting it to being active. Whenever you could, you would replace the downed server with a new passive machine (and hope the active one did not fail in the interim).</p><p></p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/2t8Aa7Rb2oIa25t0Zc3c9A/0ae7f4c00832945f1e1a9632b5dc737c/active-passive-failover.png"><img alt="active-passive-failover" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/2t8Aa7Rb2oIa25t0Zc3c9A/0ae7f4c00832945f1e1a9632b5dc737c/active-passive-failover.png"/></a></div></div><p>At first, replication from the active to the passive node was a synchronous procedure, i.e., transformations were not committed until the Passive node acknowledged them. However, it was unclear what to do if the passive node went down. It certainly didn’t make sense for the entire system to go down if the backup system wasn’t available—but with synchronous replication, that’s what would happen.</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/VTKZ10htttxE8c6wYDh68/fed3f72545b1cc5a9a6031affb6e5f30/active-passive-passive-down.png"><img alt="active-passive-passive-down" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/VTKZ10htttxE8c6wYDh68/fed3f72545b1cc5a9a6031affb6e5f30/active-passive-passive-down.png"/></a></div></div><p>To further improve availability, data could instead be replicated asynchronously. While its architecture looks the same, it was capable of handling either the active or the passive node going down without impacting the database’s availability.</p><p>While asynchronous Active-Passive was another step forward, there were still significant downsides:</p><ul><li><p>When the active node died, any data that wasn’t yet replicated to the passive node could be lost—despite the fact that the client was led to believe the data was fully committed.</p></li><li><p>By relying on a single machine to handle traffic, you were still bound to the maximum available resources of a single machine.</p></li></ul><h2 id="Chasing-Five-9s-High-Availability:-Scale-to-many-machines">Chasing Five 9s High Availability: Scale to many machines<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p>As the Internet proliferated, business&#x27; needs grew in scale and complexity. For databases this meant that they needed the ability to handle more traffic than any single node could handle, and that providing “always on” high availability became a mandate.</p><p>Given that swaths of engineers now had experience working on other distributed technologies, it was clear that databases could move beyond single-node Active-Passive setups and distribute a database across many machines.</p><h3 id="Sharding">Sharding<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h3><p>Again, the easiest place to start is adapting what you currently have, so engineers adapted Active-Passive replication into something more scalable by developing sharding.</p><p>In this scheme, you split up a cluster’s data by some value (such as a number of rows or unique values in a primary key) and distributed those segments among a number of sites, each of which has an Active-Passive pair. You then add some kind of routing technology in front of the cluster to direct clients to the correct site for their requests.</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/XK6aVe3XVzf93wyAZunYo/cf556af9bd4ee16196e04f60096275b9/sharded.png"><img alt="sharded" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/XK6aVe3XVzf93wyAZunYo/cf556af9bd4ee16196e04f60096275b9/sharded.png"/></a></div></div><p>Sharding lets you distribute your workload among many machines, improving throughput, as well as creating even greater resilience by tolerating a greater number of partial failures and eliminating single points of failure.</p><p>Despite these upsides, sharding a system was complex and posed a substantial operational burden on teams. The deliberate accounting of shards could grow so onerous that the routing ended up creeping into an application’s business logic. And worse, if you needed to modify the way a system was sharded (such as a schema change), it often posed a significant (or even monumental) amount of engineering to achieve.</p><p>Single-node Active-Passive systems had also provided transactional support (even if not strong consistency). However, the difficulty of coordinating transactions across shards was so knotted and complex, many sharded systems decided to forgo them completely.</p><p><!--$!--><template data-dgst="BAILOUT_TO_CLIENT_SIDE_RENDERING"></template><!--/$-->
</p><h2 id="What-is-Active-Active-Availability?">What is Active-Active Availability?<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p><i>Active-active availability means a database has at least two active nodes that shard data and perform writes to the database. Active-active availability represents an evolution from active-passive, enabling databases to scale beyond single machines by letting nodes in a cluster serve reads and writes.</i></p><p>Given that sharded databases were difficult to manage and not fully featured, engineers began developing systems that would at least solve one of the problems. What emerged were systems that still didn’t support transactions, but were dramatically easier to manage. With the increased demand on applications&#x27; uptime, it was a sensible decision to help teams meet their SLAs.</p><p>The motivating idea behind these systems was that each site could contain some (or all) of a cluster’s data and serve reads and writes for it. Whenever a node received a write it would propagate the change to all other nodes that would need a copy of it. To handle situations where two nodes received writes for the same key, other nodes&#x27; transformations were fed into a conflict resolution algorithm before committing. Given that each site was “active”, it was dubbed Active-Active.</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/56TAQs94PfEpjs0j97yShB/0a0f3dec393c3affb61fb313cba64c08/active-active.png"><img alt="active-active" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/56TAQs94PfEpjs0j97yShB/0a0f3dec393c3affb61fb313cba64c08/active-active.png"/></a></div></div><p>Because each server could handle reads and writes for all of its data, sharding was easier to accomplish algorithmically and made deployments easier to manage.</p><p>In terms of availability, Active-Active was excellent. If a node failed, clients just needed to be redirected to another node that did contain the data. As long as a single replica of the data was live, you could serve both reads and writes for it.</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/6XafJGMBKxlByUNAaDDLDp/9074295eb967cbf079a6ed8d1604957e/active-active-failover.png"><img alt="active-active-failover" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/6XafJGMBKxlByUNAaDDLDp/9074295eb967cbf079a6ed8d1604957e/active-active-failover.png"/></a></div></div><p>While this scheme is fantastic for high availability, its design is fundamentally at odds with consistency and data correctness. Because each site can handle writes for a key (and would in a failover scenario), it’s incredibly difficult to keep data totally synchronized as it is being processed. Instead, the approach is generally to mediate conflicts between sites through the conflict resolution algorithm that makes coarse-grained decisions about how to “smooth out” inconsistencies.</p><p>Because that resolution is done post hoc, after a client has already received an answer about a procedure—and has theoretically executed other business logic based on the response—it’s easy for active-active replication to generate anomalies in your data.</p><p>Given the premium on uptime, though, the cost of downtime was deemed greater than the cost of potential anomalies, so Active-Active became the dominant replication type.</p><h2 id="Correctness-at-Scale:-Consensus-and-Multi-Active-Availability">Correctness at Scale: Consensus and Multi-Active Availability<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p>Active-Active seemed like it addressed the major problem facing infrastructure — providing high availability. But it had only done so by forgoing transactions, which left systems that also required strong consistency without a compelling choice.</p><p>For example, Google used a massive and complex sharded MySQL system for its advertising business, which heavily relied on SQL’s expressiveness to arbitrarily query the database. Because these queries often relied on secondary indexes to improve performance, they had to be kept totally consistent with the data they were derived from.</p><p>Eventually, the system grew large enough in size that it began causing problems for sharded MySQL (Spencer Kimball discusses his first-hand experience with sharded MySQL and AdWords on <a href="https://youtu.be/NMlabY4-eE0?feature=shared" target="_blank" rel="noopener noreferrer">this podcast</a>), so their engineers began imagining how they could solve the problem of having both a massively scalable system that could also offer the strong consistency their business required. Active-Active’s lack of transactional support meant it wasn’t an option, so they had to design something new. What they ended up with was a system based around consensus replication, which would guarantee consistency, but would also provide high availability.</p><p>Using consensus replication, writes are proposed to a node, and are then replicated to some number of other nodes. Once a majority of the nodes have acknowledged the write, it can be committed.</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/59VglwC0F69o4R0nzofm9Z/6ca3c56b6b60e5d721a90c44572e2919/multi-active.png"><img alt="multi-active" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/59VglwC0F69o4R0nzofm9Z/6ca3c56b6b60e5d721a90c44572e2919/multi-active.png"/></a></div></div><h3 id="Consensus-and-High-Availability">Consensus and High Availability<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h3><p>The lynch-pin notion here is that consensus replication lies in a sweet spot between synchronous and asynchronous replication: you need some arbitrary number of nodes to behave synchronously, but it doesn’t matter which nodes those are. This means the cluster can tolerate a minority of nodes going down without impacting the system’s availability. (Caveats made for handling the downed machines&#x27; traffic, etc.)</p><div class="blog-image"><div class="-mt-6 mb-8"><a href="https://images.ctfassets.net/00voh0j35590/3YEcB4CnQu5bSGIcWS4qHY/255ac365e3ec8232effdf55162315dc3/multi-active-failover.png"><img alt="multi-active-failover" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="min-w-hit min-h-hit" style="color:transparent" src="https://images.ctfassets.net/00voh0j35590/3YEcB4CnQu5bSGIcWS4qHY/255ac365e3ec8232effdf55162315dc3/multi-active-failover.png"/></a></div></div><p>The cost of consensus, though, is that it requires nodes to communicate with others to perform writes. While there are steps you can take to reduce the latency incurred between nodes, such as placing them in the same <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/" target="_blank" rel="noopener noreferrer">availability zone</a>, this runs into trade-offs with high availability.</p><p>For example, if all of the nodes are in the same datacenter, it’s fast for them to communicate with one another, but you cannot survive an entire datacenter going offline. Spreading your nodes out to multiple datacenters may increase the latency required for writes, but can improve your availability by letting an entire datacenter going offline without bringing down your application.</p><h2 id="What-is-Multi-Active-Availability?">What is Multi-Active Availability?<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><blockquote><p><i>Multi-active availability requires that a database has at least three active nodes, each of which can perform reads and writes for any data in the cluster without generating conflicts.</i></p></blockquote><p>CockroachDB implements much of the learnings from the <a href="https://static.googleusercontent.com/media/research.google.com/en//archive/spanner-osdi2012.pdf" target="_blank" rel="noopener noreferrer">Google Spanner paper</a> (though, notably, without requiring atomic clocks), including those features beyond consensus replication that make availability much simpler. To describe how this works and differentiate it from Active-Active, we’ve coined the term Multi-Active Availability.</p><h3 id="Active-Active-vs.-Multi-Active">Active-Active vs. Multi-Active<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h3><p>Active-Active achieves availability by letting any node in your cluster serve reads and writes for its keys, but propagates any changes it accepts to other nodes only <i>after</i> committing writes.</p><p>Multi-Active Availability, on the other hand, <a href="https://www.cockroachlabs.com/docs/stable/architecture/replication-layer" target="_blank" rel="noopener noreferrer">lets any node serve reads and writes, but ensures that a majority of replicas are kept in sync on writes</a>, and only <a href="https://www.cockroachlabs.com/docs/stable/architecture/replication-layer#leases" target="_blank" rel="noopener noreferrer">serves reads from replicas of the latest version.</a></p><p>In terms of high availability, Active-Active only requires a single replica to be available to serve both reads of writes, while Multi-Active requires a majority of replicas to be online to achieve consensus (which still allows for partial failures within the system).</p><p>Downstream of these databases&#x27; availability, though, is a difference of consistency. Active-Active databases work hard to accept writes in most situations, but then don’t make guarantees about the ability for a client to then read that data now or in the future. On the other hand, Multi-Active databases accept writes only when it can guarantee that the data can later be read in a way that’s consistent.</p><h2 id="Where-to-go-from-here?">Where to go from here?<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h2><p>Over the last 30 years, database replication and availability have taken major strides and now supports globe-spanning deployments that feel like they never go down. The field’s first forays laid important groundwork through Active-Passive replication but eventually, we needed better availability and greater scale.</p><p>From there, the industry has developed two predominant paradigms of databases: Active-Active for applications whose primary concern is accepting writes quickly, and Multi-Active for those that require consistency.</p><p>May we all look forward to the day when we can harness quantum entanglement and move to the next paradigm in managing distributed state.</p><p>If defining the next phase of database replication and availability is your coffee-break daydream, then check out our open positions <a href="https://cockroa.ch/eng_hiring" target="_blank" rel="noopener noreferrer">here</a>.</p><h3 id="Further-reading">Further reading<span class="relative ml-2 inline-block size-4 hover:size-5"><img src="/images/icons/copy-icon.svg" alt="Copy Icon" style="cursor:pointer"/></span></h3><ul><li><p><a href="https://www.cockroachlabs.com/blog/how-to-reduce-database-costs/" target="_blank" rel="noopener noreferrer">Building fault-tolerant applications while improving operational efficiency</a></p></li><li><p><a href="https://www.cockroachlabs.com/blog/5-reasons-to-build-multi-region-application-architecture/" target="_blank" rel="noopener noreferrer">5 reasons to build using a multi-region architecture</a></p></li><li><p><a href="https://www.cockroachlabs.com/docs/stable/demo-fault-tolerance-and-recovery" target="_blank" rel="noopener noreferrer">Fault tolerance and recovery demo</a></p></li><li><p><a href="https://www.cockroachlabs.com/blog/demand-zero-rpo/" target="_blank" rel="noopener noreferrer">How to get to near-zero RPO/RTO</a></p></li></ul><p><i>Illustration by </i><a href="http://www.christina-chung.com/" target="_blank" rel="noopener noreferrer"><i>Christina Chung</i></a></p></article><div class="mt-8 flex flex-wrap items-center gap-2"><div class="rounded-full border border-[#E2E2F5] bg-[#E9F4FF] px-4 text-[#9458BD]">always-on database</div><div class="rounded-full border border-[#E2E2F5] bg-[#E9F4FF] px-4 text-[#9458BD]">high availability database</div><div class="rounded-full border border-[#E2E2F5] bg-[#E9F4FF] px-4 text-[#9458BD]">active-active</div></div></div><div class="w-full lg:w-1/4"><div class="flex flex-col gap-0 sm:flex-row sm:gap-8 lg:flex-col lg:gap-0"><div class="share-container lg:max-h-[90vh]"><div class="w-full"><p class="font-open-sans font-semibold uppercase">Share</p><div class="mt-4 rounded rounded-b-none border border-solid border-[#D5D5D5] bg-[#F5F5F5] p-4"><div class="flex items-center justify-center self-end md:mb-0 md:self-auto"><button aria-label="Share on X" class="react-share__ShareButton w-14" style="background-color:transparent;border:none;padding:0;display:inline-flex;border-radius:0;outline-offset:2px;font:inherit;color:inherit;cursor:pointer" type="button"><div class="flex h-10 w-full cursor-pointer flex-nowrap items-center justify-center border bg-white hover:bg-neutral-600 border-lightgray-300 border-l-1 rounded-l-md"><svg width="20" height="20" role="img" aria-label="twitter-x" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-neutral-700"><use href="#twitter-x"></use></svg></div></button><button aria-label="Share on Facebook" class="react-share__ShareButton w-14" style="background-color:transparent;border:none;padding:0;display:inline-flex;border-radius:0;outline-offset:2px;font:inherit;color:inherit;cursor:pointer" type="button"><div class="flex h-10 w-full cursor-pointer flex-nowrap items-center justify-center border border-l-0 bg-white hover:bg-neutral-600 border-lightgray-300"><svg width="20" height="20" role="img" aria-label="facebook-f" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-neutral-700"><use href="#facebook-f"></use></svg></div></button><button aria-label="Share on LinkedIn" class="react-share__ShareButton w-14" style="background-color:transparent;border:none;padding:0;display:inline-flex;border-radius:0;outline-offset:2px;font:inherit;color:inherit;cursor:pointer" type="button"><div class="flex h-10 w-full cursor-pointer flex-nowrap items-center justify-center border border-l-0 bg-white hover:bg-neutral-600 border-lightgray-300"><svg width="20" height="20" role="img" aria-label="linkedin-in" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-neutral-700"><use href="#linkedin-in"></use></svg></div></button><button aria-label="Share by email" class="react-share__ShareButton w-14" style="background-color:transparent;border:none;padding:0;display:inline-flex;border-radius:0;outline-offset:2px;font:inherit;color:inherit;cursor:pointer" type="button"><div class="flex h-10 w-full cursor-pointer flex-nowrap items-center justify-center border border-l-0 bg-white hover:bg-neutral-600 border-lightgray-300"><svg width="20" height="20" role="img" aria-label="email" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-neutral-700"><use href="#email"></use></svg></div></button><button aria-label="Share on Reddit" class="react-share__ShareButton w-14" style="background-color:transparent;border:none;padding:0;display:inline-flex;border-radius:0;outline-offset:2px;font:inherit;color:inherit;cursor:pointer" type="button"><div class="flex h-10 w-full cursor-pointer flex-nowrap items-center justify-center border border-l-0 bg-white hover:bg-neutral-600 border-lightgray-300 rounded-r-md"><svg width="20" height="20" role="img" aria-label="reddit" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-neutral-700"><use href="#reddit"></use></svg></div></button></div></div><div class="rounded rounded-t-none border border-t-0 border-solid border-[#D5D5D5] bg-[#F5F5F5] p-4 text-center"><p class="-mb-3 font-open-sans font-semibold">Subscribe to our newsletter</p><div class="[&amp;&gt;div]:w-full [&amp;&gt;div]:p-0"><div class="shadow flex max-w-lg flex-col rounded-md px-2 py-5 text-center sm:px-3 sm:py-12 bg-gray-1100"><form class="pt-3 blogNewsletter" id="mktoForm_1084"></form></div><p class="mt-4 font-open-sans text-[14px] leading-4">We will email you updates about CockroachDB. You can<!-- --> <a class="font-semibold text-electric-purple-500" href="/email-preferences/">unsubscribe</a> <!-- -->at any time. Learn more about our privacy practices<!-- --> <a class="font-semibold text-electric-purple-500" href="/privacy/">here.</a></p></div></div></div><div class="mt-8 w-full rounded rounded-b-none border border-solid border-[#D5D5D5] bg-[#F5F5F5] p-4"><p class="mb-4 mt-1 text-[24px] font-semibold leading-6 text-[#482e8e]">Recommended</p><ol class="mx-0 mt-3 space-y-2 px-0 font-[15px] font-medium"><li class="mb-2 border-b-2 pb-2"><a href="https://www.cockroachlabs.com/guides/application-modernization/?guide_type=default" target="_blank" rel="noopener noreferrer" class="hover:underline">Modernize Applications and Infrastructure with CockroachDB</a></li><li class="mb-2 border-b-2 pb-2"><a href="https://www.cockroachlabs.com/guides/state-of-ai/?guide_type=default" target="_blank" rel="noopener noreferrer" class="hover:underline">The State of AI Infrastructure 2026</a></li><li class="mb-2 border-b-2 pb-2"><a href="https://www.cockroachlabs.com/guides/3-ai-use-cases/?guide_type=default" target="_blank" rel="noopener noreferrer" class="hover:underline">Three AI Use Cases, One Database: IAM, Metadata Management, and Vector Search at Scale</a></li><li class="mb-2 border-b-2 pb-2"><a href="https://www.cockroachlabs.com/guides/architects-playbook-ai-ready-systems/?guide_type=default" target="_blank" rel="noopener noreferrer" class="hover:underline">The Architect’s Playbook for Building AI-Ready Systems</a></li><li class="mb-2 border-b-2 pb-2"><a href="https://www.cockroachlabs.com/compare/amazon-aurora-vs-cockroachdb/?guide_type=default" target="_blank" rel="noopener noreferrer" class="hover:underline">CockroachDB vs Amazon Aurora and DSQL</a></li></ol><div class="mt-4"><a class="inline-flex items-center gap-2 font-medium text-electric-purple-500" href="/guides/">More resources<svg width="18" height="18" role="img" aria-label="long-arrow-right" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-electric-purple-500 text-electric-purple-500"><use href="#long-arrow-right"></use></svg></a></div></div></div></div></div></div></section></div><div class="bg-lightgray-200"><div class="contain-layout relative bg-no-repeat bg-center bg-cover"><section class="mx-auto px-3 xl:max-w-[1140px] 2xl:max-w-[1320px] lg:pt-16 pt-6 lg:pb-16 pb-6"><div><div class="mb-7 flex justify-between"><p class="text-display-xs font-semibold">Keep reading</p><a class="ml-5 flex gap-3 text-end font-medium text-electric-purple-500" href="/blog/">View all posts<svg width="24" height="24" role="img" aria-label="long-arrow-right" xmlns="http://www.w3.org/2000/svg" fill="currentColor" class="fill-electric-purple-500 text-electric-purple-500"><use href="#long-arrow-right"></use></svg></a></div><div class="-mx-3 flex flex-wrap"><div class="w-full p-3 sm:w-1/2 lg:w-1/3"><a class="group flex h-full flex-col rounded border border-solid border-neutral-400 shadow-lg hover:shadow-2xl hover:outline hover:outline-1 hover:outline-electric-purple-500" href="/blog/sql-user-lifecycle-management-automation/"><div class="h-36 min-h-[230px] bg-lightgray-100"><img alt="CockroachDB Automate SQL User Lifecycle Management BLOG" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="size-full rounded-t object-cover" style="color:transparent" srcSet="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F54JK93QnOOzLaAxPLugelQ%2F37df4b0d5eeb453770c7e9b3ef653cad%2FCockroachDB_Automate_SQL_User_Lifecycle_Management_BLOG.png&amp;w=1920&amp;q=75 1x, /_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F54JK93QnOOzLaAxPLugelQ%2F37df4b0d5eeb453770c7e9b3ef653cad%2FCockroachDB_Automate_SQL_User_Lifecycle_Management_BLOG.png&amp;w=3840&amp;q=75 2x" src="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F54JK93QnOOzLaAxPLugelQ%2F37df4b0d5eeb453770c7e9b3ef653cad%2FCockroachDB_Automate_SQL_User_Lifecycle_Management_BLOG.png&amp;w=3840&amp;q=75"/></div><div class="flex h-full flex-col items-start justify-between gap-5 px-5 py-6"><div><p class="text-base font-semibold leading-5 group-hover:text-electric-purple-500">How Does CockroachDB Automate SQL User Lifecycle Management?</p><p class="my-4 line-clamp-5 leading-5">Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory. </p></div><button class="inline-flex justify-center items-center gap-2 disabled:cursor-not-allowed border border-solid border-electric-purple-500 bg-electric-purple-500 text-white hover:bg-white hover:text-electric-purple-500 active:border-electric-purple-100 active:bg-electric-purple-100 active:text-white px-4 py-1 text-md leading-5 rounded-full">Read now</button></div></a></div><div class="w-full p-3 sm:w-1/2 lg:w-1/3"><a class="group flex h-full flex-col rounded border border-solid border-neutral-400 shadow-lg hover:shadow-2xl hover:outline hover:outline-1 hover:outline-electric-purple-500" href="/blog/core-banking-modernization-temenos-cockroachdb/"><div class="h-36 min-h-[230px] bg-lightgray-100"><img alt="CockroachDB Core Banking Modernization with Temenos Core BLOG" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="size-full rounded-t object-cover" style="color:transparent" srcSet="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F2aDUge47uqIeN7wvNB43N3%2F7f89ce8f8d866481e0d22e840ce9745e%2FCockroachDB_Core_Banking_Modernization_with_Temenos_Core_BLOG.png&amp;w=1920&amp;q=75 1x, /_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F2aDUge47uqIeN7wvNB43N3%2F7f89ce8f8d866481e0d22e840ce9745e%2FCockroachDB_Core_Banking_Modernization_with_Temenos_Core_BLOG.png&amp;w=3840&amp;q=75 2x" src="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F2aDUge47uqIeN7wvNB43N3%2F7f89ce8f8d866481e0d22e840ce9745e%2FCockroachDB_Core_Banking_Modernization_with_Temenos_Core_BLOG.png&amp;w=3840&amp;q=75"/></div><div class="flex h-full flex-col items-start justify-between gap-5 px-5 py-6"><div><p class="text-base font-semibold leading-5 group-hover:text-electric-purple-500">Core Banking Modernization with Temenos Core and CockroachDB </p><p class="my-4 line-clamp-5 leading-5">Banking has become an always-on business. Customers expect instant payments, accurate balances, and continuous access to financial services...</p></div><button class="inline-flex justify-center items-center gap-2 disabled:cursor-not-allowed border border-solid border-electric-purple-500 bg-electric-purple-500 text-white hover:bg-white hover:text-electric-purple-500 active:border-electric-purple-100 active:bg-electric-purple-100 active:text-white px-4 py-1 text-md leading-5 rounded-full">Read now</button></div></a></div><div class="w-full p-3 sm:w-1/2 lg:w-1/3"><a class="group flex h-full flex-col rounded border border-solid border-neutral-400 shadow-lg hover:shadow-2xl hover:outline hover:outline-1 hover:outline-electric-purple-500" href="/blog/a2a-agent-state-data-layer/"><div class="h-36 min-h-[230px] bg-lightgray-100"><img alt="CockroachDB A2A open standard Blog" loading="lazy" width="1920" height="1080" decoding="async" data-nimg="1" class="size-full rounded-t object-cover" style="color:transparent" srcSet="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F3REYvldUgwVXYUIb6QLRUs%2F3b8601c85f2c3e1853d6813f8c240cd9%2FCockroachDB_A2A_open_standard_Blog.png&amp;w=1920&amp;q=75 1x, /_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F3REYvldUgwVXYUIb6QLRUs%2F3b8601c85f2c3e1853d6813f8c240cd9%2FCockroachDB_A2A_open_standard_Blog.png&amp;w=3840&amp;q=75 2x" src="/_next/image/?url=https%3A%2F%2Fimages.ctfassets.net%2F00voh0j35590%2F3REYvldUgwVXYUIb6QLRUs%2F3b8601c85f2c3e1853d6813f8c240cd9%2FCockroachDB_A2A_open_standard_Blog.png&amp;w=3840&amp;q=75"/></div><div class="flex h-full flex-col items-start justify-between gap-5 px-5 py-6"><div><p class="text-base font-semibold leading-5 group-hover:text-electric-purple-500"> A2A Is Now an Open Standard. The Data Layer Underneath It Isn&#x27;t.</p><p class="my-4 line-clamp-5 leading-5">In April 2025, Google released a protocol for agent-to-agent communication. Within three months, Google had donated it to the Linux Foundation...</p></div><button class="inline-flex justify-center items-center gap-2 disabled:cursor-not-allowed border border-solid border-electric-purple-500 bg-electric-purple-500 text-white hover:bg-white hover:text-electric-purple-500 active:border-electric-purple-100 active:bg-electric-purple-100 active:text-white px-4 py-1 text-md leading-5 rounded-full">Read now</button></div></a></div></div></div></section></div></div></div><footer class="py-10 lg:py-24 bg-white"><div class="m-auto px-6 xl:max-w-[1140px] 2xl:max-w-[1320px]"><div class="homepage-newsletter-form mb-12 flex w-full flex-col rounded-lg p-6 bg-gray-100 text-black"><div class="flex w-full flex-wrap lg:items-center"><div class="w-full lg:w-4/12"><h1 class="mb-2 mt-6 text-[18px] font-semibold">Join our community and get updates delivered straight to your inbox.</h1></div><div class="w-full px-3 lg:w-8/12"><div class="shadow flex flex-col px-2 py-5 text-center sm:px-3 sm:py-12 NewsletterFullMain max-w-full mt-4 w-full rounded lg:mt-0"><form class="pt-3" id="mktoForm_1704"></form></div></div></div><div class="hero-desc mt-[10px] w-full"><p class="font-open-sans !text-[15px]">We will email you updates about CockroachDB. You can unsubscribe at any time. Learn more about our privacy practices <a href="https://www.cockroachlabs.com/privacy/">here</a>.</p></div></div><div class="grid grid-cols-1 gap-6 md:grid-cols-4"><div class="space-y-8"><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Product">Product</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/product/overview/">Product overview</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/product/cloud/">CockroachDB Fully-Managed Cloud </a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://cockroachlabs.com/product/cloud/bring-your-own-cloud">CockroachDB Bring Your Own Cloud</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/product/enterprise/">CockroachDB Enterprise</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/whatsnew/">Latest release</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/pricing/">Pricing</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://cockroachlabs.cloud/">Sign in</a></li></ul></div></div><div class="space-y-8"><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Solutions">Solutions</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/customers/">Customers</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/database-modernization/">Database Modernization</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/resilience/">High availability and disaster recovery</a></li></ul></div><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black By Industry">By Industry</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/solutions/verticals/ai-innovators/">AI Innovators</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/financialservices/">Banking &amp; Fintech</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/solutions/verticals/cybersecurity">Cybersecurity</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/gambling/">Gambling</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/gaming/">Gaming</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/healthcare/">Healthcare</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/manufacturing-logistics/">Manufacturing &amp; Logistics</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/media/">Media &amp; Streaming</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/quantitative-investment/">Quant/Trading &amp; Research</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/retail-ecommerce/">Retail &amp; eCommerce</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/saas/">SaaS</a></li></ul></div><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black By Use Case">By Use Case</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/solutions/usecases/generative-ai/">Vector Search</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/banking-and-wallet/">Banking &amp; Wallet</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/verticals/gaming/">Gaming</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/identity-access-management/">Identity Access Management</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/iot-and-device-management/">IoT &amp; Device Mgmt</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/orders-and-inventory-management/">Orders &amp; Inventory Management</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/payments/">Payments</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/routing-and-logistics/">Routing &amp; Logistics</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/solutions/usecases/user-accounts-and-metadata/">User Metadata</a></li></ul></div><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black By Initiative">By Initiative</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://www.cockroachlabs.com/database-modernization/">Database Modernization</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/architectural-simplification/">Architectural Simplification</a></li></ul></div></div><div class="space-y-8"><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Resources">Resources</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://docs.cockroachlabs.com/">Documentation</a></li></ul></div><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Connect">Connect</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/events/">Events</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/big-ideas-podcast/">Podcast</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/company/professional-services/">Professional Services</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/support/">Support</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/community/webinars/">Webinars</a></li></ul></div><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Learn">Learn</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/blog/">Blog</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="https://learn.cockroachlabs.com/">Cockroach University</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/compare/">Competitive Comparisons</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/guides/">Guides</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/resource/product-demos/">Product Demos</a></li></ul></div></div><div class="space-y-8"><div><h4 class="mb-[7px] text-[18px] font-semibold leading-[38px] text-black Company">Company</h4><ul><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/about/">About</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/careers/">Careers</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/contact/">Contact Us</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/legal-notices/">Legal Notices</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/press/">News / Press</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/partners/">Partners</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/privacy/">Privacy</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/security/">Security</a></li><li class="mb-2 font-open-sans text-[16px] font-light leading-[22px]"><a class="hover:text-electric-purple-500 text-black" href="/trust-center/"> Trust Center</a></li></ul></div></div></div><div class="mt-6 flex flex-col items-start gap-4 border-t border-[#CCCCCC] pt-10 sm:flex-row sm:justify-between lg:flex-row lg:justify-between"><div class="flex flex-row items-start gap-6"><a target="_blank" href="https://www.youtube.com/@cockroachdb"><img alt="Youtube" loading="lazy" width="24" height="20" decoding="async" data-nimg="1" class="object-contain" style="color:transparent" src="/_next/static/media/youtube.4ba947d4.svg"/></a><a target="_blank" href="https://x.com/CockroachDB"><img alt="Twitter" loading="lazy" width="24" height="20" decoding="async" data-nimg="1" class="object-contain" style="color:transparent" src="/_next/static/media/twitter.bbc35ec1.svg"/></a><a target="_blank" href="https://www.linkedin.com/company/cockroach-labs/mycompany/verification/"><img alt="Linkedin" loading="lazy" width="24" height="20" decoding="async" data-nimg="1" class="object-contain" style="color:transparent" src="/_next/static/media/linkedin.af9eaeac.svg"/></a><a target="_blank" href="https://www.instagram.com/cockroachdb/"><img alt="Instagram" loading="lazy" width="24" height="20" decoding="async" data-nimg="1" class="object-contain" style="color:transparent" src="/_next/static/media/instagram.fb391cad.svg"/></a></div><div class="flex items-center gap-6"><button type="button" aria-label="Open cookie settings" class="text-black rounded-md px-2 font-open-sans text-[16px] leading-[22px] transition-colors duration-200 hover:text-electric-purple-500 focus:outline-none focus:ring-2 focus:ring-electric-purple-500">Cookie Settings</button><span class="font-base text-right font-open-sans text-[16px] leading-[22px]">© 2026 Cockroach Labs</span></div></div></div></footer></div><script src="/_next/static/chunks/webpack-83edb66965ac3e69.js" async=""></script><script>(self.__next_f=self.__next_f||[]).push([0]);self.__next_f.push([2,null])</script><script>self.__next_f.push([1,"1:HL[\"/_next/static/css/88295a675380e144.css\",\"style\"]\n2:HL[\"/_next/static/css/dc1197790a7221a6.css\",\"style\"]\n"])</script><script>self.__next_f.push([1,"3:I[12846,[],\"\"]\n6:I[4707,[],\"\"]\n8:I[36423,[],\"\"]\nb:I[61060,[],\"\"]\n7:[\"slug\",\"brief-history-high-availability\",\"d\"]\nc:[]\n0:[\"$\",\"$L3\",null,{\"buildId\":\"dmJHH2NqYWRChKdZfs63D\",\"assetPrefix\":\"\",\"urlParts\":[\"\",\"blog\",\"brief-history-high-availability\",\"\"],\"initialTree\":[\"\",{\"children\":[\"blog\",{\"children\":[[\"slug\",\"brief-history-high-availability\",\"d\"],{\"children\":[\"__PAGE__\",{}]}]}]},\"$undefined\",\"$undefined\",true],\"initialSeedData\":[\"\",{\"children\":[\"blog\",{\"children\":[[\"slug\",\"brief-history-high-availability\",\"d\"],{\"children\":[\"__PAGE__\",{},[[\"$L4\",\"$L5\",null],null],null]},[null,[\"$\",\"$L6\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"blog\",\"children\",\"$7\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L8\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\"}]],null]},[null,[\"$\",\"$L6\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\",\"blog\",\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L8\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$undefined\",\"notFoundStyles\":\"$undefined\"}]],null]},[[[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/88295a675380e144.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}],[\"$\",\"link\",\"1\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/dc1197790a7221a6.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\"}]],\"$L9\"],null],null],\"couldBeIntercepted\":false,\"initialHead\":[null,\"$La\"],\"globalErrorComponent\":\"$b\",\"missingSlots\":\"$Wc\"}]\n"])</script><script>self.__next_f.push([1,"d:I[98087,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"7878\",\"static/chunks/7878-4acaa52979fada4f.js\",\"3185\",\"static/chunks/app/layout-1dec2751509bb5fe.js\"],\"GoogleTagManager\"]\ne:I[88003,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"7878\",\"static/chunks/7878-4acaa52979fada4f.js\",\"3185\",\"static/chunks/app/layout-1dec2751509bb5fe.js\"],\"\"]\nf:I[48847,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"7878\",\"static/chunks/7878-4acaa52979fada4f.js\",\"3185\",\"static/chunks/app/layout-1dec2751509bb5fe.js\"],\"default\"]\n11:Td65,"])</script><script>self.__next_f.push([1,"{\"@context\":\"https://schema.org\",\"@graph\":[{\"@id\":\"https://www.cockroachlabs.com/#software\",\"@type\":\"WebApplication\",\"name\":\"CockroachDB\",\"alternateName\":\"CockroachDB Cloud\",\"applicationCategory\":\"DatabaseApplication\",\"applicationSubCategory\":\"Distributed SQL Database\",\"operatingSystem\":\"Cloud, Linux, Kubernetes, On-Premise\",\"description\":\"CockroachDB is a cloud-native, PostgreSQL-compatible distributed SQL database built for always-on, globally distributed applications. It delivers the consistency of relational databases, the scalability of NoSQL, and the simplicity of cloud - with elastic scale, zero downtime, and enterprise-grade security for mission-critical and AI-native workloads.\",\"url\":\"https://www.cockroachlabs.com\",\"featureList\":[\"Distributed vector indexing powered by C-SPANN, SPFresh, and RaBitQ\",\"pgvector-compatible vector search\",\"Retrieval Augmented Generation (RAG) support\",\"Vector similarity search and approximate nearest neighbor (ANN) queries\",\"Vector embeddings storage and querying at billions of vectors\",\"Semantic search and natural language processing (NLP) support\",\"AI agent metadata management\",\"LangChain integration for agentic AI applications\",\"AWS Bedrock, Hugging Face, and Postgres MCP server integrations\",\"Generative AI and LLM application support\",\"Hybrid SQL and vector search queries\",\"Elastic automated horizontal scaling for reads and writes\",\"Guaranteed global writes with strong consistency\",\"Hotspot detection and automatic data rebalancing\",\"Always-on availability with automatic failover\",\"Survive node, rack, availability zone, and regional failures\",\"Logical Data Replication\",\"Built-in RAFT replication\",\"Zero downtime rolling upgrades and online schema changes\",\"PostgreSQL compatibility\",\"User-defined functions (UDFs) and stored procedures\",\"Read committed transactions and serializable isolation\",\"MOLT migration tools for database modernization\",\"Built-in Change Data Capture (CDC)\",\"Cost-based optimizer\",\"Generic query plans\",\"Buffered writes\",\"Query inspection and admission control\",\"Native data domiciling for regional compliance\",\"Multi-region and multi-cloud deployment\",\"Kubernetes and Terraform support\",\"Fleet management and APIs\",\"Role-based access control (RBAC) and encryption\",\"Row-level security\",\"OIDC/SSO integration and CMEK\",\"Private endpoints and perimeter security\",\"OpenTelemetry and Prometheus integrations\",\"Audit logging\",\"PCI DSS compliant\",\"HIPAA ready\",\"SOC 2 Type 2\",\"FIPS 140-2\",\"ISO 20001 and 27017\"],\"offers\":[{\"@type\":\"Offer\",\"name\":\"CockroachDB Fully-Managed Cloud\",\"description\":\"A fully-managed cloud database service where Cockroach Labs handles all infrastructure, scaling, and operations - letting teams focus entirely on building applications.\",\"url\":\"https://www.cockroachlabs.com/product/cloud/\"},{\"@type\":\"Offer\",\"name\":\"CockroachDB Bring Your Own Cloud (BYOC)\",\"description\":\"Deploy CockroachDB in your own cloud environment with the operational simplicity of a managed service. Ideal for teams that need data isolation and compliance while avoiding infrastructure overhead.\",\"url\":\"https://www.cockroachlabs.com/product/cloud/bring-your-own-cloud/\"},{\"@type\":\"Offer\",\"name\":\"CockroachDB Enterprise\",\"description\":\"Self-hosted, on-premise deployment of CockroachDB for enterprises requiring full infrastructure control, advanced security, and compliance.\",\"url\":\"https://www.cockroachlabs.com/product/enterprise/\"}]}]}"])</script><script>self.__next_f.push([1,"12:T68b,\n !function(){var analytics=window.analytics=window.analytics||[];if(!analytics.initialize)if(analytics.invoked)window.console\u0026\u0026console.error\u0026\u0026console.error(\"Segment snippet included twice.\");else{analytics.invoked=!0;analytics.methods=[\"trackSubmit\",\"trackClick\",\"trackLink\",\"trackForm\",\"pageview\",\"identify\",\"reset\",\"group\",\"track\",\"ready\",\"alias\",\"debug\",\"page\",\"once\",\"off\",\"on\",\"addSourceMiddleware\",\"addIntegrationMiddleware\",\"setAnonymousId\",\"addDestinationMiddleware\"];analytics.factory=function(e){return function(){var t=Array.prototype.slice.call(arguments);t.unshift(e);analytics.push(t);return analytics}};for(var e=0;e\u003canalytics.methods.length;e++){var key=analytics.methods[e];analytics[key]=analytics.factory(key)}analytics.load=function(key,e){var t=document.createElement(\"script\");t.type=\"text/javascript\";t.async=!0;t.src=\"https://cdn.segment.com/analytics.js/v1/\" + key + \"/analytics.min.js\";var n=document.getElementsByTagName(\"script\")[0];n.parentNode.insertBefore(t,n);analytics._loadOptions=e};analytics._writeKey=\"Mz68FzJ2r4poMQ4bQTniyvZF9yF0ycET\";;analytics.SNIPPET_VERSION=\"4.15.3\";\n analytics.load(\"Mz68FzJ2r4poMQ4bQTniyvZF9yF0ycET\", {\n user: {\n cookie: {\n key: \"crl_brand_ajs_user_id\",\n oldKey: \"crl_brand_ajs_user\",\n },\n localStorage: {\n key: \"crl_brand_ajs_user_traits\",\n },\n },\n localStorage: {\n key: \"crl_brand_ajs_group_properties\",\n }\n });\n analytics.page();\n }}();\n "])</script><script>self.__next_f.push([1,"9:[\"$\",\"html\",null,{\"lang\":\"en\",\"children\":[[\"$\",\"$Ld\",null,{\"gtmId\":\"GTM-NR8LC4\"}],[\"$\",\"head\",null,{\"children\":[\"$\",\"$Le\",null,{\"src\":\"https://boards.greenhouse.io/embed/job_board/js?for=cockroachlabs\",\"nonce\":\"\"}]}],[\"$\",\"body\",null,{\"children\":[[\"$\",\"$Lf\",null,{\"ninetailed\":{\"preview\":{\"allAudiences\":[{\"id\":\"2AtTnKsNI6x2tbub5fCs4l\",\"name\":\"All \",\"description\":null},{\"id\":\"5MYkRvrEAmeXrg7KWe9cjw\",\"name\":\"US Only\",\"description\":null},{\"id\":\"1vQVL3dgdKFR3PjKU9zZNl\",\"name\":\"AI Interest\",\"description\":null},{\"id\":\"4MIWBOCNbXgcvOfvNkf9WW\",\"name\":\"RoachFest London Audience \",\"description\":null},{\"id\":\"51uMnqLbZvhFX45SDKNGLt\",\"name\":\"Test Tech\",\"description\":null},{\"id\":\"nyk2s9mWgMgsW80GZ0SoL\",\"name\":\"All Audiences\",\"description\":null}],\"allExperiences\":[{\"id\":\"2d00ac3b-91fe-45d2-ba6b-eea3e8330b67\",\"type\":\"nt_experiment\",\"name\":\"[Ninetailed] Global Nav Bar Experiment (Try for free)\",\"audience\":{\"id\":\"2AtTnKsNI6x2tbub5fCs4l\"},\"trafficAllocation\":0.2,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4sdqhd9ekH57ufrme4VNWC\",\"hidden\":false},\"variants\":[]},{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4sdqhd9ekH57ufrme4VNWC\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"2e4sawE8nAgOk6e5N9sExM\",\"type\":\"nt_experiment\",\"name\":\"[Ninetailed] Global Nav Bar Experiment\",\"audience\":{\"id\":\"2AtTnKsNI6x2tbub5fCs4l\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4sdqhd9ekH57ufrme4VNWC\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"3fOAMFU9HLGrM7nhUM9PsN\",\"type\":\"nt_experiment\",\"name\":\"[Guide Banner Test]\",\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"349HEs0mAbbrjtPT0bBOMZ\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"3B6dC9hVTBUp0KhRt83ZkV\",\"type\":\"nt_experiment\",\"name\":\"CTA Test\",\"audience\":{\"id\":\"5MYkRvrEAmeXrg7KWe9cjw\"},\"trafficAllocation\":0.8,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"1vNMG52KHKQG6dl6QR22Fy\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"5Y4TajmeGrJmvxlT4oagzo\",\"type\":\"nt_experiment\",\"name\":\"test template guide\",\"audience\":{\"id\":\"2AtTnKsNI6x2tbub5fCs4l\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"1rN9VmMF0xHKk5yv7Z6UIu\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"56w2SGQicQ7wpEbcFNRe8A\",\"type\":\"nt_experiment\",\"name\":\"[Paid] Distributed SQL Demo\",\"audience\":{\"id\":\"2AtTnKsNI6x2tbub5fCs4l\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"5JZzFjqNo3sWEpAZva6JQq\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"4lb1bnfUxkpr8H9S0egmxk\",\"type\":\"nt_personalization\",\"name\":\"USA RoachFest\",\"audience\":{\"id\":\"5MYkRvrEAmeXrg7KWe9cjw\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0},{\"index\":1,\"start\":0,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"79F0MeN8RhLE1pkj9l54YX\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"1rhctkVaUuYJpZtCntZjxI\",\"type\":\"nt_personalization\",\"name\":\"US\",\"audience\":{\"id\":\"5MYkRvrEAmeXrg7KWe9cjw\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0},{\"index\":1,\"start\":0,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"79F0MeN8RhLE1pkj9l54YX\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"2olPLJTC2sZDjoCBv0ZrdG\",\"type\":\"nt_experiment\",\"name\":\"Dist SQL Demo\",\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"1mPV8irFZGtvLQOHHkzwgv\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"4UCzmxQRy6MF1kb98gh0k\",\"type\":\"nt_personalization\",\"name\":\"RoachFest London\",\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.1},{\"index\":1,\"start\":0.1,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4AUNRRVQiZ27y95R0kiZvz\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"1CWzkowfzU62GAoCufD2QY\",\"type\":\"nt_experiment\",\"name\":\"Demo LP\",\"trafficAllocation\":0.49,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"oVhWL0M4TedDM8Fz2GfMV\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"6fF2JJNWUbmwpVy1BLe0RA\",\"type\":\"nt_personalization\",\"name\":\"RoachFest Virtual\",\"audience\":{\"id\":\"4MIWBOCNbXgcvOfvNkf9WW\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.1},{\"index\":1,\"start\":0.1,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"1q7efLDjwYuDrhPRLxtm2s\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"2DWR8lJLf2O06CYqkCATxM\",\"type\":\"nt_personalization\",\"name\":\"Test Tech Insight\",\"audience\":{\"id\":\"51uMnqLbZvhFX45SDKNGLt\"},\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.5},{\"index\":1,\"start\":0.5,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"79F0MeN8RhLE1pkj9l54YX\",\"hidden\":false},\"variants\":[]}]},{\"id\":\"3m8mS7mSVMeMJhWisUsYoe\",\"type\":\"nt_experiment\",\"name\":\"Homepage Banner vs PUA\",\"trafficAllocation\":1,\"distribution\":[{\"index\":0,\"start\":0,\"end\":0.7},{\"index\":1,\"start\":0.7,\"end\":1}],\"sticky\":false,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"1q7efLDjwYuDrhPRLxtm2s\",\"hidden\":false},\"variants\":[]}]}]}},\"children\":[\"$\",\"$L6\",null,{\"parallelRouterKey\":\"children\",\"segmentPath\":[\"children\"],\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L8\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":\"$L10\",\"notFoundStyles\":[]}]}],[\"$\",\"$Le\",null,{\"id\":\"OrganizationStructuredData\",\"type\":\"application/ld+json\",\"dangerouslySetInnerHTML\":{\"__html\":\"{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"Organization\\\",\\\"name\\\":\\\"Cockroach Labs\\\",\\\"url\\\":\\\"https://www.cockroachlabs.com\\\",\\\"logo\\\":{\\\"@type\\\":\\\"ImageObject\\\",\\\"url\\\":\\\"https://www.cockroachlabs.com/favicon.ico\\\"},\\\"areaServed\\\":\\\"Global\\\",\\\"foundingDate\\\":\\\"2015-01-01\\\",\\\"contactPoint\\\":{\\\"@type\\\":\\\"ContactPoint\\\",\\\"email\\\":\\\"info@cockroachlabs.com\\\",\\\"contactType\\\":\\\"customer support\\\",\\\"areaServed\\\":\\\"Global\\\",\\\"availableLanguage\\\":[\\\"English\\\"]},\\\"sameAs\\\":[\\\"https://twitter.com/cockroachdb\\\",\\\"https://github.com/cockroachdb/cockroach\\\",\\\"https://www.linkedin.com/company/cockroach-labs/\\\"]}\"}}],[\"$\",\"$Le\",null,{\"id\":\"SoftwareStructuredData\",\"type\":\"application/ld+json\",\"dangerouslySetInnerHTML\":{\"__html\":\"$11\"}}]]}],[\"$\",\"$Le\",null,{\"id\":\"Segment\",\"dangerouslySetInnerHTML\":{\"__html\":\"$12\"}}],[\"$\",\"$Le\",null,{\"id\":\"DataDog\",\"dangerouslySetInnerHTML\":{\"__html\":\"\\n (function(h,o,u,n,d) {\\n h=h[d]=h[d]||{q:[],onReady:function(c){h.q.push(c)}}\\n d=o.createElement(u);d.async=1;d.src=n\\n n=o.getElementsByTagName(u)[0];n.parentNode.insertBefore(d,n)\\n })(window,document,'script','https://www.datadoghq-browser-agent.com/datadog-rum-v3.js','DD_RUM')\\n DD_RUM.onReady(function() {\\n DD_RUM.init({\\n clientToken: 'pub4ca4d65c8d073132f3233fe9189a0fd3',\\n applicationId: 'bd392428-cb13-4b5f-91c4-adbebdc6bb59',\\n site: 'datadoghq.com',\\n service:'www-cockroachlabs',\\n env:'prod',\\n // Specify a version number to identify the deployed version of your application in Datadog \\n // version: '1.0.0',\\n sampleRate: 100,\\n trackInteractions: true,\\n })\\n })\\n \"}}]]}]\n"])</script><script>self.__next_f.push([1,"a:[[\"$\",\"meta\",\"0\",{\"name\":\"viewport\",\"content\":\"width=device-width, initial-scale=1\"}],[\"$\",\"meta\",\"1\",{\"charSet\":\"utf-8\"}],[\"$\",\"title\",\"2\",{\"children\":\"A brief history of high availability\"}],[\"$\",\"meta\",\"3\",{\"name\":\"description\",\"content\":\"The perennial question of homo sapiens is, 'How did we get here?' Today we're going to take a crack at answering that: where 'here' is defined as 'high availability for web services'.\"}],[\"$\",\"meta\",\"4\",{\"name\":\"robots\",\"content\":\"index, follow\"}],[\"$\",\"link\",\"5\",{\"rel\":\"canonical\",\"href\":\"https://www.cockroachlabs.com/blog/brief-history-high-availability/\"}],[\"$\",\"meta\",\"6\",{\"property\":\"og:title\",\"content\":\"A brief history of high availability\"}],[\"$\",\"meta\",\"7\",{\"property\":\"og:description\",\"content\":\"The perennial question of homo sapiens is, 'How did we get here?' Today we're going to take a crack at answering that: where 'here' is defined as 'high availability for web services'.\"}],[\"$\",\"meta\",\"8\",{\"property\":\"og:url\",\"content\":\"https://www.cockroachlabs.com/blog/brief-history-high-availability/\"}],[\"$\",\"meta\",\"9\",{\"property\":\"og:image\",\"content\":\"https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg\"}],[\"$\",\"meta\",\"10\",{\"property\":\"og:image:alt\",\"content\":\"DataReplication ChristinaChung-1\"}],[\"$\",\"meta\",\"11\",{\"name\":\"twitter:card\",\"content\":\"summary_large_image\"}],[\"$\",\"meta\",\"12\",{\"name\":\"twitter:title\",\"content\":\"A brief history of high availability\"}],[\"$\",\"meta\",\"13\",{\"name\":\"twitter:description\",\"content\":\"The perennial question of homo sapiens is, 'How did we get here?' Today we're going to take a crack at answering that: where 'here' is defined as 'high availability for web services'.\"}],[\"$\",\"meta\",\"14\",{\"name\":\"twitter:image\",\"content\":\"https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg\"}],[\"$\",\"meta\",\"15\",{\"name\":\"twitter:image:alt\",\"content\":\"DataReplication ChristinaChung-1\"}],[\"$\",\"link\",\"16\",{\"rel\":\"icon\",\"href\":\"/icon.png?682d166483111c8f\",\"type\":\"image/png\",\"sizes\":\"48x48\"}]]\n"])</script><script>self.__next_f.push([1,"4:null\n"])</script><script>self.__next_f.push([1,"13:I[51054,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"4767\",\"static/chunks/4767-3be12bccc3485fef.js\",\"5902\",\"static/chunks/5902-b023fdecad77ece9.js\",\"5181\",\"static/chunks/5181-a7292807635098af.js\",\"1166\",\"static/chunks/1166-3e5e918f62c8a9c5.js\",\"7518\",\"static/chunks/7518-f6cc01f2368b270a.js\",\"308\",\"static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js\"],\"NinetailedHeaderWrapper\"]\n15:I[87290,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"4767\",\"static/chunks/4767-3be12bccc3485fef.js\",\"5902\",\"static/chunks/5902-b023fdecad77ece9.js\",\"5181\",\"static/chunks/5181-a7292807635098af.js\",\"1166\",\"static/chunks/1166-3e5e918f62c8a9c5.js\",\"7518\",\"static/chunks/7518-f6cc01f2368b270a.js\",\"308\",\"static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js\"],\"default\"]\n"])</script><script>self.__next_f.push([1,"10:[\"$\",\"div\",null,{\"children\":[[\"$\",\"$L13\",null,{\"headerData\":{\"__typename\":\"ComponentHeaderCollection\",\"items\":[{\"__typename\":\"ComponentHeader\",\"ntExperiencesCollection\":{\"__typename\":\"ComponentHeaderNt_experiencesCollection\",\"items\":[{\"__typename\":\"NtExperience\",\"ntVariantsCollection\":{\"__typename\":\"NtExperienceNt_variantsCollection\",\"items\":[{\"__typename\":\"ComponentHeader\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3F3zZlYkHnkHMMlChW6U5e\"},\"ctaButton\":{\"__typename\":\"ComponentButton\",\"internalName\":\"[Global Nav] Enroll now\",\"label\":\"Try CockroachDB\",\"url\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global_2\",\"longUrl\":null,\"type\":[\"primaryDark\"],\"size\":[\"xs\"],\"rounded\":[\"full\"],\"customStyle\":null,\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null},\"contentfulMetadata\":{\"__typename\":\"ContentfulMetadata\"},\"internalName\":\"[Ninetailed Variant] Global Header\",\"announcementBar\":false,\"announcementBarText\":\"RoachFest is back — Live \u0026 virtual | June 25, London | Register now →\",\"announcementBarUrl\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"logo\":{\"__typename\":\"Asset\",\"description\":null,\"title\":\"cockroachlabs-logo-170\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4L99WneFfQZfEiTbAz7FBY/cde51d5ab34e96fe246fbc8fe4dea72c/cockroachlabs-logo-170.png\",\"width\":340,\"height\":48},\"contactUsLink\":\"/contact\",\"signInLink\":\"https://cockroachlabs.cloud/\",\"startLink\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\"}]},\"sys\":{\"__typename\":\"Sys\",\"id\":\"1SrZaLT4lfwBBAX6vktZca\"},\"ntExperienceId\":\"2d00ac3b-91fe-45d2-ba6b-eea3e8330b67\",\"ntName\":\"[Ninetailed] Global Nav Bar Experiment (Try for free)\",\"ntType\":\"nt_experiment\",\"ntConfig\":{\"traffic\":0.2,\"components\":[{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4sdqhd9ekH57ufrme4VNWC\",\"title\":\"New Global Header Rev\"},\"variants\":[{\"id\":\"3F3zZlYkHnkHMMlChW6U5e\",\"hidden\":false}]},{\"type\":\"EntryReplacement\",\"baseline\":{\"id\":\"4sdqhd9ekH57ufrme4VNWC\"},\"variants\":[{\"id\":\"\",\"hidden\":false}]}],\"distribution\":[0.5,0.5],\"primaryMetric\":\"38470cbd-28ba-4b31-a3e6-7da903ae736e\",\"distributionType\":\"even-split\"},\"ntAudience\":{\"__typename\":\"NtAudience\",\"ntAudienceId\":\"2AtTnKsNI6x2tbub5fCs4l\",\"ntDescription\":null,\"ntName\":\"All \"}}]},\"sys\":{\"__typename\":\"Sys\",\"id\":\"4sdqhd9ekH57ufrme4VNWC\"},\"contentfulMetadata\":{\"__typename\":\"ContentfulMetadata\"},\"internalName\":\"New Global Header Rev\",\"announcementBar\":false,\"announcementBarText\":\"RoachFest is back — Live \u0026 virtual | June 25, London | Register now →\",\"announcementBarUrl\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"logo\":{\"__typename\":\"Asset\",\"description\":null,\"title\":\"cockroachlabs-logo-170\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4L99WneFfQZfEiTbAz7FBY/cde51d5ab34e96fe246fbc8fe4dea72c/cockroachlabs-logo-170.png\",\"width\":340,\"height\":48},\"contactUsLink\":\"/contact\",\"signInLink\":\"https://cockroachlabs.cloud/\",\"startLink\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\",\"menuCollection\":{\"__typename\":\"ComponentHeaderMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Product\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\" \",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB for Agents\",\"labelColor\":null,\"link\":\"/product/ai/\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Fully-Managed Cloud \",\"labelColor\":null,\"link\":\"/product/cloud/\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Bring Your Own Cloud\",\"labelColor\":null,\"link\":\"https://cockroachlabs.com/product/cloud/bring-your-own-cloud\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Enterprise\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/product/enterprise/\"},{\"__typename\":\"MenuItems\",\"label\":\"Partner Integrations\",\"labelColor\":null,\"link\":\"/product/partner-integrations/\"},{\"__typename\":\"MenuItems\",\"label\":\"Migrations\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/migrations/\"},{\"__typename\":\"MenuItems\",\"label\":\"Latest release\",\"labelColor\":null,\"link\":\"/whatsnew/\"},{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"labelColor\":null,\"link\":\"/pricing\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}]},\"narrow\":false,\"twoColumn\":null,\"cta\":{\"__typename\":\"MenuItemsCta\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"CockroachDB\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The cloud native, distributed SQL database enterprises trust to run mission-critical applications that scale fast, survive disaster, and thrive everywhere.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"AL3FSfdNHpT50JJEc1Sns\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":{\"__typename\":\"MenuItemsCtaEntries\",\"block\":[{\"__typename\":\"ComponentButton\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"AL3FSfdNHpT50JJEc1Sns\"},\"internalName\":\"[Menu] Product Overview\",\"label\":\"Product Overview\",\"url\":\"https://www.cockroachlabs.com/product/overview/\",\"longUrl\":null,\"type\":null,\"size\":[\"sm\"],\"rounded\":[\"full\"],\"customStyle\":[\"header-button\"],\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}]}}},\"ctaPosition\":true,\"media\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"what-is-dist-sql\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3IxxzR4MUE6aWz33L9PuGu/c7d233621deb26b2372be9c790e970ad/what-is-dist-sql.png\",\"width\":288,\"height\":339},\"mediaLink\":\"https://www.cockroachlabs.com/blog/what-is-distributed-sql/\",\"media2\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"enterprise-downtime-guide\",\"url\":\"https://images.ctfassets.net/00voh0j35590/76s4JBRoX1MLh1AIJzGRrP/9dcf819fc8bfac91573327af7ae9ab8f/enterprise-downtime-guide.jpg\",\"width\":431,\"height\":507},\"mediaLink2\":\"https://www.cockroachlabs.com/guides/the-state-of-resilience-2025/\"},{\"__typename\":\"MenuItems\",\"label\":\"Solutions\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"By Use Case\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Agent State Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/agent-state-management\"},{\"__typename\":\"MenuItems\",\"label\":\"AI\",\"labelColor\":null,\"link\":\"/solutions/usecases/ai\"},{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Wallet\",\"labelColor\":null,\"link\":\"/solutions/usecases/banking-and-wallet\"},{\"__typename\":\"MenuItems\",\"label\":\"Data Modernization\",\"labelColor\":null,\"link\":\"/database-modernization/\"},{\"__typename\":\"MenuItems\",\"label\":\"Gaming Platform\",\"labelColor\":null,\"link\":\"/solutions/usecases/gaming-platforms\"},{\"__typename\":\"MenuItems\",\"label\":\"Identity Access Mgmt (IAM)\",\"labelColor\":null,\"link\":\"/solutions/usecases/identity-access-management\"},{\"__typename\":\"MenuItems\",\"label\":\"IoT \u0026 Device Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/iot-and-device-management\"},{\"__typename\":\"MenuItems\",\"label\":\"Order \u0026 Inventory Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/orders-and-inventory-management\"},{\"__typename\":\"MenuItems\",\"label\":\"Payments\",\"labelColor\":null,\"link\":\"/solutions/usecases/payments\"},{\"__typename\":\"MenuItems\",\"label\":\"Routing \u0026 Logistics\",\"labelColor\":null,\"link\":\"/solutions/usecases/routing-and-logistics\"},{\"__typename\":\"MenuItems\",\"label\":\"User Metadata\",\"labelColor\":null,\"link\":\"/solutions/usecases/user-accounts-and-metadata/\"},{\"__typename\":\"MenuItems\",\"label\":\"Vector Search\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/usecases/generative-ai/\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null},{\"__typename\":\"MenuItems\",\"label\":\"By Vertical\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"AI Innovators\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/ai-innovators/\"},{\"__typename\":\"MenuItems\",\"label\":\"Cybersecurity\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/cybersecurity\"},{\"__typename\":\"MenuItems\",\"label\":\"Financial Services\",\"labelColor\":null,\"link\":\"/solutions/verticals/financialservices/\"},{\"__typename\":\"MenuItems\",\"label\":\"Gambling\",\"labelColor\":null,\"link\":\"/solutions/verticals/gambling/\"},{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"labelColor\":null,\"link\":\"/solutions/verticals/gaming/\"},{\"__typename\":\"MenuItems\",\"label\":\"Healthcare\",\"labelColor\":null,\"link\":\"/solutions/verticals/healthcare\"},{\"__typename\":\"MenuItems\",\"label\":\"Manufacturing \u0026 Logistics\",\"labelColor\":null,\"link\":\"/solutions/verticals/manufacturing-logistics/\"},{\"__typename\":\"MenuItems\",\"label\":\"Media \u0026 Streaming\",\"labelColor\":null,\"link\":\"/solutions/verticals/media/\"},{\"__typename\":\"MenuItems\",\"label\":\"Quant/Trading \u0026 Research\",\"labelColor\":null,\"link\":\"/solutions/verticals/quantitative-investment/\"},{\"__typename\":\"MenuItems\",\"label\":\"Retail \u0026 eCommerce\",\"labelColor\":null,\"link\":\"/solutions/verticals/retail-ecommerce/\"},{\"__typename\":\"MenuItems\",\"label\":\"SaaS\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/saas/\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}]},\"narrow\":false,\"twoColumn\":null,\"cta\":{\"__typename\":\"MenuItemsCta\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Customers\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Industry leaders trust CockroachDB to run their most data-intensive, mission-critical applications.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"6WiuJnSC9QsEVjqGRMSi9N\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":{\"__typename\":\"MenuItemsCtaEntries\",\"block\":[{\"__typename\":\"ComponentButton\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"6WiuJnSC9QsEVjqGRMSi9N\"},\"internalName\":\"Explore customer stories\",\"label\":\"Explore customer stories\",\"url\":\"https://www.cockroachlabs.com/customers/\",\"longUrl\":null,\"type\":null,\"size\":[\"sm\"],\"rounded\":[\"full\"],\"customStyle\":[\"header-button\"],\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}]}}},\"ctaPosition\":true,\"media\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"modernize-inf\",\"url\":\"https://images.ctfassets.net/00voh0j35590/1P4tI5v8ElwGQX8189XfHr/46332d3b90382698e5133395e3c00ae2/modernize-inf.jpg\",\"width\":287,\"height\":160},\"mediaLink\":\"/database-modernization/\",\"media2\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Group 19597\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6ljtnICVBI7s4hKzVt6Nbs/3fc2bedaeadc8c65213354a302554155/Group_19597.png\",\"width\":431,\"height\":240},\"mediaLink2\":\"/resilience/\"},{\"__typename\":\"MenuItems\",\"label\":\"Resources\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Learn\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Blog\",\"labelColor\":null,\"link\":\"/blog/\"},{\"__typename\":\"MenuItems\",\"label\":\"Cockroach University\",\"labelColor\":null,\"link\":\"https://learn.cockroachlabs.com/\"},{\"__typename\":\"MenuItems\",\"label\":\"Competitive Comparisons\",\"labelColor\":null,\"link\":\"/compare/\"},{\"__typename\":\"MenuItems\",\"label\":\"Guides\",\"labelColor\":null,\"link\":\"/guides/\"},{\"__typename\":\"MenuItems\",\"label\":\"Product Demos\",\"labelColor\":null,\"link\":\"/resource/product-demos/\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null},{\"__typename\":\"MenuItems\",\"label\":\"Connect\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Events\",\"labelColor\":null,\"link\":\"/events/\"},{\"__typename\":\"MenuItems\",\"label\":\"Podcast\",\"labelColor\":null,\"link\":\"/big-ideas-podcast/\"},{\"__typename\":\"MenuItems\",\"label\":\"Professional Services\",\"labelColor\":null,\"link\":\"/company/professional-services/\"},{\"__typename\":\"MenuItems\",\"label\":\"Support\",\"labelColor\":null,\"link\":\"/support/\"},{\"__typename\":\"MenuItems\",\"label\":\"Webinars\",\"labelColor\":null,\"link\":\"/community/webinars/\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}]},\"narrow\":false,\"twoColumn\":null,\"cta\":{\"__typename\":\"MenuItemsCta\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Documentation\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Access tutorials, guides, example application, and much more\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"56fXxWRDgEm3Jmf0uQDcZM\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":{\"__typename\":\"MenuItemsCtaEntries\",\"block\":[{\"__typename\":\"ComponentButton\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"56fXxWRDgEm3Jmf0uQDcZM\"},\"internalName\":\"Explore Docs\",\"label\":\"Explore Docs\",\"url\":\"https://docs.cockroachlabs.com/\",\"longUrl\":null,\"type\":null,\"size\":[\"sm\"],\"rounded\":[\"full\"],\"customStyle\":[\"header-button\"],\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}]}}},\"ctaPosition\":true,\"media\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"rf26\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3NViyVYW37PI3K0OY2mjER/4dcc464bc1e4d6769964b511bc685a40/rf26.png\",\"width\":576,\"height\":678},\"mediaLink\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"media2\":null,\"mediaLink2\":null},{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"labelColor\":null,\"link\":\"/pricing\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[]},\"narrow\":null,\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null,\"media\":null,\"mediaLink\":\"This is for header dropdown menu media link.\",\"media2\":null,\"mediaLink2\":null},{\"__typename\":\"MenuItems\",\"label\":\" Company\",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\" \",\"labelColor\":null,\"link\":null,\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Careers\",\"labelColor\":null,\"link\":\"/careers/\"},{\"__typename\":\"MenuItems\",\"label\":\"Partners\",\"labelColor\":null,\"link\":\"/partners/\"},{\"__typename\":\"MenuItems\",\"label\":\" Trust Center\",\"labelColor\":null,\"link\":\"/trust-center/\"}]},\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}]},\"narrow\":false,\"twoColumn\":null,\"cta\":{\"__typename\":\"MenuItemsCta\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"About Us\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Cockroach Labs is the creator \u2028of CockroachDB, the cloud native, distributed SQL database enterprises trust to run mission-critical applications that scale \u2028fast, survive disaster, and thrive everywhere.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"39wptWpxEWhuNJSv4c1uqo\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":{\"__typename\":\"MenuItemsCtaEntries\",\"block\":[{\"__typename\":\"ComponentButton\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"39wptWpxEWhuNJSv4c1uqo\"},\"internalName\":\"Get to know us\",\"label\":\"Get to know us\",\"url\":\"https://www.cockroachlabs.com/about/\",\"longUrl\":null,\"type\":null,\"size\":[\"sm\"],\"rounded\":[\"full\"],\"customStyle\":[\"header-button\"],\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}]}}},\"ctaPosition\":true,\"media\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"rf26\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3NViyVYW37PI3K0OY2mjER/4dcc464bc1e4d6769964b511bc685a40/rf26.png\",\"width\":576,\"height\":678},\"mediaLink\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"media2\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Group 19596\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6lT25boB4PhmQXHHXNK7gp/7304f1979776bea93adc4f525b101f7d/Group_19596.png\",\"width\":431,\"height\":507},\"mediaLink2\":\"https://www.cockroachlabs.com/blog/software-engineering-internship-jasmine-sun/\"}]},\"ctaButton\":{\"__typename\":\"ComponentButton\",\"internalName\":\"[Global Nav] Get started free\",\"label\":\"Try for free\",\"url\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\",\"longUrl\":null,\"type\":[\"primaryDark\"],\"size\":[\"xs\"],\"rounded\":[\"full\"],\"customStyle\":null,\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}}]},\"showAnnouncementBar\":false}],\"$L14\",[\"$\",\"$L15\",null,{\"darkBg\":true,\"footerData\":{\"__typename\":\"ComponentFooterCollection\",\"items\":[{\"__typename\":\"ComponentFooter\",\"internalName\":\"New Footer Rev\",\"menuItemsCollection\":{\"__typename\":\"ComponentFooterMenuItemsCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Product\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Product overview\",\"link\":\"/product/overview\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Fully-Managed Cloud \",\"link\":\"/product/cloud/\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Bring Your Own Cloud\",\"link\":\"https://cockroachlabs.com/product/cloud/bring-your-own-cloud\"},{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Enterprise\",\"link\":\"https://www.cockroachlabs.com/product/enterprise/\"},{\"__typename\":\"MenuItems\",\"label\":\"Latest release\",\"link\":\"/whatsnew/\"},{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"link\":\"/pricing/\"},{\"__typename\":\"MenuItems\",\"label\":\"Sign in\",\"link\":\"https://cockroachlabs.cloud/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"Solutions\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Customers\",\"link\":\"/customers/\"},{\"__typename\":\"MenuItems\",\"label\":\"Database Modernization\",\"link\":\"https://www.cockroachlabs.com/database-modernization/\"},{\"__typename\":\"MenuItems\",\"label\":\"High availability and disaster recovery\",\"link\":\"/resilience\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"By Industry\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"AI Innovators\",\"link\":\"https://www.cockroachlabs.com/solutions/verticals/ai-innovators/\"},{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Fintech\",\"link\":\"/solutions/verticals/financialservices/\"},{\"__typename\":\"MenuItems\",\"label\":\"Cybersecurity\",\"link\":\"https://www.cockroachlabs.com/solutions/verticals/cybersecurity\"},{\"__typename\":\"MenuItems\",\"label\":\"Gambling\",\"link\":\"/solutions/verticals/gambling/\"},{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"link\":\"/solutions/verticals/gaming/\"},{\"__typename\":\"MenuItems\",\"label\":\"Healthcare\",\"link\":\"/solutions/verticals/healthcare\"},{\"__typename\":\"MenuItems\",\"label\":\"Manufacturing \u0026 Logistics\",\"link\":\"/solutions/verticals/manufacturing-logistics/\"},{\"__typename\":\"MenuItems\",\"label\":\"Media \u0026 Streaming\",\"link\":\"/solutions/verticals/media/\"},{\"__typename\":\"MenuItems\",\"label\":\"Quant/Trading \u0026 Research\",\"link\":\"/solutions/verticals/quantitative-investment/\"},{\"__typename\":\"MenuItems\",\"label\":\"Retail \u0026 eCommerce\",\"link\":\"/solutions/verticals/retail-ecommerce/\"},{\"__typename\":\"MenuItems\",\"label\":\"SaaS\",\"link\":\"/solutions/verticals/saas/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"By Use Case\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Vector Search\",\"link\":\"https://www.cockroachlabs.com/solutions/usecases/generative-ai/\"},{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Wallet\",\"link\":\"/solutions/usecases/banking-and-wallet\"},{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"link\":\"/solutions/verticals/gaming/\"},{\"__typename\":\"MenuItems\",\"label\":\"Identity Access Management\",\"link\":\"/solutions/usecases/identity-access-management/\"},{\"__typename\":\"MenuItems\",\"label\":\"IoT \u0026 Device Mgmt\",\"link\":\"/solutions/usecases/iot-and-device-management\"},{\"__typename\":\"MenuItems\",\"label\":\"Orders \u0026 Inventory Management\",\"link\":\"/solutions/usecases/orders-and-inventory-management/\"},{\"__typename\":\"MenuItems\",\"label\":\"Payments\",\"link\":\"/solutions/usecases/payments/\"},{\"__typename\":\"MenuItems\",\"label\":\"Routing \u0026 Logistics\",\"link\":\"/solutions/usecases/routing-and-logistics\"},{\"__typename\":\"MenuItems\",\"label\":\"User Metadata\",\"link\":\"/solutions/usecases/user-accounts-and-metadata/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"By Initiative\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Database Modernization\",\"link\":\"https://www.cockroachlabs.com/database-modernization/\"},{\"__typename\":\"MenuItems\",\"label\":\"Architectural Simplification\",\"link\":\"/architectural-simplification/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"Resources\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Documentation\",\"link\":\"https://docs.cockroachlabs.com/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"Connect\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Events\",\"link\":\"/events/\"},{\"__typename\":\"MenuItems\",\"label\":\"Podcast\",\"link\":\"/big-ideas-podcast/\"},{\"__typename\":\"MenuItems\",\"label\":\"Professional Services\",\"link\":\"/company/professional-services/\"},{\"__typename\":\"MenuItems\",\"label\":\"Support\",\"link\":\"/support/\"},{\"__typename\":\"MenuItems\",\"label\":\"Webinars\",\"link\":\"/community/webinars/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"Learn\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"Blog\",\"link\":\"/blog/\"},{\"__typename\":\"MenuItems\",\"label\":\"Cockroach University\",\"link\":\"https://learn.cockroachlabs.com/\"},{\"__typename\":\"MenuItems\",\"label\":\"Competitive Comparisons\",\"link\":\"/compare/\"},{\"__typename\":\"MenuItems\",\"label\":\"Guides\",\"link\":\"/guides/\"},{\"__typename\":\"MenuItems\",\"label\":\"Product Demos\",\"link\":\"/resource/product-demos/\"}]}},{\"__typename\":\"MenuItems\",\"label\":\"Company\",\"menuCollection\":{\"__typename\":\"MenuItemsMenuCollection\",\"items\":[{\"__typename\":\"MenuItems\",\"label\":\"About\",\"link\":\"/about/\"},{\"__typename\":\"MenuItems\",\"label\":\"Careers\",\"link\":\"/careers/\"},{\"__typename\":\"MenuItems\",\"label\":\"Contact Us\",\"link\":\"/contact/\"},{\"__typename\":\"MenuItems\",\"label\":\"Legal Notices\",\"link\":\"/legal-notices/\"},{\"__typename\":\"MenuItems\",\"label\":\"News / Press\",\"link\":\"/press/\"},{\"__typename\":\"MenuItems\",\"label\":\"Partners\",\"link\":\"/partners/\"},{\"__typename\":\"MenuItems\",\"label\":\"Privacy\",\"link\":\"/privacy/\"},{\"__typename\":\"MenuItems\",\"label\":\"Security\",\"link\":\"/security/\"},{\"__typename\":\"MenuItems\",\"label\":\" Trust Center\",\"link\":\"/trust-center/\"}]}}]}}]}}]]}]\n"])</script><script>self.__next_f.push([1,"16:I[72972,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"4767\",\"static/chunks/4767-3be12bccc3485fef.js\",\"5902\",\"static/chunks/5902-b023fdecad77ece9.js\",\"5181\",\"static/chunks/5181-a7292807635098af.js\",\"1166\",\"static/chunks/1166-3e5e918f62c8a9c5.js\",\"7518\",\"static/chunks/7518-f6cc01f2368b270a.js\",\"308\",\"static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js\"],\"\"]\n14:[\"$\",\"div\",null,{\"className\":\"border-b-4 border-solid border-iridiscent-blue-600 bg-deep-purple-700\",\"children\":[[\"$\",\"div\",null,{\"className\":\"fixed h-1 w-full bg-iridiscent-blue-600\"}],[[\"$\",\"div\",null,{\"className\":\"contain-layout relative bg-no-repeat bg-center bg-cover\",\"style\":{},\"children\":[\"$undefined\",[\"$\",\"section\",null,{\"className\":\"mx-auto px-3 xl:max-w-[1140px] 2xl:max-w-[1320px] py-32 lg:py-32\",\"children\":[[\"$\",\"h1\",null,{\"className\":\"mb-2 bg-gradient-to-r from-electric-purple-500 to-iridiscent-blue-500 bg-clip-text text-center text-[116px] font-bold leading-[139px] text-transparent\",\"children\":\"404\"}],[\"$\",\"h2\",null,{\"className\":\"mb-4 text-center text-[32px] font-semibold leading-[38px] text-white\",\"children\":\"Sorry, this page bugged out.\"}],[\"$\",\"div\",null,{\"className\":\"mx-auto my-9 h-0.5 w-full max-w-[200px] bg-iridiscent-blue-600\"}],[\"$\",\"h3\",null,{\"className\":\"mb-2 text-center text-base font-semibold text-white\",\"children\":\"Maybe try:\"}],[\"$\",\"ul\",null,{\"className\":\"my-8\",\"children\":[[\"$\",\"li\",\"The history of databases at Netflix\",{\"className\":\"mb-3 text-center font-roboto-mono text-white hover:text-iridiscent-blue-600\",\"children\":[\"$\",\"$L16\",null,{\"href\":\"/roachfest/2022/the-journey-of-cockroachdb-in-netflix/\",\"children\":[\"⟶ \",\"The history of databases at Netflix\"]}]}],[\"$\",\"li\",\"DoorDash's Journey from AWS Aurora to CockroachDB\",{\"className\":\"mb-3 text-center font-roboto-mono text-white hover:text-iridiscent-blue-600\",\"children\":[\"$\",\"$L16\",null,{\"href\":\"/roachfest/2023/doordashs-journey-from-aurora-postgres-to-cockroachdb/\",\"children\":[\"⟶ \",\"DoorDash's Journey from AWS Aurora to CockroachDB\"]}]}]]}]]}]]}]]]}]\n"])</script><script>self.__next_f.push([1,"11d:I[94737,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"4767\",\"static/chunks/4767-3be12bccc3485fef.js\",\"5902\",\"static/chunks/5902-b023fdecad77ece9.js\",\"5181\",\"static/chunks/5181-a7292807635098af.js\",\"1166\",\"static/chunks/1166-3e5e918f62c8a9c5.js\",\"7518\",\"static/chunks/7518-f6cc01f2368b270a.js\",\"308\",\"static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js\"],\"default\"]\n11e:I[87973,[\"2941\",\"static/chunks/2941-ea6fdd90a456b354.js\",\"4767\",\"static/chunks/4767-3be12bccc3485fef.js\",\"5902\",\"static/chunks/5902-b023fdecad77ece9.js\",\"5181\",\"static/chunks/5181-a7292807635098af.js\",\"1166\",\"static/chunks/1166-3e5e918f62c8a9c5.js\",\"7518\",\"static/chunks/7518-f6cc01f2368b270a.js\",\"308\",\"static/chunks/app/blog/%5Bslug%5D/page-dd2ce34859366544.js\"],\"default\"]\n20:{\"__typename\":\"Sys\",\"id\":\"3F3zZlYkHnkHMMlChW6U5e\"}\n22:[\"primaryDark\"]\n23:[\"xs\"]\n24:[\"full\"]\n21:{\"__typename\":\"ComponentButton\",\"internalName\":\"[Global Nav] Enroll now\",\"label\":\"Try CockroachDB\",\"url\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global_2\",\"longUrl\":null,\"type\":\"$22\",\"size\":\"$23\",\"rounded\":\"$24\",\"customStyle\":null,\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\n25:{\"__typename\":\"ContentfulMetadata\"}\n26:{\"__typename\":\"Asset\",\"description\":null,\"title\":\"cockroachlabs-logo-170\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4L99WneFfQZfEiTbAz7FBY/cde51d5ab34e96fe246fbc8fe4dea72c/cockroachlabs-logo-170.png\",\"width\":340,\"height\":48}\n1f:{\"__typename\":\"ComponentHeader\",\"sys\":\"$20\",\"ctaButton\":\"$21\",\"contentfulMetadata\":\"$25\",\"internalName\":\"[Ninetailed Variant] Global Header\",\"announcementBar\":false,\"announcementBarText\":\"RoachFest is back — Live \u0026 virtual | June 25, London | Register now →\",\"announcementBarUrl\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"logo\":\"$26\",\"contactUsLink\":\"/contact\",\"signInLink\":\"https://cockroachlabs.cloud/\",\"startLink\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\"}\n1e:[\"$1f\"]\n1d:{\"__typename\":\"NtExperienceNt_variantsCollection\",\"items\":\"$1e\"}\n27:{\"__typename\":\""])</script><script>self.__next_f.push([1,"Sys\",\"id\":\"1SrZaLT4lfwBBAX6vktZca\"}\n2b:{\"id\":\"4sdqhd9ekH57ufrme4VNWC\",\"title\":\"New Global Header Rev\"}\n2d:{\"id\":\"3F3zZlYkHnkHMMlChW6U5e\",\"hidden\":false}\n2c:[\"$2d\"]\n2a:{\"type\":\"EntryReplacement\",\"baseline\":\"$2b\",\"variants\":\"$2c\"}\n2f:{\"id\":\"4sdqhd9ekH57ufrme4VNWC\"}\n31:{\"id\":\"\",\"hidden\":false}\n30:[\"$31\"]\n2e:{\"type\":\"EntryReplacement\",\"baseline\":\"$2f\",\"variants\":\"$30\"}\n29:[\"$2a\",\"$2e\"]\n32:[0.5,0.5]\n28:{\"traffic\":0.2,\"components\":\"$29\",\"distribution\":\"$32\",\"primaryMetric\":\"38470cbd-28ba-4b31-a3e6-7da903ae736e\",\"distributionType\":\"even-split\"}\n33:{\"__typename\":\"NtAudience\",\"ntAudienceId\":\"2AtTnKsNI6x2tbub5fCs4l\",\"ntDescription\":null,\"ntName\":\"All \"}\n1c:{\"__typename\":\"NtExperience\",\"ntVariantsCollection\":\"$1d\",\"sys\":\"$27\",\"ntExperienceId\":\"2d00ac3b-91fe-45d2-ba6b-eea3e8330b67\",\"ntName\":\"[Ninetailed] Global Nav Bar Experiment (Try for free)\",\"ntType\":\"nt_experiment\",\"ntConfig\":\"$28\",\"ntAudience\":\"$33\"}\n1b:[\"$1c\"]\n1a:{\"__typename\":\"ComponentHeaderNt_experiencesCollection\",\"items\":\"$1b\"}\n34:{\"__typename\":\"Sys\",\"id\":\"4sdqhd9ekH57ufrme4VNWC\"}\n35:{\"__typename\":\"ContentfulMetadata\"}\n36:{\"__typename\":\"Asset\",\"description\":null,\"title\":\"cockroachlabs-logo-170\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4L99WneFfQZfEiTbAz7FBY/cde51d5ab34e96fe246fbc8fe4dea72c/cockroachlabs-logo-170.png\",\"width\":340,\"height\":48}\n3f:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB for Agents\",\"labelColor\":null,\"link\":\"/product/ai/\"}\n40:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Fully-Managed Cloud \",\"labelColor\":null,\"link\":\"/product/cloud/\"}\n41:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Bring Your Own Cloud\",\"labelColor\":null,\"link\":\"https://cockroachlabs.com/product/cloud/bring-your-own-cloud\"}\n42:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Enterprise\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/product/enterprise/\"}\n43:{\"__typename\":\"MenuItems\",\"label\":\"Partner Integrations\",\"labelColor\":null,\"link\":\"/product/partner-integrations/\"}\n44:{\"__typename\":\"MenuItems\",\"label\":\"Migrations\",\"labelColor\":null,\"link\":\"https://www."])</script><script>self.__next_f.push([1,"cockroachlabs.com/migrations/\"}\n45:{\"__typename\":\"MenuItems\",\"label\":\"Latest release\",\"labelColor\":null,\"link\":\"/whatsnew/\"}\n46:{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"labelColor\":null,\"link\":\"/pricing\"}\n3e:[\"$3f\",\"$40\",\"$41\",\"$42\",\"$43\",\"$44\",\"$45\",\"$46\"]\n3d:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$3e\"}\n3c:{\"__typename\":\"MenuItems\",\"label\":\" \",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$3d\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\n3b:[\"$3c\"]\n3a:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$3b\"}\n49:{}\n4c:{}\n4f:{}\n50:[]\n4e:{\"data\":\"$4f\",\"marks\":\"$50\",\"value\":\"CockroachDB\",\"nodeType\":\"text\"}\n4d:[\"$4e\"]\n4b:{\"data\":\"$4c\",\"content\":\"$4d\",\"nodeType\":\"heading-3\"}\n52:{}\n55:{}\n56:[]\n54:{\"data\":\"$55\",\"marks\":\"$56\",\"value\":\"The cloud native, distributed SQL database enterprises trust to run mission-critical applications that scale fast, survive disaster, and thrive everywhere.\",\"nodeType\":\"text\"}\n53:[\"$54\"]\n51:{\"data\":\"$52\",\"content\":\"$53\",\"nodeType\":\"paragraph\"}\n5a:{\"id\":\"AL3FSfdNHpT50JJEc1Sns\",\"type\":\"Link\",\"linkType\":\"Entry\"}\n59:{\"sys\":\"$5a\"}\n58:{\"target\":\"$59\"}\n5b:[]\n57:{\"data\":\"$58\",\"content\":\"$5b\",\"nodeType\":\"embedded-entry-block\"}\n5d:{}\n60:{}\n61:[]\n5f:{\"data\":\"$60\",\"marks\":\"$61\",\"value\":\"\",\"nodeType\":\"text\"}\n5e:[\"$5f\"]\n5c:{\"data\":\"$5d\",\"content\":\"$5e\",\"nodeType\":\"paragraph\"}\n4a:[\"$4b\",\"$51\",\"$57\",\"$5c\"]\n48:{\"data\":\"$49\",\"content\":\"$4a\",\"nodeType\":\"document\"}\n66:{\"__typename\":\"Sys\",\"id\":\"AL3FSfdNHpT50JJEc1Sns\"}\n67:[\"sm\"]\n68:[\"full\"]\n69:[\"header-button\"]\n65:{\"__typename\":\"ComponentButton\",\"sys\":\"$66\",\"internalName\":\"[Menu] Product Overview\",\"label\":\"Product Overview\",\"url\":\"https://www.cockroachlabs.com/product/overview/\",\"longUrl\":null,\"type\":null,\"size\":\"$67\",\"rounded\":\"$68\",\"customStyle\":\"$69\",\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\n64:[\"$65\"]\n63:{\"__typename\":\"MenuItemsCtaEntries\",\"block\":\"$64\"}\n62:{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":\"$63\"}\n47:{\"__typename\":\"MenuItemsCta\",\"json\":\"$48\",\"links\":\"$62\"}\n6a:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":"])</script><script>self.__next_f.push([1,"\"what-is-dist-sql\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3IxxzR4MUE6aWz33L9PuGu/c7d233621deb26b2372be9c790e970ad/what-is-dist-sql.png\",\"width\":288,\"height\":339}\n6b:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"enterprise-downtime-guide\",\"url\":\"https://images.ctfassets.net/00voh0j35590/76s4JBRoX1MLh1AIJzGRrP/9dcf819fc8bfac91573327af7ae9ab8f/enterprise-downtime-guide.jpg\",\"width\":431,\"height\":507}\n39:{\"__typename\":\"MenuItems\",\"label\":\"Product\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$3a\",\"narrow\":false,\"twoColumn\":null,\"cta\":\"$47\",\"ctaPosition\":true,\"media\":\"$6a\",\"mediaLink\":\"https://www.cockroachlabs.com/blog/what-is-distributed-sql/\",\"media2\":\"$6b\",\"mediaLink2\":\"https://www.cockroachlabs.com/guides/the-state-of-resilience-2025/\"}\n72:{\"__typename\":\"MenuItems\",\"label\":\"Agent State Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/agent-state-management\"}\n73:{\"__typename\":\"MenuItems\",\"label\":\"AI\",\"labelColor\":null,\"link\":\"/solutions/usecases/ai\"}\n74:{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Wallet\",\"labelColor\":null,\"link\":\"/solutions/usecases/banking-and-wallet\"}\n75:{\"__typename\":\"MenuItems\",\"label\":\"Data Modernization\",\"labelColor\":null,\"link\":\"/database-modernization/\"}\n76:{\"__typename\":\"MenuItems\",\"label\":\"Gaming Platform\",\"labelColor\":null,\"link\":\"/solutions/usecases/gaming-platforms\"}\n77:{\"__typename\":\"MenuItems\",\"label\":\"Identity Access Mgmt (IAM)\",\"labelColor\":null,\"link\":\"/solutions/usecases/identity-access-management\"}\n78:{\"__typename\":\"MenuItems\",\"label\":\"IoT \u0026 Device Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/iot-and-device-management\"}\n79:{\"__typename\":\"MenuItems\",\"label\":\"Order \u0026 Inventory Mgmt\",\"labelColor\":null,\"link\":\"/solutions/usecases/orders-and-inventory-management\"}\n7a:{\"__typename\":\"MenuItems\",\"label\":\"Payments\",\"labelColor\":null,\"link\":\"/solutions/usecases/payments\"}\n7b:{\"__typename\":\"MenuItems\",\"label\":\"Routing \u0026 Logistics\",\"labelColor\":null,\"link\":\"/solutions/usecases/routing-and-logistics\"}\n7c:{\"__typename\":\"MenuItems\",\"label\":\"User Metadata\",\"labelColor\""])</script><script>self.__next_f.push([1,":null,\"link\":\"/solutions/usecases/user-accounts-and-metadata/\"}\n7d:{\"__typename\":\"MenuItems\",\"label\":\"Vector Search\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/usecases/generative-ai/\"}\n71:[\"$72\",\"$73\",\"$74\",\"$75\",\"$76\",\"$77\",\"$78\",\"$79\",\"$7a\",\"$7b\",\"$7c\",\"$7d\"]\n70:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$71\"}\n6f:{\"__typename\":\"MenuItems\",\"label\":\"By Use Case\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$70\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\n81:{\"__typename\":\"MenuItems\",\"label\":\"AI Innovators\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/ai-innovators/\"}\n82:{\"__typename\":\"MenuItems\",\"label\":\"Cybersecurity\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/cybersecurity\"}\n83:{\"__typename\":\"MenuItems\",\"label\":\"Financial Services\",\"labelColor\":null,\"link\":\"/solutions/verticals/financialservices/\"}\n84:{\"__typename\":\"MenuItems\",\"label\":\"Gambling\",\"labelColor\":null,\"link\":\"/solutions/verticals/gambling/\"}\n85:{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"labelColor\":null,\"link\":\"/solutions/verticals/gaming/\"}\n86:{\"__typename\":\"MenuItems\",\"label\":\"Healthcare\",\"labelColor\":null,\"link\":\"/solutions/verticals/healthcare\"}\n87:{\"__typename\":\"MenuItems\",\"label\":\"Manufacturing \u0026 Logistics\",\"labelColor\":null,\"link\":\"/solutions/verticals/manufacturing-logistics/\"}\n88:{\"__typename\":\"MenuItems\",\"label\":\"Media \u0026 Streaming\",\"labelColor\":null,\"link\":\"/solutions/verticals/media/\"}\n89:{\"__typename\":\"MenuItems\",\"label\":\"Quant/Trading \u0026 Research\",\"labelColor\":null,\"link\":\"/solutions/verticals/quantitative-investment/\"}\n8a:{\"__typename\":\"MenuItems\",\"label\":\"Retail \u0026 eCommerce\",\"labelColor\":null,\"link\":\"/solutions/verticals/retail-ecommerce/\"}\n8b:{\"__typename\":\"MenuItems\",\"label\":\"SaaS\",\"labelColor\":null,\"link\":\"https://www.cockroachlabs.com/solutions/verticals/saas/\"}\n80:[\"$81\",\"$82\",\"$83\",\"$84\",\"$85\",\"$86\",\"$87\",\"$88\",\"$89\",\"$8a\",\"$8b\"]\n7f:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$80\"}\n7e:{\"__typename\":\"MenuItems\",\"label\":\"By Ve"])</script><script>self.__next_f.push([1,"rtical\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$7f\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\n6e:[\"$6f\",\"$7e\"]\n6d:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$6e\"}\n8e:{}\n91:{}\n94:{}\n95:[]\n93:{\"data\":\"$94\",\"marks\":\"$95\",\"value\":\"Customers\",\"nodeType\":\"text\"}\n92:[\"$93\"]\n90:{\"data\":\"$91\",\"content\":\"$92\",\"nodeType\":\"heading-3\"}\n97:{}\n9a:{}\n9b:[]\n99:{\"data\":\"$9a\",\"marks\":\"$9b\",\"value\":\"Industry leaders trust CockroachDB to run their most data-intensive, mission-critical applications.\",\"nodeType\":\"text\"}\n98:[\"$99\"]\n96:{\"data\":\"$97\",\"content\":\"$98\",\"nodeType\":\"paragraph\"}\n9f:{\"id\":\"6WiuJnSC9QsEVjqGRMSi9N\",\"type\":\"Link\",\"linkType\":\"Entry\"}\n9e:{\"sys\":\"$9f\"}\n9d:{\"target\":\"$9e\"}\na0:[]\n9c:{\"data\":\"$9d\",\"content\":\"$a0\",\"nodeType\":\"embedded-entry-block\"}\na2:{}\na5:{}\na6:[]\na4:{\"data\":\"$a5\",\"marks\":\"$a6\",\"value\":\"\",\"nodeType\":\"text\"}\na3:[\"$a4\"]\na1:{\"data\":\"$a2\",\"content\":\"$a3\",\"nodeType\":\"paragraph\"}\n8f:[\"$90\",\"$96\",\"$9c\",\"$a1\"]\n8d:{\"data\":\"$8e\",\"content\":\"$8f\",\"nodeType\":\"document\"}\nab:{\"__typename\":\"Sys\",\"id\":\"6WiuJnSC9QsEVjqGRMSi9N\"}\nac:[\"sm\"]\nad:[\"full\"]\nae:[\"header-button\"]\naa:{\"__typename\":\"ComponentButton\",\"sys\":\"$ab\",\"internalName\":\"Explore customer stories\",\"label\":\"Explore customer stories\",\"url\":\"https://www.cockroachlabs.com/customers/\",\"longUrl\":null,\"type\":null,\"size\":\"$ac\",\"rounded\":\"$ad\",\"customStyle\":\"$ae\",\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\na9:[\"$aa\"]\na8:{\"__typename\":\"MenuItemsCtaEntries\",\"block\":\"$a9\"}\na7:{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":\"$a8\"}\n8c:{\"__typename\":\"MenuItemsCta\",\"json\":\"$8d\",\"links\":\"$a7\"}\naf:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"modernize-inf\",\"url\":\"https://images.ctfassets.net/00voh0j35590/1P4tI5v8ElwGQX8189XfHr/46332d3b90382698e5133395e3c00ae2/modernize-inf.jpg\",\"width\":287,\"height\":160}\nb0:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Group 19597\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6ljtnICVBI7s4hKzVt6Nbs/3fc2bedaeadc8c65213354a302554155/Group_19597.png\",\"width\":431,\"height\":240}\n6c:{\"__typename\":\"MenuI"])</script><script>self.__next_f.push([1,"tems\",\"label\":\"Solutions\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$6d\",\"narrow\":false,\"twoColumn\":null,\"cta\":\"$8c\",\"ctaPosition\":true,\"media\":\"$af\",\"mediaLink\":\"/database-modernization/\",\"media2\":\"$b0\",\"mediaLink2\":\"/resilience/\"}\nb7:{\"__typename\":\"MenuItems\",\"label\":\"Blog\",\"labelColor\":null,\"link\":\"/blog/\"}\nb8:{\"__typename\":\"MenuItems\",\"label\":\"Cockroach University\",\"labelColor\":null,\"link\":\"https://learn.cockroachlabs.com/\"}\nb9:{\"__typename\":\"MenuItems\",\"label\":\"Competitive Comparisons\",\"labelColor\":null,\"link\":\"/compare/\"}\nba:{\"__typename\":\"MenuItems\",\"label\":\"Guides\",\"labelColor\":null,\"link\":\"/guides/\"}\nbb:{\"__typename\":\"MenuItems\",\"label\":\"Product Demos\",\"labelColor\":null,\"link\":\"/resource/product-demos/\"}\nb6:[\"$b7\",\"$b8\",\"$b9\",\"$ba\",\"$bb\"]\nb5:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$b6\"}\nb4:{\"__typename\":\"MenuItems\",\"label\":\"Learn\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$b5\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\nbf:{\"__typename\":\"MenuItems\",\"label\":\"Events\",\"labelColor\":null,\"link\":\"/events/\"}\nc0:{\"__typename\":\"MenuItems\",\"label\":\"Podcast\",\"labelColor\":null,\"link\":\"/big-ideas-podcast/\"}\nc1:{\"__typename\":\"MenuItems\",\"label\":\"Professional Services\",\"labelColor\":null,\"link\":\"/company/professional-services/\"}\nc2:{\"__typename\":\"MenuItems\",\"label\":\"Support\",\"labelColor\":null,\"link\":\"/support/\"}\nc3:{\"__typename\":\"MenuItems\",\"label\":\"Webinars\",\"labelColor\":null,\"link\":\"/community/webinars/\"}\nbe:[\"$bf\",\"$c0\",\"$c1\",\"$c2\",\"$c3\"]\nbd:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$be\"}\nbc:{\"__typename\":\"MenuItems\",\"label\":\"Connect\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$bd\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\nb3:[\"$b4\",\"$bc\"]\nb2:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$b3\"}\nc6:{}\nc9:{}\ncc:{}\ncd:[]\ncb:{\"data\":\"$cc\",\"marks\":\"$cd\",\"value\":\"Documentation\",\"nodeType\":\"text\"}\nca:[\"$cb\"]\nc8:{\"data\":\"$c9\",\"content\":\"$ca\",\"nodeType\":\"heading-3\"}\ncf:{}\nd2:{}\nd3:[]\nd1:{\"data\":\"$d2\",\"marks\":\"$d3\",\"value\":\"Access tutorials, guides, example application, and much mor"])</script><script>self.__next_f.push([1,"e\",\"nodeType\":\"text\"}\nd0:[\"$d1\"]\nce:{\"data\":\"$cf\",\"content\":\"$d0\",\"nodeType\":\"paragraph\"}\nd7:{\"id\":\"56fXxWRDgEm3Jmf0uQDcZM\",\"type\":\"Link\",\"linkType\":\"Entry\"}\nd6:{\"sys\":\"$d7\"}\nd5:{\"target\":\"$d6\"}\nd8:[]\nd4:{\"data\":\"$d5\",\"content\":\"$d8\",\"nodeType\":\"embedded-entry-block\"}\nda:{}\ndd:{}\nde:[]\ndc:{\"data\":\"$dd\",\"marks\":\"$de\",\"value\":\"\",\"nodeType\":\"text\"}\ndb:[\"$dc\"]\nd9:{\"data\":\"$da\",\"content\":\"$db\",\"nodeType\":\"paragraph\"}\nc7:[\"$c8\",\"$ce\",\"$d4\",\"$d9\"]\nc5:{\"data\":\"$c6\",\"content\":\"$c7\",\"nodeType\":\"document\"}\ne3:{\"__typename\":\"Sys\",\"id\":\"56fXxWRDgEm3Jmf0uQDcZM\"}\ne4:[\"sm\"]\ne5:[\"full\"]\ne6:[\"header-button\"]\ne2:{\"__typename\":\"ComponentButton\",\"sys\":\"$e3\",\"internalName\":\"Explore Docs\",\"label\":\"Explore Docs\",\"url\":\"https://docs.cockroachlabs.com/\",\"longUrl\":null,\"type\":null,\"size\":\"$e4\",\"rounded\":\"$e5\",\"customStyle\":\"$e6\",\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\ne1:[\"$e2\"]\ne0:{\"__typename\":\"MenuItemsCtaEntries\",\"block\":\"$e1\"}\ndf:{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":\"$e0\"}\nc4:{\"__typename\":\"MenuItemsCta\",\"json\":\"$c5\",\"links\":\"$df\"}\ne7:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"rf26\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3NViyVYW37PI3K0OY2mjER/4dcc464bc1e4d6769964b511bc685a40/rf26.png\",\"width\":576,\"height\":678}\nb1:{\"__typename\":\"MenuItems\",\"label\":\"Resources\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$b2\",\"narrow\":false,\"twoColumn\":null,\"cta\":\"$c4\",\"ctaPosition\":true,\"media\":\"$e7\",\"mediaLink\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"media2\":null,\"mediaLink2\":null}\nea:[]\ne9:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$ea\"}\ne8:{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"labelColor\":null,\"link\":\"/pricing\",\"menuCollection\":\"$e9\",\"narrow\":null,\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null,\"media\":null,\"mediaLink\":\"This is for header dropdown menu media link.\",\"media2\":null,\"mediaLink2\":null}\nf1:{\"__typename\":\"MenuItems\",\"label\":\"Careers\",\"labelColor\":null,\"link\":\"/careers/\"}\nf2:{\"__typename\":\"MenuItems\",\"label\":\"Partners\",\"labelColor\":null,\"link\":\"/partners/"])</script><script>self.__next_f.push([1,"\"}\nf3:{\"__typename\":\"MenuItems\",\"label\":\" Trust Center\",\"labelColor\":null,\"link\":\"/trust-center/\"}\nf0:[\"$f1\",\"$f2\",\"$f3\"]\nef:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$f0\"}\nee:{\"__typename\":\"MenuItems\",\"label\":\" \",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$ef\",\"twoColumn\":null,\"cta\":null,\"ctaPosition\":null}\ned:[\"$ee\"]\nec:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$ed\"}\nf6:{}\nf9:{}\nfc:{}\nfd:[]\nfb:{\"data\":\"$fc\",\"marks\":\"$fd\",\"value\":\"About Us\",\"nodeType\":\"text\"}\nfa:[\"$fb\"]\nf8:{\"data\":\"$f9\",\"content\":\"$fa\",\"nodeType\":\"heading-3\"}\nff:{}\n102:{}\n103:[]\n101:{\"data\":\"$102\",\"marks\":\"$103\",\"value\":\"Cockroach Labs is the creator \u2028of CockroachDB, the cloud native, distributed SQL database enterprises trust to run mission-critical applications that scale \u2028fast, survive disaster, and thrive everywhere.\",\"nodeType\":\"text\"}\n100:[\"$101\"]\nfe:{\"data\":\"$ff\",\"content\":\"$100\",\"nodeType\":\"paragraph\"}\n107:{\"id\":\"39wptWpxEWhuNJSv4c1uqo\",\"type\":\"Link\",\"linkType\":\"Entry\"}\n106:{\"sys\":\"$107\"}\n105:{\"target\":\"$106\"}\n108:[]\n104:{\"data\":\"$105\",\"content\":\"$108\",\"nodeType\":\"embedded-entry-block\"}\n10a:{}\n10d:{}\n10e:[]\n10c:{\"data\":\"$10d\",\"marks\":\"$10e\",\"value\":\"\",\"nodeType\":\"text\"}\n10b:[\"$10c\"]\n109:{\"data\":\"$10a\",\"content\":\"$10b\",\"nodeType\":\"paragraph\"}\nf7:[\"$f8\",\"$fe\",\"$104\",\"$109\"]\nf5:{\"data\":\"$f6\",\"content\":\"$f7\",\"nodeType\":\"document\"}\n113:{\"__typename\":\"Sys\",\"id\":\"39wptWpxEWhuNJSv4c1uqo\"}\n114:[\"sm\"]\n115:[\"full\"]\n116:[\"header-button\"]\n112:{\"__typename\":\"ComponentButton\",\"sys\":\"$113\",\"internalName\":\"Get to know us\",\"label\":\"Get to know us\",\"url\":\"https://www.cockroachlabs.com/about/\",\"longUrl\":null,\"type\":null,\"size\":\"$114\",\"rounded\":\"$115\",\"customStyle\":\"$116\",\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\n111:[\"$112\"]\n110:{\"__typename\":\"MenuItemsCtaEntries\",\"block\":\"$111\"}\n10f:{\"__typename\":\"MenuItemsCtaLinks\",\"entries\":\"$110\"}\nf4:{\"__typename\":\"MenuItemsCta\",\"json\":\"$f5\",\"links\":\"$10f\"}\n117:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"rf26\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3NViyVYW"])</script><script>self.__next_f.push([1,"37PI3K0OY2mjER/4dcc464bc1e4d6769964b511bc685a40/rf26.png\",\"width\":576,\"height\":678}\n118:{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Group 19596\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6lT25boB4PhmQXHHXNK7gp/7304f1979776bea93adc4f525b101f7d/Group_19596.png\",\"width\":431,\"height\":507}\neb:{\"__typename\":\"MenuItems\",\"label\":\" Company\",\"labelColor\":null,\"link\":null,\"menuCollection\":\"$ec\",\"narrow\":false,\"twoColumn\":null,\"cta\":\"$f4\",\"ctaPosition\":true,\"media\":\"$117\",\"mediaLink\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"media2\":\"$118\",\"mediaLink2\":\"https://www.cockroachlabs.com/blog/software-engineering-internship-jasmine-sun/\"}\n38:[\"$39\",\"$6c\",\"$b1\",\"$e8\",\"$eb\"]\n37:{\"__typename\":\"ComponentHeaderMenuCollection\",\"items\":\"$38\"}\n11a:[\"primaryDark\"]\n11b:[\"xs\"]\n11c:[\"full\"]\n119:{\"__typename\":\"ComponentButton\",\"internalName\":\"[Global Nav] Get started free\",\"label\":\"Try for free\",\"url\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\",\"longUrl\":null,\"type\":\"$11a\",\"size\":\"$11b\",\"rounded\":\"$11c\",\"customStyle\":null,\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}\n19:{\"__typename\":\"ComponentHeader\",\"ntExperiencesCollection\":\"$1a\",\"sys\":\"$34\",\"contentfulMetadata\":\"$35\",\"internalName\":\"New Global Header Rev\",\"announcementBar\":false,\"announcementBarText\":\"RoachFest is back — Live \u0026 virtual | June 25, London | Register now →\",\"announcementBarUrl\":\"https://www.cockroachlabs.com/roachfest/location/london/\",\"logo\":\"$36\",\"contactUsLink\":\"/contact\",\"signInLink\":\"https://cockroachlabs.cloud/\",\"startLink\":\"https://cockroachlabs.cloud/signup?referralId=cc_nav_global\",\"menuCollection\":\"$37\",\"ctaButton\":\"$119\"}\n18:[\"$19\"]\n17:{\"__typename\":\"ComponentHeaderCollection\",\"items\":\"$18\"}\n11f:T719,-- Agent 1:\nBEGIN;\nSET TRANSACTION ISOLATION LEVEL READ COMMITTED;\nSELECT claimed FROM task_claims WHERE task_id = 'compliance-check-8842';\n-- Agent 1 sees: false\n\n-- Agent 2, concurrently, in its own transaction:\nBEGIN;\nSET TRANSACTION ISOLATION LEVEL READ COMMITTED;\nSELECT claimed FROM task_cl"])</script><script>self.__next_f.push([1,"aims WHERE task_id = 'compliance-check-8842';\n-- Agent 2 also sees: false\n\n-- Agent 1 claims and commits:\nUPDATE task_claims SET claimed = true, claimed_by = 'agent-1'\n WHERE task_id = 'compliance-check-8842';\nCOMMIT;\n-- succeeds\n\n-- Agent 2 claims: its UPDATE waits briefly on agent-1's lock, then proceeds:\nUPDATE task_claims SET claimed = true, claimed_by = 'agent-2'\n WHERE task_id = 'compliance-check-8842';\nCOMMIT;\n-- also succeeds. No error, no retry. Both agents believe they own the task.\n-- claimed_by now silently reads 'agent-2'. Agent 1's claim is gone, and nothing logged it.\n\nRun the same interleaving at SERIALIZABLE, CockroachDB's default, and the second write doesn't get to silently win:\n\n-- Agent 1:\nBEGIN;\nSELECT claimed FROM task_claims WHERE task_id = 'compliance-check-8842';\n-- Agent 1 sees: false\n\n-- Agent 2, concurrently:\nBEGIN;\nSELECT claimed FROM task_claims WHERE task_id = 'compliance-check-8842';\n-- Agent 2 also sees: false\n\n-- Agent 1 claims and commits:\nUPDATE task_claims SET claimed = true, claimed_by = 'agent-1'\n WHERE task_id = 'compliance-check-8842';\nCOMMIT;\n-- succeeds\n\n-- Agent 2 claims:\nUPDATE task_claims SET claimed = true, claimed_by = 'agent-2'\n WHERE task_id = 'compliance-check-8842';\n-- ERROR: restart transaction: TransactionRetryWithProtoRefreshError: WriteTooOldError ...\n-- SQLSTATE: 40001\n-- Agent 2's transaction is aborted, not silently applied. The application catches\n-- 40001, retries, re-reads claimed = true, and backs off instead of double-claiming.\n120:T694,# AGENTS.md\n\n## Database rules for agents working in this repository\n\n- Default to SERIALIZABLE for any table more than one agent can write to. It's CockroachDB's default; don't lower it on shared-state tables without a documented reason. READ COMMITTED is fine for single-writer or read-heavy paths that can tolerate lost updates and write skew.\n\n- Connect as a scoped role, not root or a database owner:\n CREATE ROLE agent_worker WITH LOGIN PASSWORD '\u003csecret\u003e';\n GRANT SELECT, INSERT, UPDATE ON TABLE agent_context"])</script><script>self.__next_f.push([1," TO agent_worker;\n GRANT SELECT, INSERT ON TABLE agent_audit_log TO agent_worker;\n -- No UPDATE or DELETE grant on agent_audit_log. Enforce append-only at the\n -- database layer, not in application code that can be bypassed or changed.\n\n- Use AS OF SYSTEM TIME for reads that can tolerate a few seconds of staleness (context lookups, dashboards). It avoids contending with concurrent writers:\n SELECT * FROM agent_context AS OF SYSTEM TIME '-5s' WHERE task_id = $1;\n\n- Catch SQLSTATE 40001 on every write to a shared-state table and retry the transaction. Do not log-and-continue; it means another agent's write changed data yours depended on. Standard retry shape:\n BEGIN;\n SAVEPOINT cockroach_restart;\n -- statements here\n RELEASE SAVEPOINT cockroach_restart;\n COMMIT;\n -- on SQLSTATE 40001 before COMMIT: ROLLBACK TO SAVEPOINT cockroach_restart,\n -- then re-run the statements, RELEASE SAVEPOINT cockroach_restart, and COMMIT again.\n\n- Never issue UPDATE or DELETE against agent_audit_log from application code. The audit trail across an A2A boundary is only useful if it's provably append-only; that has to be true even if the calling code has a bug.\n129:{\"__typename\":\"MenuItems\",\"label\":\"Product overview\",\"link\":\"/product/overview\"}\n12a:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Fully-Managed Cloud \",\"link\":\"/product/cloud/\"}\n12b:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Bring Your Own Cloud\",\"link\":\"https://cockroachlabs.com/product/cloud/bring-your-own-cloud\"}\n12c:{\"__typename\":\"MenuItems\",\"label\":\"CockroachDB Enterprise\",\"link\":\"https://www.cockroachlabs.com/product/enterprise/\"}\n12d:{\"__typename\":\"MenuItems\",\"label\":\"Latest release\",\"link\":\"/whatsnew/\"}\n12e:{\"__typename\":\"MenuItems\",\"label\":\"Pricing\",\"link\":\"/pricing/\"}\n12f:{\"__typename\":\"MenuItems\",\"label\":\"Sign in\",\"link\":\"https://cockroachlabs.cloud/\"}\n128:[\"$129\",\"$12a\",\"$12b\",\"$12c\",\"$12d\",\"$12e\",\"$12f\"]\n127:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$128\"}\n126:{\"__typename\":\"MenuItems\",\"label\":\"Product\",\"menuCollection\":\"$127\"}\n133:{\"__type"])</script><script>self.__next_f.push([1,"name\":\"MenuItems\",\"label\":\"Customers\",\"link\":\"/customers/\"}\n134:{\"__typename\":\"MenuItems\",\"label\":\"Database Modernization\",\"link\":\"https://www.cockroachlabs.com/database-modernization/\"}\n135:{\"__typename\":\"MenuItems\",\"label\":\"High availability and disaster recovery\",\"link\":\"/resilience\"}\n132:[\"$133\",\"$134\",\"$135\"]\n131:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$132\"}\n130:{\"__typename\":\"MenuItems\",\"label\":\"Solutions\",\"menuCollection\":\"$131\"}\n139:{\"__typename\":\"MenuItems\",\"label\":\"AI Innovators\",\"link\":\"https://www.cockroachlabs.com/solutions/verticals/ai-innovators/\"}\n13a:{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Fintech\",\"link\":\"/solutions/verticals/financialservices/\"}\n13b:{\"__typename\":\"MenuItems\",\"label\":\"Cybersecurity\",\"link\":\"https://www.cockroachlabs.com/solutions/verticals/cybersecurity\"}\n13c:{\"__typename\":\"MenuItems\",\"label\":\"Gambling\",\"link\":\"/solutions/verticals/gambling/\"}\n13d:{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"link\":\"/solutions/verticals/gaming/\"}\n13e:{\"__typename\":\"MenuItems\",\"label\":\"Healthcare\",\"link\":\"/solutions/verticals/healthcare\"}\n13f:{\"__typename\":\"MenuItems\",\"label\":\"Manufacturing \u0026 Logistics\",\"link\":\"/solutions/verticals/manufacturing-logistics/\"}\n140:{\"__typename\":\"MenuItems\",\"label\":\"Media \u0026 Streaming\",\"link\":\"/solutions/verticals/media/\"}\n141:{\"__typename\":\"MenuItems\",\"label\":\"Quant/Trading \u0026 Research\",\"link\":\"/solutions/verticals/quantitative-investment/\"}\n142:{\"__typename\":\"MenuItems\",\"label\":\"Retail \u0026 eCommerce\",\"link\":\"/solutions/verticals/retail-ecommerce/\"}\n143:{\"__typename\":\"MenuItems\",\"label\":\"SaaS\",\"link\":\"/solutions/verticals/saas/\"}\n138:[\"$139\",\"$13a\",\"$13b\",\"$13c\",\"$13d\",\"$13e\",\"$13f\",\"$140\",\"$141\",\"$142\",\"$143\"]\n137:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$138\"}\n136:{\"__typename\":\"MenuItems\",\"label\":\"By Industry\",\"menuCollection\":\"$137\"}\n147:{\"__typename\":\"MenuItems\",\"label\":\"Vector Search\",\"link\":\"https://www.cockroachlabs.com/solutions/usecases/generative-ai/\"}\n148:{\"__typename\":\"MenuItems\",\"label\":\"Banking \u0026 Wallet\",\"link\":\"/solutions/usecases/b"])</script><script>self.__next_f.push([1,"anking-and-wallet\"}\n149:{\"__typename\":\"MenuItems\",\"label\":\"Gaming\",\"link\":\"/solutions/verticals/gaming/\"}\n14a:{\"__typename\":\"MenuItems\",\"label\":\"Identity Access Management\",\"link\":\"/solutions/usecases/identity-access-management/\"}\n14b:{\"__typename\":\"MenuItems\",\"label\":\"IoT \u0026 Device Mgmt\",\"link\":\"/solutions/usecases/iot-and-device-management\"}\n14c:{\"__typename\":\"MenuItems\",\"label\":\"Orders \u0026 Inventory Management\",\"link\":\"/solutions/usecases/orders-and-inventory-management/\"}\n14d:{\"__typename\":\"MenuItems\",\"label\":\"Payments\",\"link\":\"/solutions/usecases/payments/\"}\n14e:{\"__typename\":\"MenuItems\",\"label\":\"Routing \u0026 Logistics\",\"link\":\"/solutions/usecases/routing-and-logistics\"}\n14f:{\"__typename\":\"MenuItems\",\"label\":\"User Metadata\",\"link\":\"/solutions/usecases/user-accounts-and-metadata/\"}\n146:[\"$147\",\"$148\",\"$149\",\"$14a\",\"$14b\",\"$14c\",\"$14d\",\"$14e\",\"$14f\"]\n145:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$146\"}\n144:{\"__typename\":\"MenuItems\",\"label\":\"By Use Case\",\"menuCollection\":\"$145\"}\n153:{\"__typename\":\"MenuItems\",\"label\":\"Database Modernization\",\"link\":\"https://www.cockroachlabs.com/database-modernization/\"}\n154:{\"__typename\":\"MenuItems\",\"label\":\"Architectural Simplification\",\"link\":\"/architectural-simplification/\"}\n152:[\"$153\",\"$154\"]\n151:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$152\"}\n150:{\"__typename\":\"MenuItems\",\"label\":\"By Initiative\",\"menuCollection\":\"$151\"}\n158:{\"__typename\":\"MenuItems\",\"label\":\"Documentation\",\"link\":\"https://docs.cockroachlabs.com/\"}\n157:[\"$158\"]\n156:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$157\"}\n155:{\"__typename\":\"MenuItems\",\"label\":\"Resources\",\"menuCollection\":\"$156\"}\n15c:{\"__typename\":\"MenuItems\",\"label\":\"Events\",\"link\":\"/events/\"}\n15d:{\"__typename\":\"MenuItems\",\"label\":\"Podcast\",\"link\":\"/big-ideas-podcast/\"}\n15e:{\"__typename\":\"MenuItems\",\"label\":\"Professional Services\",\"link\":\"/company/professional-services/\"}\n15f:{\"__typename\":\"MenuItems\",\"label\":\"Support\",\"link\":\"/support/\"}\n160:{\"__typename\":\"MenuItems\",\"label\":\"Webinars\",\"link\":\"/community/webinars/\"}\n15b:[\"$15c\",\"$1"])</script><script>self.__next_f.push([1,"5d\",\"$15e\",\"$15f\",\"$160\"]\n15a:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$15b\"}\n159:{\"__typename\":\"MenuItems\",\"label\":\"Connect\",\"menuCollection\":\"$15a\"}\n164:{\"__typename\":\"MenuItems\",\"label\":\"Blog\",\"link\":\"/blog/\"}\n165:{\"__typename\":\"MenuItems\",\"label\":\"Cockroach University\",\"link\":\"https://learn.cockroachlabs.com/\"}\n166:{\"__typename\":\"MenuItems\",\"label\":\"Competitive Comparisons\",\"link\":\"/compare/\"}\n167:{\"__typename\":\"MenuItems\",\"label\":\"Guides\",\"link\":\"/guides/\"}\n168:{\"__typename\":\"MenuItems\",\"label\":\"Product Demos\",\"link\":\"/resource/product-demos/\"}\n163:[\"$164\",\"$165\",\"$166\",\"$167\",\"$168\"]\n162:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$163\"}\n161:{\"__typename\":\"MenuItems\",\"label\":\"Learn\",\"menuCollection\":\"$162\"}\n16c:{\"__typename\":\"MenuItems\",\"label\":\"About\",\"link\":\"/about/\"}\n16d:{\"__typename\":\"MenuItems\",\"label\":\"Careers\",\"link\":\"/careers/\"}\n16e:{\"__typename\":\"MenuItems\",\"label\":\"Contact Us\",\"link\":\"/contact/\"}\n16f:{\"__typename\":\"MenuItems\",\"label\":\"Legal Notices\",\"link\":\"/legal-notices/\"}\n170:{\"__typename\":\"MenuItems\",\"label\":\"News / Press\",\"link\":\"/press/\"}\n171:{\"__typename\":\"MenuItems\",\"label\":\"Partners\",\"link\":\"/partners/\"}\n172:{\"__typename\":\"MenuItems\",\"label\":\"Privacy\",\"link\":\"/privacy/\"}\n173:{\"__typename\":\"MenuItems\",\"label\":\"Security\",\"link\":\"/security/\"}\n174:{\"__typename\":\"MenuItems\",\"label\":\" Trust Center\",\"link\":\"/trust-center/\"}\n16b:[\"$16c\",\"$16d\",\"$16e\",\"$16f\",\"$170\",\"$171\",\"$172\",\"$173\",\"$174\"]\n16a:{\"__typename\":\"MenuItemsMenuCollection\",\"items\":\"$16b\"}\n169:{\"__typename\":\"MenuItems\",\"label\":\"Company\",\"menuCollection\":\"$16a\"}\n125:[\"$126\",\"$130\",\"$136\",\"$144\",\"$150\",\"$155\",\"$159\",\"$161\",\"$169\"]\n124:{\"__typename\":\"ComponentFooterMenuItemsCollection\",\"items\":\"$125\"}\n123:{\"__typename\":\"ComponentFooter\",\"internalName\":\"New Footer Rev\",\"menuItemsCollection\":\"$124\"}\n122:[\"$123\"]\n121:{\"__typename\":\"ComponentFooterCollection\",\"items\":\"$122\"}\n"])</script><script>self.__next_f.push([1,"5:[\"$\",\"div\",null,{\"children\":[[\"$\",\"$L13\",null,{\"headerData\":\"$17\",\"showAnnouncementBar\":false}],[\"$\",\"div\",null,{\"className\":\"blog-template\",\"children\":[[\"$\",\"div\",null,{\"className\":\"py-3 contain-layout relative bg-no-repeat bg-center bg-cover\",\"style\":{},\"children\":[\"$undefined\",[\"$\",\"section\",null,{\"className\":\"mx-auto px-3 xl:max-w-[1140px] 2xl:max-w-[1320px] py-0 sm:py-0 lg:py-0\",\"children\":[[\"$\",\"nav\",null,{\"className\":\"text-sm false\",\"aria-label\":\"Breadcrumb\",\"children\":[\"$\",\"ol\",null,{\"className\":\"inline-flex list-none p-0\",\"children\":[[\"$\",\"li\",\"Home\",{\"className\":\"flex items-center\",\"children\":[[\"$\",\"$L16\",null,{\"href\":\"/\",\"children\":\"Home\"}],[\"$\",\"span\",null,{\"className\":\"mx-1\",\"children\":\"/\"}]]}],[\"$\",\"li\",\"Resources\",{\"className\":\"flex items-center\",\"children\":[[\"$\",\"$L16\",null,{\"href\":\"/resources\",\"children\":\"Resources\"}],[\"$\",\"span\",null,{\"className\":\"mx-1\",\"children\":\"/\"}]]}],[\"$\",\"li\",\"Back to Blog\",{\"className\":\"flex items-center\",\"children\":[[\"$\",\"$L16\",null,{\"href\":\"/blog\",\"children\":\"Back to Blog\"}],false]}]]}]}],[\"$\",\"script\",null,{\"type\":\"application/ld+json\",\"dangerouslySetInnerHTML\":{\"__html\":\"{\\\"@context\\\":\\\"https://schema.org\\\",\\\"@type\\\":\\\"BreadcrumbList\\\",\\\"itemListElement\\\":[{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":1,\\\"name\\\":\\\"Home\\\",\\\"item\\\":\\\"https://www.cockroachlabs.com/\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":2,\\\"name\\\":\\\"Resources\\\",\\\"item\\\":\\\"https://www.cockroachlabs.com/resources/\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":3,\\\"name\\\":\\\"Blog\\\",\\\"item\\\":\\\"https://www.cockroachlabs.com/blog/\\\"},{\\\"@type\\\":\\\"ListItem\\\",\\\"position\\\":4,\\\"name\\\":\\\"A brief history of high availability\\\",\\\"item\\\":\\\"https://www.cockroachlabs.com/blog/brief-history-high-availability\\\"}]}\"}}]]}]]}],[\"$\",\"$L11d\",null,{}],[\"$\",\"$L11e\",null,{\"data\":{\"__typename\":\"TemplateBlog\",\"seo\":{\"__typename\":\"MetaSeo\",\"pageTitle\":\"A brief history of high availability\",\"pageDescription\":\"The perennial question of homo sapiens is, 'How did we get here?' Today we're going to take a crack at answering that: where 'here' is defined as 'high availability for web services'.\",\"openGraphImage\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"DataReplication ChristinaChung-1\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg\",\"width\":1158,\"height\":404},\"noIndex\":false,\"noFollow\":null,\"canonicalUrl\":\"https://www.cockroachlabs.com/blog/brief-history-high-availability/\",\"seoSchemaJson\":null},\"internalName\":\"A brief history of high availability\",\"sys\":{\"__typename\":\"Sys\",\"spaceId\":\"00voh0j35590\",\"publishedAt\":\"2025-01-23T17:57:19.522Z\",\"firstPublishedAt\":\"2024-03-05T07:06:51.737Z\",\"environmentId\":\"ab43b007-3cfb-450c-b575-1282ff083a83\",\"publishedVersion\":87},\"title\":\"A brief history of high availability\",\"slug\":\"brief-history-high-availability\",\"publishDate\":\"2023-03-23T00:00:00.000Z\",\"lastUpdatedDate\":\"2025-01-23T00:00:00.000Z\",\"tags\":[\"always-on database\",\"high availability database\",\"active-active\"],\"thumbnailImage\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"DataReplication ChristinaChung-1\",\"url\":\"https://images.ctfassets.net/00voh0j35590/4jENc2bY2uvMh9YXQQfRvS/0a08768c0b1282999303fbcf14d4572c/DataReplication_ChristinaChung-1.jpg\",\"width\":1158,\"height\":404},\"excerpt\":\"I once went to a website that had “hours of operation,” and was only “open” when its brick and mortar counterpart had its lights on. I felt perplexed and a little frustrated; computers are capable of running all day every day, so why shouldn’t they? I’d been habituated to the internet’s incredible availability guarantees.\\n\\nHowever, before the internet, 24/7 high availability wasn’t “a thing.” Availability was desirable, but not something to which we felt fundamentally entitled. We used computers only when we needed them; they weren’t waiting idly by on the off-chance a request came by. As the internet grew, those previously uncommon requests at 3am local time became prime business hours partway across the globe, and making sure that a computer could facilitate the request was important.\",\"buttonText\":\"Read Now\",\"authorsCollection\":{\"__typename\":\"TemplateBlogAuthorsCollection\",\"items\":[{\"__typename\":\"EntityPerson\",\"fullName\":\" Jessica Edwards\",\"link\":\"/author/jessica-edwards\",\"bio\":\"Jessica Edwards has been marketing for technical products and companies for a dog's age, and worked with non-profits for years before moving into the tech space. She has a deep love of storytelling, education, knowledge-sharing, and community building. After 13 years in NYC, she recently moved to Portland, OR. She is still getting used to the rain.\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"jessica headshot\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6tWdomQQHSO4QvtVE47p6o/6b2a82ca2c15076d4736546af8d28dae/jessica_headshot.jpeg\",\"width\":330,\"height\":330},\"role\":\"Director of Content\",\"linkedInUrl\":null,\"githubUrl\":null,\"company\":{\"__typename\":\"EntityCompany\",\"name\":\"Cockroach Labs\"}},{\"__typename\":\"EntityPerson\",\"fullName\":\"Sean Loiselle\",\"link\":\"/author/sean-loiselle\",\"bio\":null,\"headshot\":null,\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null}]},\"darkFooter\":false,\"blogDetail\":{\"__typename\":\"TemplateBlogBlogDetail\",\"json\":{\"data\":{},\"content\":[{\"data\":{\"target\":{\"sys\":{\"id\":\"IjA2FGDgYRrhqMEUWr2xk\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"I once went to a website that had “hours of operation,” and was only “open” when its brick and mortar counterpart had its lights on. I felt perplexed and a little frustrated; computers are capable of running all day every day, so why shouldn’t they? I’d been habituated to the internet’s incredible availability guarantees.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"However, before the internet, 24/7 high availability wasn’t “a thing.” Availability was desirable, but not something to which we felt fundamentally entitled. We used computers only when we needed them; they weren’t waiting idly by on the off-chance a request came by. As the internet grew, those previously uncommon requests at 3am local time became prime business hours partway across the globe, and making sure that a computer could facilitate the request was important.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Many systems, though, relied on only one computer to facilitate these requests — a single point of failure — which we all know is a story that doesn’t end well. To keep things up and running, we needed to distribute the load among multiple computers that could fulfill our needs. However, distributed computation, for all its well-known upsides, has sharp edges: in particular, synchronization and tolerating partial failures (fault tolerance) within a system. Each generation of engineers has iterated on these solutions to fit the needs of their time.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"How distribution came to databases is of particular interest because it is a difficult problem that has been much slower to develop than other areas of computer science. Certainly, software tracked the results of some distributed computation in a local database, but the state of the database itself was kept on a single machine. Why? Replicating state across machines is hard.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In this post, we take a look at how distributed databases have historically handled fault tolerance and—at a high level—what high availability looks like. We also walk through different types of high availability systems and address the \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/guides/do-more-with-less-with-distributed-sql/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"operational costs (and financial costs) of architectures that are vulnerable to downtime\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\".\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Fault Tolerance vs. High Availability\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Before we dive deep into the colorful history of high availability I want to clarify the distinction between these two terms that are often thought of as synonyms. While they are very closely related, they are not the same.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Fault tolerance implies zero service interruptions. If there is a failure somewhere the system will instantly switch to the backup solution and service will continue without interruption. High availability, on the other hand, implies that services are, well, \",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"highly available but not always available\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\". \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/what-is-fault-tolerance/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A system can be highly available but not fault tolerant\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\". I generally consider high availability to be an aspect of fault tolerance. In that, it addresses a certain type of “fault” (availability), but doesn’t necessarily talk about other aspects.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"This is somewhat of a contrived example, but basically everyone watches streaming content, so let’s consider a digital rights management service that determines whether a viewer can watch a particular video. The service could be configured to be highly available, in that it will always serve and return queries. However, it may not handle certain backend data correctly and get into a state where it returns errors, or denies all requests. In this case, it would be highly available (it is reachable and is returning an answer), but it is not fault tolerant, because something in the system has caused it to misbehave.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The caveat with this example is that there’s a fine line between a “bug” and fault tolerance. But the idea of fault tolerance is that the system can handle unexpected events gracefully and continue providing an excellent user experience. (If this example is interesting to you, I recommend taking a look at how \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://netflix.github.io/chaosmonkey/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Netflix’s chaos monkey\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" randomly terminates instances in production to ensure that engineers implement their services to be resilient to instance failures).\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Okay, let’s get into some highly available database examples.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What are the Types of High Availability Databases?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"High availability databases generally fall into two categories, with a third category becoming more common:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Active-passive databases\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\": Where a database has an active node that processes requests with a hot spare that is ready to go in a disaster\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Active-active databases\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\": Where a database has active nodes that shard data and perform writes to the database\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Multi-active databases\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\": Where a database has at least three active nodes, each of which can perform reads and writes for any data in the cluster without generating conflicts.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"ordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What is Active-Passive Availability?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Active-passive availability means the database has an active node that processes requests with a hot spare that is ready to go in a disaster. The active-passive availability model works on the two-node concept of one node receiving all requests that it then replicates to its follower.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In the days of yore, databases ran on single machines. There was only one node and it handled all reads and all writes. There was no such thing as a “partial failure”; the database was either up or down.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Total failure of a single database was a two-fold problem for the internet; first, computers were being accessed around the clock, so downtime was more likely to directly impact users; second, by placing computers under constant demand, they were more likely to fail. The obvious solution to this problem is to have more than one computer that can handle the request, and this is where the story of distributed databases truly begins.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Living in a single-node world, the most natural solution was to continue letting a single node serve reads and writes and simply sync its state onto a secondary, passive machine—and thus, Active-Passive replication was born.\\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"K7sk3YRaL8wYEtKiITX96\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Active-Passive was an early step towards high availability with an up-to-date backup. In cases where the active node failed, you could simply start directing traffic to the passive node, thereby promoting it to being active. Whenever you could, you would replace the downed server with a new passive machine (and hope the active one did not fail in the interim).\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"2t8Aa7Rb2oIa25t0Zc3c9A\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"At first, replication from the active to the passive node was a synchronous procedure, i.e., transformations were not committed until the Passive node acknowledged them. However, it was unclear what to do if the passive node went down. It certainly didn’t make sense for the entire system to go down if the backup system wasn’t available—but with synchronous replication, that’s what would happen.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"VTKZ10htttxE8c6wYDh68\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"To further improve availability, data could instead be replicated asynchronously. While its architecture looks the same, it was capable of handling either the active or the passive node going down without impacting the database’s availability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"While asynchronous Active-Passive was another step forward, there were still significant downsides:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"When the active node died, any data that wasn’t yet replicated to the passive node could be lost—despite the fact that the client was led to believe the data was fully committed.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"By relying on a single machine to handle traffic, you were still bound to the maximum available resources of a single machine.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Chasing Five 9s High Availability: Scale to many machines\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"As the Internet proliferated, business' needs grew in scale and complexity. For databases this meant that they needed the ability to handle more traffic than any single node could handle, and that providing “always on” high availability became a mandate.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Given that swaths of engineers now had experience working on other distributed technologies, it was clear that databases could move beyond single-node Active-Passive setups and distribute a database across many machines.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Sharding\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Again, the easiest place to start is adapting what you currently have, so engineers adapted Active-Passive replication into something more scalable by developing sharding.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In this scheme, you split up a cluster’s data by some value (such as a number of rows or unique values in a primary key) and distributed those segments among a number of sites, each of which has an Active-Passive pair. You then add some kind of routing technology in front of the cluster to direct clients to the correct site for their requests.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"XK6aVe3XVzf93wyAZunYo\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Sharding lets you distribute your workload among many machines, improving throughput, as well as creating even greater resilience by tolerating a greater number of partial failures and eliminating single points of failure.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Despite these upsides, sharding a system was complex and posed a substantial operational burden on teams. The deliberate accounting of shards could grow so onerous that the routing ended up creeping into an application’s business logic. And worse, if you needed to modify the way a system was sharded (such as a schema change), it often posed a significant (or even monumental) amount of engineering to achieve.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Single-node Active-Passive systems had also provided transactional support (even if not strong consistency). However, the difficulty of coordinating transactions across shards was so knotted and complex, many sharded systems decided to forgo them completely.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.youtube.com/watch?v=wuOm12O4iOI\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"How to scale a database without sharding\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What is Active-Active Availability?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Active-active availability means a database has at least two active nodes that shard data and perform writes to the database. Active-active availability represents an evolution from active-passive, enabling databases to scale beyond single machines by letting nodes in a cluster serve reads and writes.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Given that sharded databases were difficult to manage and not fully featured, engineers began developing systems that would at least solve one of the problems. What emerged were systems that still didn’t support transactions, but were dramatically easier to manage. With the increased demand on applications' uptime, it was a sensible decision to help teams meet their SLAs.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The motivating idea behind these systems was that each site could contain some (or all) of a cluster’s data and serve reads and writes for it. Whenever a node received a write it would propagate the change to all other nodes that would need a copy of it. To handle situations where two nodes received writes for the same key, other nodes' transformations were fed into a conflict resolution algorithm before committing. Given that each site was “active”, it was dubbed Active-Active.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"56TAQs94PfEpjs0j97yShB\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Because each server could handle reads and writes for all of its data, sharding was easier to accomplish algorithmically and made deployments easier to manage.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In terms of availability, Active-Active was excellent. If a node failed, clients just needed to be redirected to another node that did contain the data. As long as a single replica of the data was live, you could serve both reads and writes for it.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"6XafJGMBKxlByUNAaDDLDp\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"While this scheme is fantastic for high availability, its design is fundamentally at odds with consistency and data correctness. Because each site can handle writes for a key (and would in a failover scenario), it’s incredibly difficult to keep data totally synchronized as it is being processed. Instead, the approach is generally to mediate conflicts between sites through the conflict resolution algorithm that makes coarse-grained decisions about how to “smooth out” inconsistencies.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Because that resolution is done post hoc, after a client has already received an answer about a procedure—and has theoretically executed other business logic based on the response—it’s easy for active-active replication to generate anomalies in your data.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Given the premium on uptime, though, the cost of downtime was deemed greater than the cost of potential anomalies, so Active-Active became the dominant replication type.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Correctness at Scale: Consensus and Multi-Active Availability\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Active-Active seemed like it addressed the major problem facing infrastructure — providing high availability. But it had only done so by forgoing transactions, which left systems that also required strong consistency without a compelling choice.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"For example, Google used a massive and complex sharded MySQL system for its advertising business, which heavily relied on SQL’s expressiveness to arbitrarily query the database. Because these queries often relied on secondary indexes to improve performance, they had to be kept totally consistent with the data they were derived from.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Eventually, the system grew large enough in size that it began causing problems for sharded MySQL (Spencer Kimball discusses his first-hand experience with sharded MySQL and AdWords on \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://youtu.be/NMlabY4-eE0?feature=shared\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"this podcast\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"), so their engineers began imagining how they could solve the problem of having both a massively scalable system that could also offer the strong consistency their business required. Active-Active’s lack of transactional support meant it wasn’t an option, so they had to design something new. What they ended up with was a system based around consensus replication, which would guarantee consistency, but would also provide high availability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Using consensus replication, writes are proposed to a node, and are then replicated to some number of other nodes. Once a majority of the nodes have acknowledged the write, it can be committed.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"59VglwC0F69o4R0nzofm9Z\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Consensus and High Availability\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The lynch-pin notion here is that consensus replication lies in a sweet spot between synchronous and asynchronous replication: you need some arbitrary number of nodes to behave synchronously, but it doesn’t matter which nodes those are. This means the cluster can tolerate a minority of nodes going down without impacting the system’s availability. (Caveats made for handling the downed machines' traffic, etc.)\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"3YEcB4CnQu5bSGIcWS4qHY\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The cost of consensus, though, is that it requires nodes to communicate with others to perform writes. While there are steps you can take to reduce the latency incurred between nodes, such as placing them in the same \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://aws.amazon.com/about-aws/global-infrastructure/regions_az/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"availability zone\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", this runs into trade-offs with high availability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"For example, if all of the nodes are in the same datacenter, it’s fast for them to communicate with one another, but you cannot survive an entire datacenter going offline. Spreading your nodes out to multiple datacenters may increase the latency required for writes, but can improve your availability by letting an entire datacenter going offline without bringing down your application.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What is Multi-Active Availability?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Multi-active availability requires that a database has at least three active nodes, each of which can perform reads and writes for any data in the cluster without generating conflicts.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"blockquote\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"CockroachDB implements much of the learnings from the \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://static.googleusercontent.com/media/research.google.com/en//archive/spanner-osdi2012.pdf\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Google Spanner paper\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" (though, notably, without requiring atomic clocks), including those features beyond consensus replication that make availability much simpler. To describe how this works and differentiate it from Active-Active, we’ve coined the term Multi-Active Availability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Active-Active vs. Multi-Active\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Active-Active achieves availability by letting any node in your cluster serve reads and writes for its keys, but propagates any changes it accepts to other nodes only \",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"after\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" committing writes.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Multi-Active Availability, on the other hand, \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/architecture/replication-layer\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"lets any node serve reads and writes, but ensures that a majority of replicas are kept in sync on writes\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", and only \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/architecture/replication-layer#leases\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"serves reads from replicas of the latest version.\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In terms of high availability, Active-Active only requires a single replica to be available to serve both reads of writes, while Multi-Active requires a majority of replicas to be online to achieve consensus (which still allows for partial failures within the system).\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Downstream of these databases' availability, though, is a difference of consistency. Active-Active databases work hard to accept writes in most situations, but then don’t make guarantees about the ability for a client to then read that data now or in the future. On the other hand, Multi-Active databases accept writes only when it can guarantee that the data can later be read in a way that’s consistent.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Where to go from here?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Over the last 30 years, database replication and availability have taken major strides and now supports globe-spanning deployments that feel like they never go down. The field’s first forays laid important groundwork through Active-Passive replication but eventually, we needed better availability and greater scale.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"From there, the industry has developed two predominant paradigms of databases: Active-Active for applications whose primary concern is accepting writes quickly, and Multi-Active for those that require consistency.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"May we all look forward to the day when we can harness quantum entanglement and move to the next paradigm in managing distributed state.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"If defining the next phase of database replication and availability is your coffee-break daydream, then check out our open positions \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://cockroa.ch/eng_hiring\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"here\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\".\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Further reading\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/how-to-reduce-database-costs/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Building fault-tolerant applications while improving operational efficiency\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/5-reasons-to-build-multi-region-application-architecture/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"5 reasons to build using a multi-region architecture\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/demo-fault-tolerance-and-recovery\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Fault tolerance and recovery demo\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/demand-zero-rpo/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"How to get to near-zero RPO/RTO\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Illustration by \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"http://www.christina-chung.com/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Christina Chung\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"TemplateBlogBlogDetailLinks\",\"assets\":{\"__typename\":\"TemplateBlogBlogDetailAssets\",\"block\":[{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"IjA2FGDgYRrhqMEUWr2xk\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"DataReplication ChristinaChung-1\",\"url\":\"https://images.ctfassets.net/00voh0j35590/IjA2FGDgYRrhqMEUWr2xk/4fd0665b0db8270245d82c9ff55efcdf/DataReplication_ChristinaChung-1.avif\",\"width\":1185,\"height\":413},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"K7sk3YRaL8wYEtKiITX96\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"active-passive\",\"url\":\"https://images.ctfassets.net/00voh0j35590/K7sk3YRaL8wYEtKiITX96/2d1a88cd29b8e87cbba27500793ae863/active-passive.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"2t8Aa7Rb2oIa25t0Zc3c9A\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"active-passive-failover\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2t8Aa7Rb2oIa25t0Zc3c9A/0ae7f4c00832945f1e1a9632b5dc737c/active-passive-failover.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"VTKZ10htttxE8c6wYDh68\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"active-passive-passive-down\",\"url\":\"https://images.ctfassets.net/00voh0j35590/VTKZ10htttxE8c6wYDh68/fed3f72545b1cc5a9a6031affb6e5f30/active-passive-passive-down.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"XK6aVe3XVzf93wyAZunYo\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"sharded\",\"url\":\"https://images.ctfassets.net/00voh0j35590/XK6aVe3XVzf93wyAZunYo/cf556af9bd4ee16196e04f60096275b9/sharded.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"56TAQs94PfEpjs0j97yShB\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"active-active\",\"url\":\"https://images.ctfassets.net/00voh0j35590/56TAQs94PfEpjs0j97yShB/0a0f3dec393c3affb61fb313cba64c08/active-active.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"6XafJGMBKxlByUNAaDDLDp\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"active-active-failover\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6XafJGMBKxlByUNAaDDLDp/9074295eb967cbf079a6ed8d1604957e/active-active-failover.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"59VglwC0F69o4R0nzofm9Z\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"multi-active\",\"url\":\"https://images.ctfassets.net/00voh0j35590/59VglwC0F69o4R0nzofm9Z/6ca3c56b6b60e5d721a90c44572e2919/multi-active.png\",\"width\":1920,\"height\":1080},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3YEcB4CnQu5bSGIcWS4qHY\",\"spaceId\":\"00voh0j35590\"},\"description\":\"\",\"title\":\"multi-active-failover\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3YEcB4CnQu5bSGIcWS4qHY/255ac365e3ec8232effdf55162315dc3/multi-active-failover.png\",\"width\":1920,\"height\":1080}]},\"entries\":{\"__typename\":\"TemplateBlogBlogDetailEntries\",\"block\":[]}}},\"aiSummary\":null,\"featuredBlog\":{\"__typename\":\"TemplateBlog\",\"tags\":[\"disaster recovery\",\"inherent resilience\",\"surviving outages\"],\"title\":\"A Conversation with Peter Mattis: Inherent Resilience for Tomorrow’s Outage\",\"buttonText\":\"Read now\",\"slug\":\"surviving-outages-inherent-resilience-webinar\",\"thumbnailImage\":{\"__typename\":\"Asset\",\"description\":\"A blue right floating against a dark blue background. The ring looks like a thin life preserver.\",\"title\":\"surviving-outages-inherent-resilience-thumbnail\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2jQ5ogaem4MrysM5lvrI8N/e3a37fc59da7194decd1e1dd0b68cb81/surviving-outages-inherent-resilience-thumbnail.png\",\"width\":1920,\"height\":1080}},\"additionalFeatureCollection\":{\"__typename\":\"TemplateBlogAdditionalFeatureCollection\",\"items\":[{\"__typename\":\"CardPress\",\"featuredImage\":{\"__typename\":\"Asset\",\"description\":\"A blog ad image with the cover of \\\"The State of Resilience 2025: Confronting Outages, Downtime, and Organizational Readiness.\\\"\",\"title\":\"Cost of Resilience Cockroach Labs 2025\",\"url\":\"https://images.ctfassets.net/00voh0j35590/7yFgiVXXn2EUdL624GhLXr/bfb388a448621a2c4f61bdbe482293db/Cost_of_Resilience_Cockroach_Labs_2025.png\",\"width\":1200,\"height\":627},\"category\":\"[REPORT]\",\"title\":\"What’s the true cost of downtime? \",\"buttonText\":\"Get your copy\",\"buttonLink\":\"https://www.cockroachlabs.com/guides/the-state-of-resilience-2025/\",\"description\":\"1,000 senior technology leaders expose the resilience strategies, priorities, and vulnerabilities facing enterprises today.\",\"buttonColor\":null},{\"__typename\":\"CardPress\",\"featuredImage\":{\"__typename\":\"Asset\",\"description\":\"The cover page of \\\"The Architect's Guide to SQL Database Modernization: Your Step-by-Step Roadmap\\\" displayed on an iPad.\",\"title\":\"architects-guide-sql-database-modernization-on-ipad\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2UDac9o0O7v3KR2ylpOBxR/512fa8941da9aba0fd92c1a2e2cb52e0/architects-guide-sql-database-modernization-on-ipad.png\",\"width\":1920,\"height\":1080},\"category\":\"[GUIDE]\",\"title\":\"Database modernization demystified\",\"buttonText\":\"Get your guide\",\"buttonLink\":\"https://www.cockroachlabs.com/guides/architects-guide-database-modernization/\",\"description\":\"Discover where you stand, plan your path forward, and take the proven steps to build a future-ready data infrastructure.\",\"buttonColor\":\"primaryDark\"}]},\"tableStyling\":null,\"callOutEyebrow\":null,\"callOutTitle\":null,\"callOutDescription\":null,\"callOutButton\":null,\"isListing\":null,\"faqCollection\":{\"__typename\":\"TemplateBlogFaqCollection\",\"items\":[]}},\"similarResources\":[{\"__typename\":\"TemplateBlog\",\"seo\":{\"__typename\":\"MetaSeo\",\"pageTitle\":\"SQL User Lifecycle Management Automation | CockroachDB\",\"pageDescription\":\"Learn how SQL user lifecycle management automates provisioning, role sync, auditing, and deprovisioning to improve access governance at scale.\",\"openGraphImage\":{\"__typename\":\"Asset\",\"description\":\"Digital identity formed from connected data points, representing automated SQL user provisioning, access synchronization, auditing, and deprovisioning.\",\"title\":\"CockroachDB Automate SQL User Lifecycle Management BLOG\",\"url\":\"https://images.ctfassets.net/00voh0j35590/54JK93QnOOzLaAxPLugelQ/37df4b0d5eeb453770c7e9b3ef653cad/CockroachDB_Automate_SQL_User_Lifecycle_Management_BLOG.png\",\"width\":1920,\"height\":1080},\"noIndex\":false,\"noFollow\":null,\"canonicalUrl\":null,\"seoSchemaJson\":null},\"internalName\":\"How Does CockroachDB Automate SQL User Lifecycle Management?\",\"sys\":{\"__typename\":\"Sys\",\"spaceId\":\"00voh0j35590\",\"publishedAt\":\"2026-08-31T14:09:24.661Z\",\"firstPublishedAt\":\"2026-08-28T15:32:48.254Z\",\"environmentId\":\"ab43b007-3cfb-450c-b575-1282ff083a83\",\"publishedVersion\":227},\"title\":\"How Does CockroachDB Automate SQL User Lifecycle Management?\",\"slug\":\"sql-user-lifecycle-management-automation\",\"publishDate\":\"2026-08-28T00:00:00.000Z\",\"lastUpdatedDate\":null,\"tags\":[\"Architectural Simplification\"],\"thumbnailImage\":{\"__typename\":\"Asset\",\"description\":\"Digital identity formed from connected data points, representing automated SQL user provisioning, access synchronization, auditing, and deprovisioning.\",\"title\":\"CockroachDB Automate SQL User Lifecycle Management BLOG\",\"url\":\"https://images.ctfassets.net/00voh0j35590/54JK93QnOOzLaAxPLugelQ/37df4b0d5eeb453770c7e9b3ef653cad/CockroachDB_Automate_SQL_User_Lifecycle_Management_BLOG.png\",\"width\":1920,\"height\":1080},\"excerpt\":\"Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory. \",\"buttonText\":\"Read now\",\"authorsCollection\":{\"__typename\":\"TemplateBlogAuthorsCollection\",\"items\":[{\"__typename\":\"EntityPerson\",\"fullName\":\"Pritesh Lahoti\",\"link\":\"/author/pritesh-lahoti-2\",\"bio\":\"Pritesh Lahoti is an Engineering Manager at Cockroach Labs, leading the Product Security and Infrastructure teams in India. His teams build the security and identity systems that underpin CockroachDB's enterprise authentication, access governance, and compliance capabilities.\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Pritesh L. headshot\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2Qhm45wsxC5NcPOAhx22Nl/44212274bfe04e4cfcb84887c26969b4/3b316d55-c69e-4457-8a6e-7149b938757e.png\",\"width\":550,\"height\":550},\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null},{\"__typename\":\"EntityPerson\",\"fullName\":\"Biplav Saraf\",\"link\":\"/author/biplav-saraf-1\",\"bio\":\"Biplav Saraf is a Product Manager for Security \u0026 Identity at Cockroach Labs. He drives the product strategy for enterprise identity management in CockroachDB, including user provisioning, access governance, and compliance workflows across LDAP, JWT, and OIDC integrations.\\n\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"\",\"title\":\"Biplav Saraf\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3sdncEyJDkFMDEERg5i2rx/a492a7d488dd8d76df204c8e06017fad/1566080983061.jpg\",\"width\":420,\"height\":420},\"role\":\"Product Manager\",\"linkedInUrl\":\"https://www.linkedin.com/in/biplavs/\",\"githubUrl\":null,\"company\":{\"__typename\":\"EntityCompany\",\"name\":\"Cockroach Labs\"}},{\"__typename\":\"EntityPerson\",\"fullName\":\"Sourav Sarangi\",\"link\":\"sourav-sarangi\",\"bio\":\"Sourav Sarangi is a Product Security Engineer at Cockroach Labs, where he works on authentication, authorization, and identity management for CockroachDB. He built the LDAP authentication and authorization integration, auto-provisioning framework, auditing filters, and deprovisioning infrastructure.\\n\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"Sourav Sarangi, Product Security Engineer, Cockroach Labs.\",\"title\":\"Sourav Sarangi Cockroach Labs\",\"url\":\"https://images.ctfassets.net/00voh0j35590/25kHMlPxvAhhfyKyK5U8aY/b94958084c12968831105ca1c84c07df/Sourav_Sarangi_Cockroach_Labs.png\",\"width\":784,\"height\":690},\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null}]},\"darkFooter\":false,\"blogDetail\":{\"__typename\":\"TemplateBlogBlogDetail\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"embedded-asset-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"3OUNXV2BD6TTXa7HfPFmGc\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://thehackernews.com/expert-insights/2025/05/securing-tier-0-history-of-escalating.html\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Fortune 1000 enterprises widely rely\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/cockroachdb-25-3-pci-and-hipaa-azure-kubernetes/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Microsoft Active Directory\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\", and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.ory.com/case-studies/openai\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Ory\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\". If you're running \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/product/overview/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" at enterprise scale, with hundreds of clusters and thousands of users, you're almost certainly authenticating against an external identity provider. Until recently, that meant someone had to manually \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/create-user\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"CREATE USER\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"code\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" in SQL before each person could log in. At scale, this was a dealbreaker.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"At enterprise scale, this becomes a database identity lifecycle management problem: The identity provider may know who a user is, but the database still needs a governed way to create, authorize, audit, and eventually remove that user’s SQL account. Automated user provisioning reduces the manual work and access delays that arise when those lifecycle steps must be repeated across hundreds of clusters. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"We've spent the last several releases building end-to-end SQL user lifecycle management into CockroachDB: automatic provisioning on first login, auditing filters to identify dormant accounts, and bulk deprovisioning with dependency safety. This post walks through how it works, why the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/glossary/distributed-db/postgresql-wire-protocol/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"postgres wire protocol\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" made it possible, and what it means for operators managing database access at scale.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does CockroachDB authenticate SQL users? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB supports a broad set of authentication methods, configured through \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/security-reference/authentication\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Host-Based Authentication\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" (HBA) rules; the same \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"pg_hba.conf\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" mechanism familiar to PostgreSQL users. Each incoming connection is matched against HBA entries in order, and the first match determines which authentication method is used.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Here are the most commonly used methods:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"table\",\"data\":{},\"content\":[{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Method\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Description\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Connection Type\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"password\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Cleartext password (over TLS)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"scram-sha-256\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SCRAM-SHA-256 challenge-response (recommended)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"cert\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"TLS client certificate\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl only\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"cert-password\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Certificate OR cleartext password\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl \",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"cert-scram-sha-256\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Certificate OR SCRAM-SHA-256\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl \",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"ldap\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP/Active Directory bind\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"jwt_token\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT bearer token (via SQL connection)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl, hostnossl\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"oidc\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"OpenID Connect (DB Console only)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"HTTPS\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"gss\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Kerberos/GSSAPI\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"hostssl\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"trust\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"No authentication\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Any\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"reject\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Always reject\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Any\",\"marks\":[],\"data\":{}}]}]}]}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Built-in vs. External Authentication\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The built-in methods – \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"password\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/security-reference/scram-authentication\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"scram-sha-256\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\", and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"cert\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – validate credentials that CockroachDB itself manages. The user's password hash is stored internally, or the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/authentication\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"client certificate\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" is verified against the cluster's CA. These methods are self-contained: CockroachDB is both the identity provider and the authentication authority.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"External methods – \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"ldap\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"jwt_token\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"oidc\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"gss\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – delegate credential validation to an external identity provider. CockroachDB doesn't store or verify the password; it passes it through to Active Directory, validates a JWT signature against an issuer's public keys, or redirects to an OIDC provider's login page. The identity provider is the authentication authority; CockroachDB is a relying party.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This distinction matters because external auth creates a fundamental gap: \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"the identity provider knows the user exists, but CockroachDB doesn't – until someone runs `CREATE USER`\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\". At one cluster, this is a minor inconvenience. At hundreds of clusters with thousands of users rotating through Active Directory groups, it becomes an operational crisis.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"ppAZ2zKplYBNVfImxNV0e\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The HBA config above routes \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"root\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" to certificate-or-password auth, \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"admin_user\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" to SCRAM, and everyone else to LDAP. This is the entry point for everything that follows.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does external authentication work with existing PostgreSQL drivers? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"External authentication works with \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/third-party-database-tools\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"existing PostgreSQL drivers\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" because CockroachDB reuses the standard PostgreSQL password field as a credential channel. Whether the credential is an Active Directory password or a base64-encoded JWT, applications can continue using the same \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/postgresql-compatibility\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"psql, pgx, libpq,\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" or JDBC\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" driver.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This avoids custom authentication plugins, proprietary SDKs, and driver forks. CockroachDB’s HBA configuration determines how to validate the credential:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"26ucXAcpl5EuTTsZz9zg3a\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"No protocol extensions, no custom message types, no special client configuration. This means you can roll out LDAP or \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/sso-sql\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT authentication\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" across your fleet without touching a single application's database driver. That’s a significant operational advantage when you're managing hundreds of services.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"For OIDC, the flow is slightly different: Users authenticate through the DB Console (admin UI) via the standard browser-based Authorization Code grant. Once authenticated, they can retrieve a JWT identity token and use it for subsequent SQL connections. This creates a natural bridge: OIDC for interactive UI access, JWT for programmatic SQL access, both backed by the same identity provider.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-6\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Related \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/compare/cockroachdb-vs-postgresql/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB vs PostgreSQL \",\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" See how PostgreSQL wire-protocol compatibility enables lift-and-shift migrations and drop-in driver support.\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How are external identities mapped to SQL users? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Each auth method resolves an external identity to a CockroachDB SQL username through a different path. Understanding these paths is key to understanding how provisioning works.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP Identity Resolution\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP authentication is a two-phase process. First, CockroachDB binds as a service account and searches the directory for the user's Distinguished Name (DN):\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"7rjplLlWRxaiX5bmrfRSiS\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Then CockroachDB binds as the discovered user DN with the password from the connection's password field. If the bind succeeds, the user is authenticated. The SQL username is the original connection username (\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"jsmith\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"), not the DN.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"After authentication, if LDAP authorization is enabled, CockroachDB makes a second search to fetch the user's group memberships:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"2KMW3b7doVM4TsgLemuPh3\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"These groups are then synchronized as CockroachDB role grants.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.youtube.com/watch?v=bH6Mue7IalU\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Automatic User Provisioning with LDAP | Security in CockroachDB\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT Identity Resolution\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT tokens carry the identity inline. CockroachDB extracts the principal from a configurable claim (default: \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"sub\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"), validates the token's signature against the issuer's JWKS, and checks the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"aud\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"iss\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" claims:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"3DBSR6CuYKvozgosr7HK3v\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The SQL username comes from the configured claim. Group memberships can be extracted from a configurable group claim for role synchronization.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"51bWf9q6seDFvbmR6Xyjwe\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"OIDC Identity Resolution\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"OIDC authentication follows the standard Authorization Code flow, but only for the DB Console (admin UI). The user clicks \\\"Login with SSO,\\\" is redirected to the OIDC provider (e.g., Okta, Azure AD), authenticates there, and is redirected back with an authorization code. CockroachDB exchanges the code for an ID token and extracts the identity from a configurable claim:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"7HPZ2nSiGHfxH4bJZomho4\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"principal_regex\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" setting is worth noting: It lets operators transform the OIDC identity (e.g.,\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" jsmith@corp.com\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\") into the SQL username (\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"jsmith\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\").\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.youtube.com/watch?v=oil0qvJ8S9A\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"How to set up SSO \u0026 JWT | Security in CockroachDB\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does CockroachDB auto-provision SQL users? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"With identity resolution established, the provisioning flow is straightforward. After successful authentication, CockroachDB checks whether the SQL user exists. If not, and provisioning is enabled, it creates the user automatically and stamps them with an immutable \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"PROVISIONSRC\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" role option.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This is a form of just-in-time user provisioning: A verified external identity becomes a database principal only when that person first needs access. Operators don’t need to pre-create accounts, maintain custom provisioning scripts, or reconcile a separate database-user inventory with the identity provider. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"5Vq7OsHp1KNfoSBKLugw6S\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-asset-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"JPbMku3BZuWhH81fHT3gb\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP Provisioning Flow\",\"marks\":[{\"type\":\"italic\"},{\"type\":\"subscript\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The internal flow looks like this:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"oWJQFuCTU2Eq0yH9LBSJl\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What is the PROVISIONSRC tag?\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"PROVISIONSRC\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" role option is an immutable tag that records the authentication method and identity provider that auto-provisioned a SQL user. It gives each externally managed user durable provenance for auditing and source-scoped deprovisioning:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"1. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Which auth method\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" provisioned the user (\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"ldap\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"jwt_token\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", or \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"oidc\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\")\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"2. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Which identity provider\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" the user came from (the IDP URI)\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"7yAP8nfl31njX8PVDVO76g\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This tag serves three purposes:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Auditing\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Operators can identify which users were auto-created vs. manually created, and from which source.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Deprovisioning\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": The \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" statement uses this tag to scope bulk cleanup.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Compliance\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Auditors can distinguish externally provisioned accounts from manually created ones, and confirm which identity provider each provisioned account came from.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The immutability is deliberate. Once a user is stamped as LDAP-provisioned, that provenance can't be altered. This creates a tamper-resistant audit trail, which is important for organizations subject to SOX, SOC 2, or GDPR data access controls.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does the authentication pipeline work? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Under the hood, each authentication attempt flows through a composable pipeline of stages:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"2sF4w5cSWrSPIJm5Z436DP\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Each auth method composes these stages differently. LDAP uses all four stages (plus connection cleanup). JWT uses credential validation, provisioning, and authorization (no persistent connection). Certificate auth only uses credential validation (no provisioning or authorization needed). This composable design made it straightforward to add provisioning to each method without duplicating auth logic.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB also emits telemetry counters for each provisioning event, enabling operators to monitor provisioning activity and success rates through their existing metrics dashboards.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does session-based role synchronization work? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Provisioning creates the user. But what about their permissions? In traditional database administration, an admin manually runs \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/grant\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"GRANT and REVOKE\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" statements\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" to manage role memberships. When an employee changes teams or leaves the organization, someone has to remember to update their database roles. At scale, this falls apart.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB solves this with \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"session-based dynamic privilege sync\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": every time a user authenticates, their \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/security-reference/authorization\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"role memberships\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" are re-synchronized from the identity provider. No manual \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"GRANT\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" or \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"REVOKE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" needed: The IdP is the single source of truth for who has what access.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"In practice, this turns group-based database access into an identity-governance workflow. When a person changes teams or loses access in the IdP, CockroachDB can reconcile their database role memberships at their next authentication instead of relying on a separate manual cleanup process. That helps limit privilege drift across large database estates. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-asset-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"6QmrrPisNvDiitL2eaKySz\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Dynamic Privilege Sync: Session-Based Role Assignment\",\"marks\":[{\"type\":\"italic\"},{\"type\":\"subscript\"}],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How are database roles synchronized at login? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"On \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"every successful login,\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" not just the first, CockroachDB performs a full role membership sync for any auth method with authorization enabled. It compares the user's current database roles against their current IdP group memberships, then issues the necessary \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"GRANT\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"REVOKE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" statements to make them match exactly. This is a \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"full replacement\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", not an incremental update; any roles previously granted in CockroachDB that don't correspond to a current IdP group are revoked, and any new IdP groups are granted. This means older role assignments are overwritten on each login, ensuring the IdP remains the single source of truth.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"3aiI5eAP52GqH030I8BbQx\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This means if an admin removes a user from the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"db_writers \",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"group in Active Directory on Monday, the user's \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"db_writers\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" role is automatically revoked the next time they authenticate to CockroachDB. No manual intervention required.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does authorization work for each authentication method? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Each auth method fetches groups differently, but they all feed into the same sync mechanism:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP Authorization\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP group sync is triggered when the HBA entry includes the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"ldapgrouplistfilter\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" option. CockroachDB queries the LDAP directory for all groups the user belongs to, extracts the CN (Common Name) from each group's DN, and maps those to CockroachDB roles:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"26IBRc0VK7RInSTnVV8gmQ\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\nCockroachDB searches the directory for groups that list the authenticated user as a member. The CN of each matching group becomes the CockroachDB role name. For a user with DN \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"cn=jsmith,ou=Engineering,dc=example,dc=com\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", a matching group such as \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"cn=db_readers,ou=Groups,dc=example,dc=com\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" maps to the CockroachDB role \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"db_readers\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\".\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT Authorization\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"JWT groups are extracted directly from the token's claims, no external call needed. CockroachDB looks for a configurable group claim (default: \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"groups\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"):\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"5yoLGa9AoVEUsxuv7ubrUE\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"If the group claim isn't in the JWT itself, CockroachDB can optionally call the issuer's /\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"userinfo\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" endpoint to fetch group memberships.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"1B9mFbGMWiCiT2Z6SKL5v2\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"OIDC Authorization\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"OIDC groups can come from the ID token, the access token, or the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"/userinfo\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" endpoint, depending on how the provider is configured:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"65eMullG6gULXY1hp2cy3S\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"What role data is synchronized, and what is not? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB dynamically synchronizes role memberships from IdP groups, while leaving object-level privileges and reserved system roles such as \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"admin\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"root\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" unchanged. The table below defines that boundary:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"table\",\"data\":{},\"content\":[{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Synced dynamically\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Not synced\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Role memberships from IdP groups\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Object-level privileges (\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"GRANT SELECT ON table\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\")\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"New groups added in IdP\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Reserved system roles, including \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"admin\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"root\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Groups removed in IdP\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Group changes between logins\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"An important design decision: \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"the IdP is the authoritative source for role memberships\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\". On every login, the sync performs a full replacement, so the user's CockroachDB roles are set to match their IdP groups. If an admin manually runs \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"GRANT some_role TO jsmith\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", that grant will be \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"overridden on the next login\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" when the role set is re-synced from the IdP.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Role sync maps IdP groups onto roles that already exist in the database: it grants memberships rather than creating roles. Make sure the roles corresponding to your IdP groups exist in CockroachDB before you enable group sync.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This is deliberate. For externally-managed users, the identity provider should be the single source of truth for access control. Allowing manual overrides would create drift between the IdP and the database, defeating the purpose of centralized identity management. If a user needs a role that isn't mapped from an IdP group, the correct approach is to add them to the appropriate group in Active Directory or the OIDC/JWT provider.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Why use session-based rather than continuous role synchronization? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"We chose session-based sync rather than continuous polling for several reasons:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"1. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"No additional infrastructure\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": No background workers polling LDAP or SCIM endpoints. Sync happens naturally as users authenticate.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"2. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Minimal latency impact\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Group fetching is already part of the auth handshake, and CockroachDB exposes latency metrics to track the total time including sync.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"3. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Predictable behavior\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Operators know exactly when sync happens: on login. There's no race condition between a group change and when it takes effect.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"4. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Scales with usage\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Active users get synced frequently. Dormant users don't generate unnecessary load on the IdP.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The tradeoff is that role changes don't take effect until the next login. For most enterprises, this is acceptable: The security boundary is \\\"next authentication,\\\" which for interactive users is typically within hours.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does CockroachDB track login time for compliance reviews? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Successful authentications update the user's \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"estimated_last_login_time\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\". This is a best-effort timestamp: it is not guaranteed to capture every individual login event, but it is reliable enough for dormant-account reviews and deprovisioning workflows.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"66Oa8bmhGjPwZfI61iEaRC\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"A \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"NULL\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" value means the user has never logged in since the column was added (or was created manually without going through the auth flow).\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This timestamp is most useful as an operational signal for dormant-account reviews and deprovisioning decisions, \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"not\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" as a substitute for a complete forensic authentication log. That distinction lets teams automate routine access hygiene while preserving the appropriate evidence sources for formal investigations and audits. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does login-time tracking support compliance reviews?\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Login time tracking and the ability to identify dormant accounts support the access review workflows that enterprises are audited against. A few key examples:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Control 5.3\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" (Disable Dormant Accounts) requires deleting or disabling accounts after a defined inactivity period (typically 45 days). \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"SHOW USERS WITH LAST LOGIN BEFORE '...' \",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"reduces this to a single SQL query.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOC 2 CC6.2\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" requires terminating access when no longer required. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES WITH LAST LOGIN BEFORE '...'\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" supports that workflow and produces a record of what was removed.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PCI DSS v4.0.1 Requirement 8.2.6\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" requires removing inactive accounts within 90 days, again addressable with a single filtered query.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"These features also map to \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://gdpr-info.eu/art-17-gdpr/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOX Section 404, GDPR Article 5(1)(e)\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" (storage limitation), and additional CIS controls. For a detailed framework-by-framework mapping, see the Compliance Framework Mapping that appears at the end of this article.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How can operators audit provisioned SQL users? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"We extended both \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"SHOW USERS\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/show-roles\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"SHOW ROLES\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" (they're interchangeable in CockroachDB) with new filter clauses. These filters are the bridge between provisioning and deprovisioning: They let operators identify exactly which accounts to clean up.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Syntax\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"5xeq6ddBfoReJ76JLrW8Gc\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Example Output\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"52npRLFi85NDtCU3G6dbJA\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How are the user filters implemented? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"These filters are implemented as native SQL grammar extensions, which is the same approach databases use to add new statement variants. At a high level, the implementation follows a standard three-layer pattern common in SQL engines:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"1. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"AST (Abstract Syntax Tree)\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": New node types represent the filter options, capturing the source string and login-before expression as structured data\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"2. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Rewrite layer\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": The parsed AST is transformed into an optimized query plan that joins user metadata with provisioning records, with proper input sanitization\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"3. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Grammar rules\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": The SQL parser is extended to recognize the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"WITH SOURCE = '...', LAST LOGIN BEFORE \u003cexpr\u003e\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"LIMIT \u003cn\u003e\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" clauses as valid syntax\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This layered approach ensures the new filter clauses are treated as first-class SQL syntax with the same safety and optimization guarantees as any other built-in statement.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How does CockroachDB deprovision SQL users? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The final piece of the lifecycle is \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", a new SQL statement for bulk cleanup of auto-provisioned users.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Deprovisioning is where lifecycle management becomes operationally complete. Operators can identify externally managed accounts by source and login recency, review the affected users, and remove dormant accounts in controlled batches, without conflating them with manually created users or bypassing dependency checks. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Why use DROP PROVISIONED ROLES instead of DROP USER? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" enables source- and activity-scoped bulk cleanup of auto-provisioned users, which\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" \",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/drop-user\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"DROP USER\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"code\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" does not provide. It preserves the ability to target externally managed accounts without requiring operators to remove users one at a time. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"We considered several alternatives before settling on a dedicated statement:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"table\",\"data\":{},\"content\":[{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Approach\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Problem\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Proxy users\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" (shared login mapped to individual principals)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Loses per-user auditability. Can't track who did what.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temporary users\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" (auto-expire after session)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Loses job context. Scheduled jobs can't reference dropped users.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Just use DROP USER\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"No bulk operation. No way to scope by source or activity. Manual per-user cleanup.\",\"marks\":[],\"data\":{}}]}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The chosen design of persistent users with explicit bulk deprovisioning preserves audit trails, supports job scheduling, and gives operators precise control over which users to clean up.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Syntax\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"61mAwN814SxAdFemZsjHwF\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What safeguards does DROP PROVISIONED ROLES provide? \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" is designed to be safe by default:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"1. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Dependency checking\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": If a user owns tables, has active grants, or is referenced by scheduled jobs, they're \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"skipped\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" with a client \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"NOTICE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" rather than causing the statement to fail:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"4pwe1WEL5WO4BaVUjX43Ez\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"2. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Reserved user protection\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": reserved system roles, including \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"root\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"admin\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", are \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"never touched\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", regardless of filters.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"3. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Requires CREATEROLE\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Only users with the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"CREATEROLE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" privilege can execute \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\".\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"4. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Comprehensive cleanup\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": For each dropped user, the statement cleans up all associated metadata: the user record, role memberships, role options (including PROVISIONSRC), per-user settings, and active web sessions.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"Audit trail\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\": Every individual drop generates a \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DropRole\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" audit event logged to the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"USER_ADMIN\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" channel, providing a per-user record of what was dropped and which statement triggered it.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How do you deprovision dormant users? To deprovision dormant users, first identify externally provisioned accounts by source and login recency, then review the results before removing eligible users in controlled batches. Accounts that have never recorded a login are not surfaced by a LAST LOGIN BEFORE audit query. Review those separately before running a scoped drop.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The following workflow uses a 90-day inactivity threshold for a quarterly access review:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"3OUct5xPdUA11WwqzlGefP\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"embedded-asset-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"62cIEzgXnpKOtONdW1pkun\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES: Deprovisioning Decision Flow\",\"marks\":[{\"type\":\"italic\"},{\"type\":\"subscript\"}],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What does SQL user lifecycle management change for operators? \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Managing database users manually doesn't scale. What starts as a few \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"CREATE USER\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" commands becomes a sprawling operational burden as teams grow, clusters multiply, and compliance requirements tighten.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB now handles the full user lifecycle natively in SQL:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Provision\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – Users are created automatically on first login via LDAP, JWT, or OIDC. No manual \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"CREATE USER\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", no scripts, no drift between your identity provider and your database.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Authorize\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – Role memberships sync dynamically from the IdP on every login, ensuring privileges always reflect the source of truth.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Audit\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"SHOW USERS WITH\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" filters let operators query by provisioning source, login recency, and role membership, giving compliance teams the data they need without external tooling.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Deprovision\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" – \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" removes dormant accounts in scoped, capped batches, and skips any account that still has dependencies attached to it.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The result is a closed loop: identity providers control who has access, CockroachDB enforces that access in the database, and operators have SQL-native evidence for reviews and audits. Instead of coordinating manual account creation and cleanup across every cluster, teams can apply a consistent identity-driven access model at scale to reduce administrative toil, shorten access-review cycles, and make access governance easier to demonstrate. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Ready to operationalize identity-driven database access across your CockroachDB estate? Learn how CockroachDB helps automate SQL user lifecycle management. \",\"marks\":[{\"type\":\"italic\"}],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/contact/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Talk to an expert\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\".\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Learn More\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/ldap-authentication.html\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP Authentication Documentation\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/ldap-authorization.html\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"LDAP Authorization Documentation\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/sso-db-console.html\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Single Sign-On (SSO) for DB Console\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Appendix: Compliance Framework Mapping\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This section provides a detailed mapping between CockroachDB's user lifecycle management features and specific compliance framework requirements.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"These mappings identify where CockroachDB features can supply evidence for, or support the operational workflow behind, common control objectives. They are not a determination of compliance. Whether a given control is satisfied depends on your organization's policies, the scope of your environment, and your auditor's assessment.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Critical Security Controls (v8)\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The CIS Controls framework has several safeguards that map to user lifecycle management:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Control 5.3 (Disable Dormant Accounts):\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires organizations to delete or disable dormant accounts after a defined period of inactivity (typically 45 days). With estimated_last_login_time, operators can identify and act on dormant accounts using SQL:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"4NQvU8IznuPrrmXLrXBSon\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Control 5.1 (Establish and Maintain an Inventory of Accounts):\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires a formal account inventory as the baseline for periodic reviews. SHOW USERS WITH SOURCE = '...' provides this inventory filtered by provisioning origin, so operators can enumerate exactly which accounts were auto-created from each identity provider.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Control 6.1 (Access Control Management):\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires review of all user access rights at least annually, or when a user's role changes. The combination of PROVISIONSRC tracking and estimated_last_login_time provides the data needed for these reviews.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS Benchmark Section 4.4 (Centralize and Standardize User Management):\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Part of the CockroachDB-specific CIS benchmark. Requires centralized user management and the ability to identify orphaned accounts.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOC 2 Trust Service Criteria\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOC 2 audits under the Logical and Physical Access Controls (CC6) series have three criteria relevant to user lifecycle management:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.1:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires logical access security infrastructure to protect information assets from security events. Auditors look for evidence that stale accounts are identified and addressed, as dormant accounts increase the attack surface.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.2:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires that the entity establishes identity before issuing credentials and modifies or terminates access when no longer required. Organizations typically define an inactivity threshold in policy, after which access is treated as no longer required. DROP PROVISIONED ROLES WITH LAST LOGIN BEFORE '...' supports that workflow and produces a record of which accounts were removed.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.3:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Requires that the entity authorizes, modifies, or terminates access based on entitlement and roles. Auditors look for evidence of periodic reviews of access rights, showing that currently granted access matches actual job responsibilities. SHOW USERS WITH SOURCE = '...', LAST LOGIN BEFORE '...' helps produce that evidence natively in SQL.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOX Section 404\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Requires controls over access to financial systems. Dormant database accounts are a common audit finding. SHOW USERS WITH LAST LOGIN BEFORE '...' helps produce the evidence that access reviews are being performed.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"GDPR Article 5(1)(e): Storage Limitation\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Personal data should be kept in a form that permits identification of data subjects for no longer than is necessary. Dormant accounts that retain access to personal data widen the set of identities able to reach it. Deprovisioning workflows built on login-time tracking support access minimization by helping ensure that only active, authorized users retain database access.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Removing a SQL account is an access-control action. It does not by itself satisfy a data subject's right to erasure under Article 17, which concerns the erasure of personal data and carries its own conditions and exemptions.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PCI DSS v4.0.1 Requirement 8.2.6\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Requires that inactive user accounts be removed or disabled within 90 days of inactivity. This requirement was numbered 8.1.4 under PCI DSS v3.2.1, which was retired on 31 March 2024.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"embedded-entry-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"4Nv48x5GsnGmIRGUcndxhg\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Summary: Feature to Framework Mapping\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"table\",\"data\":{},\"content\":[{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Feature\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CIS\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOC 2\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SOX\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"GDPR\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PCI DSS\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SHOW USERS WITH LAST LOGIN BEFORE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5.3\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.1\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"404\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Art. 5(1)(e)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"8.2.6\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"SHOW USERS WITH SOURCE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5.1, 6.1\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.3\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"404\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Art. 5(1)(e)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"n/a\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"DROP PROVISIONED ROLES\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5.3\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.2\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"404\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Art. 5(1)(e)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"8.2.6\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PROVISIONSRC tag\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5.1\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.1, CC6.3\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"404\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Art. 5(1)(e)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"n/a\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"estimated_last_login_time\",\"marks\":[{\"type\":\"code\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"5.3\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CC6.1, CC6.2\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"404\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Art. 5(1)(e)\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"8.2.6\",\"marks\":[],\"data\":{}}]}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Mappings indicate where a feature can contribute evidence toward a control objective. They are not an assertion of compliance.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"About the Authors\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Pritesh Lahoti\",\"marks\":[{\"type\":\"bold\"},{\"type\":\"italic\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" is an Engineering Manager at Cockroach Labs, leading the Product Security and Infrastructure teams in India. His teams build the security and identity systems that underpin CockroachDB's enterprise authentication, access governance, and compliance capabilities, including the user lifecycle management features described in this post.\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Biplav Saraf \",\"marks\":[{\"type\":\"bold\"},{\"type\":\"italic\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"is a Product Manager for Security \u0026 Identity at Cockroach Labs. He drives the product strategy for enterprise identity management in CockroachDB, including user provisioning, access governance, and compliance workflows across LDAP, JWT, and OIDC integrations.\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Sourav Sarangi \",\"marks\":[{\"type\":\"bold\"},{\"type\":\"italic\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"is a Product Security Engineer at Cockroach Labs, where he works on authentication, authorization, and identity management for CockroachDB. He built the LDAP authentication and authorization integration, auto-provisioning framework, auditing filters, and deprovisioning infrastructure.\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\\n\\n\",\"marks\":[],\"data\":{}}]}]},\"links\":{\"__typename\":\"TemplateBlogBlogDetailLinks\",\"assets\":{\"__typename\":\"TemplateBlogBlogDetailAssets\",\"block\":[{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3OUNXV2BD6TTXa7HfPFmGc\",\"spaceId\":\"00voh0j35590\"},\"description\":\"Digital identity formed from connected data points, representing automated SQL user provisioning, access synchronization, auditing, and deprovisioning.\",\"title\":\"CockroachDB Automate SQL User Lifecycle Management SOCIALWEBP\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3OUNXV2BD6TTXa7HfPFmGc/101c1b14d2155a8c0dfe7b55bf590e9d/CockroachDB_Automate_SQL_User_Lifecycle_Management_SOCIALWEBP.webp\",\"width\":1200,\"height\":675},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"JPbMku3BZuWhH81fHT3gb\",\"spaceId\":\"00voh0j35590\"},\"description\":\"An LDAP Provisioning Flow. \",\"title\":\"CockroachDB Automate SQL User Lifecycle Management Diagram 1\",\"url\":\"https://images.ctfassets.net/00voh0j35590/JPbMku3BZuWhH81fHT3gb/8c638056e70072a33566d6008533aff1/CockroachDB_Automate_SQL_User_Lifecycle_Management_Diagram_1.png\",\"width\":1922,\"height\":1525},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"6QmrrPisNvDiitL2eaKySz\",\"spaceId\":\"00voh0j35590\"},\"description\":\"Dynamic Privilege Sync: Session-Based Role Assignment\",\"title\":\"CockroachDB Automate SQL User Lifecycle Management Diagram 2\",\"url\":\"https://images.ctfassets.net/00voh0j35590/6QmrrPisNvDiitL2eaKySz/243e0490dea43615d509c1d1758177ef/CockroachDB_Automate_SQL_User_Lifecycle_Management_Diagram_2.png\",\"width\":1922,\"height\":518},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"62cIEzgXnpKOtONdW1pkun\",\"spaceId\":\"00voh0j35590\"},\"description\":\"DROP PROVISIONED ROLES: Deprovisioning Decision Flow\",\"title\":\"CockroachDB Automate SQL User Lifecycle Management Diagram 2\",\"url\":\"https://images.ctfassets.net/00voh0j35590/62cIEzgXnpKOtONdW1pkun/fe8d85e08675d97f9c44e3311d93c368/CockroachDB_Automate_SQL_User_Lifecycle_Management_Diagram_2.png\",\"width\":1922,\"height\":518}]},\"entries\":{\"__typename\":\"TemplateBlogBlogDetailEntries\",\"block\":[{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"ppAZ2zKplYBNVfImxNV0e\"},\"internalName\":\"Code Box 1\",\"component\":\"resources\",\"description\":\"different users to different auth methods\\nhost all root all cert-password\\nhost all admin_user all scram-sha-256\\nhost all all all ldap \\\"ldapserver=ldap.example.com\\\" \\\\\\n \\\"ldapport=636\\\" \\\\\\n \\\"ldapbasedn=ou=Users,dc=example,dc=com\\\" \\\\\\n \\\"ldapbinddn=cn=svc,dc=example,dc=com\\\" \\\\\\n \\\"ldapbindpasswd=secret\\\" \\\\\\n \\\"ldapsearchattribute=uid\\\" \\\\\\n \\\"ldapsearchfilter=(objectClass=person)\\\"\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"26ucXAcpl5EuTTsZz9zg3a\"},\"internalName\":\"Code Box 2\",\"component\":\"resources\",\"description\":\"# Connecting with LDAP credentials -- same driver, same connection string format\\ncockroach sql --url \\\"postgresql://jsmith:my-ad-password@crdb-host:26257/defaultdb?sslmode=require\\\"\\n# Connecting with JWT -- just pass the token as the password\\ncockroach sql --url \\\"postgresql://jsmith:eyJhbGciOiJSUzI1NiIs...@crdb-host:26257/defaultdb?sslmode=require\u0026options=-c%20crdb:jwt_auth_enabled=true\\\"\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"7rjplLlWRxaiX5bmrfRSiS\"},\"internalName\":\"Code Box 3\",\"component\":\"resources\",\"description\":\"Service account bind:\\n  DN: cn=svc-crdb,ou=ServiceAccounts,dc=example,dc=com\\n  Password: (from HBA config)\\nSearch:\\n  Base DN: ou=Users,dc=example,dc=com\\n  Filter: (uid=jsmith)\\n  Result: cn=jsmith,ou=Engineering,dc=example,dc=com\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"2KMW3b7doVM4TsgLemuPh3\"},\"internalName\":\"Code Box 4\",\"component\":\"resources\",\"description\":\"Group search:\\n  Base DN: ou=Users,dc=example,dc=com\\n  Filter: (member=cn=jsmith,ou=Engineering,dc=example,dc=com)\\n  Result: cn=db_readers, cn=db_writers\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3DBSR6CuYKvozgosr7HK3v\"},\"internalName\":\"Code Box 5\",\"component\":\"resources\",\"description\":\"{\\n  \\\"sub\\\": \\\"jsmith\\\",\\n  \\\"iss\\\": \\\"https://auth.example.com\\\",\\n  \\\"aud\\\": \\\"cockroachdb\\\",\\n  \\\"groups\\\": [\\\"db_readers\\\", \\\"db_writers\\\"],\\n  \\\"exp\\\": 1735689600\\n}\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"51bWf9q6seDFvbmR6Xyjwe\"},\"internalName\":\"Code Box 6\",\"component\":\"resources\",\"description\":\"-- JWT cluster settings\\nSET CLUSTER SETTING server.jwt_authentication.enabled = true;\\nSET CLUSTER SETTING server.jwt_authentication.issuers = '[\\\"https://auth.example.com\\\"]';\\nSET CLUSTER SETTING server.jwt_authentication.audience = '[\\\"cockroachdb\\\"]';\\nSET CLUSTER SETTING server.jwt_authentication.claim = 'sub';\\nSET CLUSTER SETTING server.jwt_authentication.jwks_auto_fetch.enabled = true;\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"7HPZ2nSiGHfxH4bJZomho4\"},\"internalName\":\"Code Box 7\",\"component\":\"resources\",\"description\":\"-- OIDC cluster settings\\nSET CLUSTER SETTING server.oidc_authentication.enabled = true;\\nSET CLUSTER SETTING server.oidc_authentication.provider_url = 'https://okta.corp.com';\\nSET CLUSTER SETTING server.oidc_authentication.client_id = 'crdb-app-id';\\nSET CLUSTER SETTING server.oidc_authentication.client_secret = '...';\\nSET CLUSTER SETTING server.oidc_authentication.claim_json_key = 'email';\\nSET CLUSTER SETTING server.oidc_authentication.principal_regex = '^([^@]+)@corp\\\\.com$';\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5Vq7OsHp1KNfoSBKLugw6S\"},\"internalName\":\"Code Box 8\",\"component\":\"resources\",\"description\":\"-- Enable provisioning for each auth method independently\\nSET CLUSTER SETTING security.provisioning.ldap.enabled = true;\\nSET CLUSTER SETTING security.provisioning.jwt.enabled = true;\\nSET CLUSTER SETTING security.provisioning.oidc.enabled = true;\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"oWJQFuCTU2Eq0yH9LBSJl\"},\"internalName\":\"Code Box 9\",\"component\":\"resources\",\"description\":\"Authentication succeeds\\n    │\\n    ▼\\nUser already exists?\\n    │\\n    ├── Yes → Skip provisioning, continue to authorization\\n    │\\n    └── No → Is provisioning enabled for this auth method?\\n            │\\n            ├── No → Reject login (user doesn't exist)\\n            │\\n            └── Yes → CREATE USER IF NOT EXISTS jsmith\\n                       WITH PROVISIONSRC = 'ldap:ldap.example.com'\\n                       │\\n                       ▼\\n                    Continue to authorization (role sync)\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"7yAP8nfl31njX8PVDVO76g\"},\"internalName\":\"Code Box 10\",\"component\":\"resources\",\"description\":\"-- After auto-provisioning, users are tagged with their source\\n  username  |   option     |         value\\n+-----------+--------------+--------------------------+\\n  jsmith    | PROVISIONSRC | ldap:ldap.example.com\\n  agarcia   | PROVISIONSRC | jwt_token:auth.example.com\\n  bchen     | PROVISIONSRC | oidc:okta.corp.com\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"2sF4w5cSWrSPIJm5Z436DP\"},\"internalName\":\"Code Box 11\",\"component\":\"resources\",\"description\":\"Authentication Pipeline:\\n    ┌─────────────────┐     ┌─────────────────┐     ┌─────────────────┐     ┌─────────────────┐\\n    │   Credential     │     │    Identity      │     │   User           │     │   Role           │\\n    │   Validation     │ ──\u003e │    Mapping        │ ──\u003e │   Provisioning   │ ──\u003e │   Authorization  │\\n    │                  │     │                   │     │                  │     │                  │\\n    │ Verify password, │     │ Map external ID   │     │ Create user if   │     │ Sync IdP groups  │\\n    │ JWT sig, or      │     │ to SQL username   │     │ needed, stamp    │     │ to CRDB roles    │\\n    │ LDAP bind        │     │                   │     │ with PROVISIONSRC│     │                  │\\n    └─────────────────┘     └─────────────────┘     └─────────────────┘     └─────────────────┘\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3aiI5eAP52GqH030I8BbQx\"},\"internalName\":\"Code Box 12\",\"component\":\"resources\",\"description\":\"On every login:\\n    │\\n    ▼\\nFetch IdP groups                    Fetch CRDB roles\\n(LDAP search / JWT claim /          (SELECT from\\n OIDC token)                         current CRDB roles)\\n    │                                      │\\n    └──────────────┬───────────────────────┘\\n                   ▼\\n              Calculate diff\\n                   │\\n         ┌─────────┴─────────┐\\n         ▼                   ▼\\n    GRANT new roles     REVOKE removed roles\\n    (db_admins)         (db_writers)\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"26IBRc0VK7RInSTnVV8gmQ\"},\"internalName\":\"Code Box 13\",\"component\":\"resources\",\"description\":\"# HBA entry with group sync enabled\\nhost all all all ldap \\\"ldapserver=ldap.example.com\\\" \\\\\\n                      \\\"ldapport=636\\\" \\\\\\n                      \\\"ldapbasedn=ou=Users,dc=example,dc=com\\\" \\\\\\n                      \\\"ldapbinddn=cn=svc,dc=example,dc=com\\\" \\\\\\n                      \\\"ldapbindpasswd=secret\\\" \\\\\\n                      \\\"ldapsearchattribute=uid\\\" \\\\\\n                      \\\"ldapsearchfilter=(objectClass=person)\\\" \\\\\\n                      \\\"ldapgrouplistfilter=(objectClass=groupOfNames)\\\"\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5yoLGa9AoVEUsxuv7ubrUE\"},\"internalName\":\"Code Box 14\",\"component\":\"resources\",\"description\":\"{\\n  \\\"sub\\\": \\\"jsmith\\\",\\n  \\\"iss\\\": \\\"https://auth.example.com\\\",\\n  \\\"groups\\\": [\\\"db_readers\\\", \\\"db_writers\\\", \\\"analytics_team\\\"]\\n}\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"1B9mFbGMWiCiT2Z6SKL5v2\"},\"internalName\":\"Code Box 15\",\"component\":\"resources\",\"description\":\"-- Enable JWT authorization (group-based role sync)\\nSET CLUSTER SETTING server.jwt_authentication.authorization.enabled = true;\\nSET CLUSTER SETTING server.jwt_authentication.group_claim = 'groups';\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"65eMullG6gULXY1hp2cy3S\"},\"internalName\":\"Code Box 16\",\"component\":\"resources\",\"description\":\"-- Enable OIDC authorization\\nSET CLUSTER SETTING server.oidc_authentication.authorization.enabled = true;\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"66Oa8bmhGjPwZfI61iEaRC\"},\"internalName\":\"Code Box 17\",\"component\":\"resources\",\"description\":\"-- Query login times for non-system users\\n  username   | estimated_last_login_time\\n+------------+----------------------------+\\n  jsmith     | 2026-04-15 14:32:00+00\\n  agarcia    | 2026-03-01 09:15:00+00\\n  former_dev | 2025-08-22 06:00:00+00\\n  old_user   | 2025-06-20 11:00:00+00\\n  stale_svc  | NULL\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5xeq6ddBfoReJ76JLrW8Gc\"},\"internalName\":\"Code Box 18\",\"component\":\"resources\",\"description\":\"-- Basic: show all users\\nSHOW USERS;\\n-- Filter by provisioning source\\nSHOW USERS WITH SOURCE = 'ldap:ldap.example.com';\\n-- Filter by last login time\\nSHOW USERS WITH LAST LOGIN BEFORE '2026-01-01';\\n-- Combined filters with limit\\nSHOW USERS WITH SOURCE = 'ldap:ldap.example.com',\\n LAST LOGIN BEFORE '2026-01-01' LIMIT 10;\\n-- SHOW ROLES works identically\\nSHOW ROLES WITH SOURCE = 'jwt_token:auth.example.com';\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"52npRLFi85NDtCU3G6dbJA\"},\"internalName\":\"Code Box 19\",\"component\":\"resources\",\"description\":\"root@localhost\u003e SHOW USERS WITH SOURCE = 'ldap:ldap.example.com',\\n                LAST LOGIN BEFORE '2026-01-01';\\n  username   |            options              |    member_of     | estimated_last_login_time\\n+------------+---------------------------------+------------------+---------------------------+\\n  former_dev | {PROVISIONSRC=ldap:ldap.ex...}  | {db_readers}     | 2025-08-22 06:00:00+00\\n  old_user   | {PROVISIONSRC=ldap:ldap.ex...}  | {}               | 2025-06-20 11:00:00+00\\n(2 rows)\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"61mAwN814SxAdFemZsjHwF\"},\"internalName\":\"Code Box 20\",\"component\":\"resources\",\"description\":\"-- Drop up to 100 auto-provisioned users, from any source\\nDROP PROVISIONED ROLES LIMIT 100;\\n-- Drop only LDAP-provisioned users from a specific server\\nDROP PROVISIONED ROLES WITH SOURCE = 'ldap:ldap.example.com' LIMIT 100;\\n-- Drop dormant LDAP users, capped at 100\\nDROP PROVISIONED ROLES WITH SOURCE = 'ldap:ldap.example.com',\\n  LAST LOGIN BEFORE '2025-01-01' LIMIT 100;\\n-- Drop OIDC-provisioned users from a specific provider\\nDROP PROVISIONED ROLES WITH SOURCE = 'oidc:okta.corp.com' LIMIT 100;\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"4pwe1WEL5WO4BaVUjX43Ez\"},\"internalName\":\"Code Box 21\",\"component\":\"resources\",\"description\":\"NOTICE: skipping \\\"jsmith\\\": role has dependent objects\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"3OUct5xPdUA11WwqzlGefP\"},\"internalName\":\"Code Box 22\",\"component\":\"resources\",\"description\":\"-- Step 1: Audit - Find dormant LDAP users (no login in 90 days)\\nSHOW USERS WITH SOURCE = 'ldap:ldap.example.com',\\n  LAST LOGIN BEFORE (now() - INTERVAL '90 days');\\n-- Step 2: Review the list, verify no active service accounts\\n-- Step 3: Deprovision - Drop dormant users in batches\\nDROP PROVISIONED ROLES WITH SOURCE = 'ldap:ldap.example.com',\\n  LAST LOGIN BEFORE (now() - INTERVAL '90 days') LIMIT 50;\\n-- Step 4: Verify - Check remaining provisioned users\\nSHOW USERS WITH SOURCE = 'ldap:ldap.example.com';\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"4NQvU8IznuPrrmXLrXBSon\"},\"internalName\":\"Code Box 23\",\"component\":\"resources\",\"description\":\"-- CIS 5.3: Find accounts dormant for 45+ days\\nSHOW USERS WITH LAST LOGIN BEFORE (now() - INTERVAL '45 days');\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"4Nv48x5GsnGmIRGUcndxhg\"},\"internalName\":\"Code Box 24\",\"component\":\"resources\",\"description\":\"-- PCI DSS 8.2.6: Find accounts inactive for 90+ days\\nSHOW USERS WITH LAST LOGIN BEFORE (now() - INTERVAL '90 days');\\n\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}}]}}},\"aiSummary\":{\"__typename\":\"TemplateBlogAiSummary\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Database identity lifecycle management must extend beyond authentication: access should be provisioned, synchronized, audited, and safely removed from the same external identity source. CockroachDB provides these controls natively in SQL for LDAP, JWT, and OIDC users.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Just-in-time provisioning creates SQL users only after verified first login.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"IdP group changes sync to database role memberships at every successful login.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Source and login filters enable safer dormant-account reviews and cleanup.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"TemplateBlogAiSummaryLinks\",\"assets\":{\"__typename\":\"TemplateBlogAiSummaryAssets\",\"block\":[]},\"entries\":{\"__typename\":\"TemplateBlogAiSummaryEntries\",\"block\":[]}}},\"featuredBlog\":null,\"additionalFeatureCollection\":{\"__typename\":\"TemplateBlogAdditionalFeatureCollection\",\"items\":[]},\"tableStyling\":null,\"callOutEyebrow\":null,\"callOutTitle\":null,\"callOutDescription\":null,\"callOutButton\":null,\"isListing\":false,\"faqCollection\":{\"__typename\":\"TemplateBlogFaqCollection\",\"items\":[{\"__typename\":\"FaqItem\",\"title\":\"What is automatic user provisioning in CockroachDB?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Automatic user provisioning creates a CockroachDB SQL user when a person successfully authenticates through an external identity provider. It removes the need for an administrator to run \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"CREATE USER\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" before that person can access the database.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"Why can an externally authenticated user still be unable to access a database?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"External authentication verifies that a user exists in the identity provider, but the database must also recognize that person as a SQL user. Without automatic provisioning, an administrator must create the corresponding SQL user before the authenticated person can log in.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"Do I need to change database drivers to use LDAP or JWT authentication?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"No. CockroachDB uses the standard PostgreSQL password field as the credential channel, so existing PostgreSQL-compatible drivers, including \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"psql\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\",\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" pgx\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"libpq\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", and JDBC, can connect without custom authentication plugins or driver changes.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"What is just-in-time user provisioning?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Just-in-time user provisioning creates a SQL user only when a verified external identity first needs database access. In CockroachDB, a successful LDAP, JWT, or OIDC authentication can trigger creation of the corresponding SQL user when provisioning is enabled.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"}}},{\"__typename\":\"FaqItem\",\"title\":\"What is the PROVISIONSRC tag?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PROVISIONSRC \",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"is an immutable role option that records the authentication method and identity provider that provisioned a SQL user. It supports source-based auditing and lets operators scope deprovisioning to externally managed users from a specific provider.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"How does CockroachDB keep database roles synchronized with identity provider groups?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB synchronizes role memberships on every successful login for authentication methods with authorization enabled. It compares current IdP group memberships with database roles, then applies the necessary \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"GRANT\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" and \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"REVOKE\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" changes to keep the IdP as the access-control source of truth.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"Does CockroachDB automatically delete accounts removed from the identity provider?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"No. CockroachDB does not automatically delete a SQL account when its identity is removed from the provider. Operators can use \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"SHOW USERS\",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" filters to identify dormant provisioned accounts, then use\",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" DROP PROVISIONED ROLES \",\"marks\":[{\"type\":\"code\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"for controlled bulk cleanup.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"How does CockroachDB help manage the database user lifecycle?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB can provision users from external identities, synchronize their role memberships, retain provisioning-source information, and support SQL-based reviews and deprovisioning. This gives operators database-native controls for managing access across the full identity lifecycle.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}}]}},{\"__typename\":\"TemplateBlog\",\"seo\":{\"__typename\":\"MetaSeo\",\"pageTitle\":\"Core Banking Modernization with Temenos | CockroachDB\",\"pageDescription\":\"Learn how core banking modernization with Temenos Core and CockroachDB delivers scalable, resilient transaction processing without manual database sharding.\",\"openGraphImage\":{\"__typename\":\"Asset\",\"description\":\"Streams of financial data moving through a digital processing layer, representing scalable, resilient core banking modernization with Temenos Core and CockroachDB.\",\"title\":\"CockroachDB Core Banking Modernization with Temenos Core BLOG\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2aDUge47uqIeN7wvNB43N3/7f89ce8f8d866481e0d22e840ce9745e/CockroachDB_Core_Banking_Modernization_with_Temenos_Core_BLOG.png\",\"width\":1920,\"height\":1080},\"noIndex\":false,\"noFollow\":null,\"canonicalUrl\":null,\"seoSchemaJson\":null},\"internalName\":\"Core Banking Modernization with Temenos Core and CockroachDB \",\"sys\":{\"__typename\":\"Sys\",\"spaceId\":\"00voh0j35590\",\"publishedAt\":\"2026-08-24T05:00:12.455Z\",\"firstPublishedAt\":\"2026-08-24T05:00:12.455Z\",\"environmentId\":\"ab43b007-3cfb-450c-b575-1282ff083a83\",\"publishedVersion\":35},\"title\":\"Core Banking Modernization with Temenos Core and CockroachDB \",\"slug\":\"core-banking-modernization-temenos-cockroachdb\",\"publishDate\":\"2026-08-24T00:00:00.000Z\",\"lastUpdatedDate\":null,\"tags\":[\"Mainframe Modernization\"],\"thumbnailImage\":{\"__typename\":\"Asset\",\"description\":\"Streams of financial data moving through a digital processing layer, representing scalable, resilient core banking modernization with Temenos Core and CockroachDB.\",\"title\":\"CockroachDB Core Banking Modernization with Temenos Core BLOG\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2aDUge47uqIeN7wvNB43N3/7f89ce8f8d866481e0d22e840ce9745e/CockroachDB_Core_Banking_Modernization_with_Temenos_Core_BLOG.png\",\"width\":1920,\"height\":1080},\"excerpt\":\"Banking has become an always-on business. Customers expect instant payments, accurate balances, and continuous access to financial services...\",\"buttonText\":\"Read now\",\"authorsCollection\":{\"__typename\":\"TemplateBlogAuthorsCollection\",\"items\":[{\"__typename\":\"EntityPerson\",\"fullName\":\"Nanda Badrappan\",\"link\":\"/author/nanda-badrappan\",\"bio\":\"Nanda Badrappan is Deputy Chief Technology Officer at Temenos, where he plays a key role in shaping the company's technology strategy and innovation agenda. With more than 20 years of experience in banking technology, he is focused on helping financial institutions modernize core systems, embrace cloud transformation, and unlock new opportunities for growth.\\n\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"A profile image of Nanda Badrappan, Deputy Chief Technology Officer at Temenos. \",\"title\":\"Nanda Badrappan Deputy Chief Technology Officer Temenos\",\"url\":\"https://images.ctfassets.net/00voh0j35590/1s8m7ehxqERG2DPgE6WGIt/81862e3f59e6f9384cf0c1ca5571372f/Nanda_Badrappan_Deputy_Chief_Technology_Officer_Temenos.jpg\",\"width\":1588,\"height\":1584},\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null},{\"__typename\":\"EntityPerson\",\"fullName\":\"Muruga Balakrishnan\",\"link\":\"/author/muruga-balakrishnan\",\"bio\":\"Muruga Balakrishnan is a Sr. Partner Solutions Architect at Cockroach Labs, where he works with ISV, GSI, and reseller partners across the Asia-Pacific region, helping them build and scale mission-critical, always-on applications – from core banking platforms to fintech infrastructure – on CockroachDB. His background spans complex technical initiatives across core banking systems, database migration, and distributed data architecture, giving him a ground-level perspective on what it takes to align resilient database technology with real business outcomes. \\n\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"A profile image of Muruga Balakrishnan, Sr. Partner Solutions Architect Cockroach Labs.\",\"title\":\"Muruga Balakrishnan Sr. Partner Solutions Architect Cockroach Labs\",\"url\":\"https://images.ctfassets.net/00voh0j35590/2dzgsANyFeSxzVdCGAx3kI/6ae7f634de42a451ae3b67c1fd2966c4/Muruga_Balakrishnan_Sr._Partner_Solutions_Architect_Cockroach_Labs.jpg\",\"width\":1580,\"height\":1598},\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null}]},\"darkFooter\":false,\"blogDetail\":{\"__typename\":\"TemplateBlogBlogDetail\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"embedded-asset-block\",\"data\":{\"target\":{\"sys\":{\"id\":\"5iMP174nXES6QX514PdW5V\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Banking has become an always-on business. Customers expect instant payments, accurate balances, and continuous access to financial services, while banks face increasingly demanding resilience and regulatory requirements. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.temenos.com/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos \",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"and Cockroach Labs are addressing these demands by running \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.temenos.com/products/core-banking/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos Core\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" on \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/product/overview/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\", combining cloud-native core banking capabilities with a \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/glossary/distributed-db/distributed-sql/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"distributed SQL database\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" designed for resilient, scalable transaction processing.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Yet many institutions still depend on decades-old core infrastructure built around batch processing and vertically scaled databases. This makes core banking modernization increasingly important for supporting real-time transactions, continuous availability, and distributed operations.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Why legacy core banking infrastructure is falling behind \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Many banks are asking for infrastructure designed for an earlier era to support always-on transactions, modern regulatory requirements, and increasingly distributed operations. The consequences increasingly appear in database resilience and availability, technology costs, and the ability to support real-time banking. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"This pressure to modernize core banking infrastructure is no longer theoretical. \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.reuters.com/world/uk/britains-top-banks-clocked-up-33-days-worth-it-glitches-two-years-2025-03-06/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"UK banks experienced 158 outages\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" between January 2023 and February 2025, totaling 33 days of downtime. That adds up to over a month of disrupted banking services.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"At the same time, aging core systems consume technology budgets that could otherwise fund innovation. Batch-oriented architectures also make it harder to deliver the real-time processing customers expect, while regulations such as the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/dora-database-requirements-ai-agents/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"EU Digital Operational Resilience Act (DORA)\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" raise the bar for operational resilience.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-6\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Related\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Cockroach Labs sales engineers David Joy and Jim Hatcher trace how data modernization has evolved from early on-prem systems through virtualization and the cloud, and explain why distributed SQL is now central to building resilient, scalable, future-ready data infrastructure. \",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.youtube.com/watch?v=1TkrOzsxCqs\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Unboxing the Cloud: AI, Microservices, and Resilient Databases | Big Ideas In App Architecture\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What core banking actually does, and why the database matters\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“A core banking system is the operational system of record for customer accounts, balances, transactions, and financial events,” says David Joy, Technical Director | AI, Ecosystem \u0026 Partnerships. “It must support workloads ranging from real-time transaction processing to interest accruals, Close of Business (COB), multi-currency and multi-entity operations, and integrations with payments, fraud, and regulatory systems.”\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“That makes the underlying database a foundational part of core banking system architecture,” Joy continues. “Its scalability affects transaction capacity, its availability affects whether customers can transact, and its consistency affects the accuracy of the bank's books.”\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How T24 evolved into Temenos Core \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos Core is a cloud-native, microservices-based core banking platform designed for continuous innovation and upgradability. It evolved from the platform previously known as T24 and Temenos Transact and today serves more than 1,000 financial institutions across 150+ countries. \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Key capabilities include:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"High-volume transaction processing:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Manages the transaction lifecycle from booking through settlement, including the High Volume Transaction (HVT) Merge Service for efficiently processing large volumes of postings.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Multi-currency and multi-entity operations:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Supports operations across 20+ currencies, multiple legal entities, cross-border booking, and back-valued transactions up to 10 years.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Close of Business processing:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Runs parallel end-of-day processing for account balancing, interest accruals, and preparation for the next business day.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Open, extensible architecture:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Uses open APIs, the Temenos Extensibility Framework (TEF), and the Java-based TAFJ runtime to support integration, extensibility, and cloud-native deployment.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Why CockroachDB for Temenos Core?\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“Scaling a modern core banking platform has many requirements,” explains Joy. “The database layer must support growing transaction volumes, continuous availability, distributed deployments, and strong transactional consistency without relying on \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/sharding-bad-business/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"manual sharding\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" or complex failover architectures.”\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“CockroachDB is a distributed SQL database built on a transactional, strongly consistent key-value store, inspired by \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/what-is-distributed-sql/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Google Spanner and F1\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\",” Joy says. “It combines horizontal scale and automated resilience with serializable ACID transactions and a familiar SQL interface, providing a distributed database foundation for Temenos Core.” \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Key CockroachDB capabilities that support Temenos Core include: \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Horizontal scalability without manual sharding:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" CockroachDB supports database scalability by allowing nodes to be added as transaction volumes grow without manual re-sharding or schema redesign. \",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"High availability by design:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" CockroachDB provides a high availability database architecture by replicating data across nodes using the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/raft-is-so-fetch/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Raft consensus algorithm\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" and automatically recovering from infrastructure failures without requiring manual failover.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Serializable ACID transactions:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" CockroachDB provides serializable isolation across the distributed cluster, maintaining transactional consistency as workloads span nodes.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Flexible deployment:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" CockroachDB can run on-premises on Kubernetes, in Cockroach Cloud on Azure or AWS, or as part of a hybrid architecture.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Data sovereignty controls:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/product/geo-partitioning/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Geo-partitioning\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" capabilities can place data in specific regions to support data residency requirements while maintaining distributed operations.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"PostgreSQL compatibility:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" CockroachDB supports the \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/docs/stable/postgresql-compatibility\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"PostgreSQL wire protocol\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" and the majority of PostgreSQL syntax. Temenos Core connects through a PostgreSQL-flavored JDBC configuration in TAFJ, reducing integration complexity.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Proven financial services adoption:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" \",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/solutions/verticals/financialservices/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Financial services organizations\",\"marks\":[{\"type\":\"underline\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\", including Global Payments and Groww, use CockroachDB for critical transactional workloads.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Related \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/guides/financial-services/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Banking resilience at global scale with Distributed SQL\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" — how Fortune 500 financial service companies use distributed SQL to eliminate risk, optimize costs, and deliver an ideal customer experience. \",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"How Temenos Core and CockroachDB work together \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos Core and CockroachDB address complementary layers of the banking stack: Temenos provides the core banking application capabilities, while CockroachDB provides a distributed transactional database foundation for scale, resilience, and consistency.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"table\",\"data\":{},\"content\":[{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Business Need\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What Temenos Brings\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"What CockroachDB Brings\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Transaction at scale\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"HVT architecture, parallel booking, real-time COB\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Horizontal scaling and near-linear TPS growth with node addition\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Always-on operations\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Modular microservices and Kubernetes-native deployment\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Automatic failover and multi-region replication\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Regulatory compliance\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"AML, tax, audit, ISO 20022 and SWIFT MX capabilities\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Geo-partitioning, data sovereignty controls, and serializable isolation\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Multi-currency / multi-entity\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"20+ currency support and multi-company framework\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Consistent distributed ACID transactions\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Cloud flexibility\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Kubernetes on-premises, Azure, and AWS deployment models\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Cloud-agnostic, on-premises, and hybrid deployment\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Operational efficiency\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"TAFJ Java runtime, containerization, and open APIs\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Automatic rebalancing without manual database sharding\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"table-row\",\"data\":{},\"content\":[{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"AI and real-time analytics readiness\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Event-driven architecture and open data APIs\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"table-cell\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Changefeeds for streaming data to analytics platforms\",\"marks\":[],\"data\":{}}]}]}]}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Related \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/compare/cockroachdb-vs-google-spanner/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB vs. Google Spanner\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" — a technical comparison of two distributed SQL pioneers, including deployment flexibility across on-prem, hybrid, and multi-cloud. \",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“For existing Temenos Core customers, CockroachDB provides a path to database modernization by addressing database scalability and availability requirements without replacing the application's business logic,” says Nanda Badrappan, Deputy Chief Technology Officer for Temenos. “TAFJ's CockroachDB configuration provides the integration path between the two platforms.”\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos Core on CockroachDB: functionality and performance validation \",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Joint testing demonstrated that Temenos Core on CockroachDB could support the tested multi-currency, high-volume, and Close of Business (COB) workloads while scaling near-linearly as resources were added in the tested configurations. Temenos and Cockroach Labs jointly validated Temenos Core on CockroachDB v25.4.2 across on-premises Kubernetes environments and Microsoft Azure. The testing processed \",\"marks\":[],\"data\":{}},{\"nodeType\":\"text\",\"value\":\"2 million transactions across 20,000 accounts\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\", including approximately 750,000 transactions against a single high-volume account.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The validation covered:\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"unordered-list\",\"data\":{},\"content\":[{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Multi-currency transaction processing:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Transactions across 20 currencies, including back-valued transactions spanning up to 10 years.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"High-volume processing:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" The HVT Merge Service ran concurrently with live online transaction workloads without degrading online transaction performance.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Close of Business:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" COB processing completed successfully following active transaction workloads without interruption or performance degradation.\",\"marks\":[],\"data\":{}}]}]},{\"nodeType\":\"list-item\",\"data\":{},\"content\":[{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Horizontal and vertical scalability:\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"text\",\"value\":\" Both increasing resources per node and adding application pods and database nodes were evaluated using a realistic Tier 1 bank transaction mix. Near-linear scaling was observed in the tested configurations as resources were added.\",\"marks\":[],\"data\":{}}]}]}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"In the cloud environment, transaction throughput increased as application pods and database nodes were added while CPU utilization and memory profiles remained stable across the cluster. In the on-premises configuration, the HVT Merge Service completed concurrently with online transaction workloads, demonstrating the ability to run mixed workload types without mutual interference. COB processing also completed successfully across test runs, validating operational integrity from transaction booking through day-end settlement.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"The integration required targeted configuration across TAFJ, CockroachDB, and the application layer, including transaction isolation settings, zone configurations for high-contention tables, and messaging-layer optimizations. These configuration parameters have been documented as part of the joint reference architecture.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Detailed benchmarking results including hardware specifications, tuning parameters, scalability results, and monitoring charts are available to prospective customers through the joint Temenos–Cockroach Labs engagement team.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Looking ahead\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"“This validation program marks the beginning of a deeper integration roadmap,” Badrappan observes. “Temenos and Cockroach Labs plan to extend the joint work through larger-scale performance testing, reference architectures for on-premises and cloud deployments, migration tooling for existing Temenos customers, multi-region deployment patterns for data sovereignty requirements, and deeper integration across the Temenos suite.”\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"heading-2\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Get started\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"See how the validated Temenos Core and CockroachDB architecture could support your core banking modernization requirements.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Request the full technical benchmarking report or speak with a \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.temenos.com/contact-us/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Temenos\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\" or \",\"marks\":[{\"type\":\"bold\"}],\"data\":{}},{\"nodeType\":\"hyperlink\",\"data\":{\"uri\":\"https://www.cockroachlabs.com/contact/\"},\"content\":[{\"nodeType\":\"text\",\"value\":\"Cockroach Labs expert\",\"marks\":[{\"type\":\"underline\"},{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"text\",\"value\":\".\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"hr\",\"data\":{},\"content\":[]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"2026 Temenos Headquarters SA and Cockroach Labs, Inc. This document is intended for informational purposes. Performance results are environment-specific and may vary based on configuration, workload, and infrastructure. \",\"marks\":[{\"type\":\"italic\"}],\"data\":{}}]}]},\"links\":{\"__typename\":\"TemplateBlogBlogDetailLinks\",\"assets\":{\"__typename\":\"TemplateBlogBlogDetailAssets\",\"block\":[{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5iMP174nXES6QX514PdW5V\",\"spaceId\":\"00voh0j35590\"},\"description\":\"Streams of financial data moving through a digital processing layer, representing scalable, resilient core banking modernization with Temenos Core and CockroachDB.\",\"title\":\"CockroachDB Core Banking Modernization with Temenos Core SOCIAL Webp\",\"url\":\"https://images.ctfassets.net/00voh0j35590/5iMP174nXES6QX514PdW5V/95532e1872eced869db33c9286657b7c/CockroachDB_Core_Banking_Modernization_with_Temenos_Core_SOCIAL_Webp.webp\",\"width\":1200,\"height\":675}]},\"entries\":{\"__typename\":\"TemplateBlogBlogDetailEntries\",\"block\":[]}}},\"aiSummary\":{\"__typename\":\"TemplateBlogAiSummary\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"CockroachDB scales Temenos Core without manual database sharding.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"CockroachDB modernizes Temenos Core without replacing its business logic.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Joint testing processed 2M transactions across 20K accounts and scaled near-linearly.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"TemplateBlogAiSummaryLinks\",\"assets\":{\"__typename\":\"TemplateBlogAiSummaryAssets\",\"block\":[]},\"entries\":{\"__typename\":\"TemplateBlogAiSummaryEntries\",\"block\":[]}}},\"featuredBlog\":null,\"additionalFeatureCollection\":{\"__typename\":\"TemplateBlogAdditionalFeatureCollection\",\"items\":[]},\"tableStyling\":null,\"callOutEyebrow\":null,\"callOutTitle\":null,\"callOutDescription\":null,\"callOutButton\":null,\"isListing\":false,\"faqCollection\":{\"__typename\":\"TemplateBlogFaqCollection\",\"items\":[{\"__typename\":\"FaqItem\",\"title\":\"What is core banking modernization?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Core banking modernization updates the technology supporting a bank’s core transaction and account systems to meet modern requirements for real-time processing, availability, scalability, and regulatory resilience. Modernization can occur at multiple layers and does not always require replacing the core application itself.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"How does distributed SQL support core banking modernization?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Distributed SQL supports core banking modernization by combining relational SQL and transactional consistency with horizontal scalability and distributed resilience. This can help core banking systems handle growing transaction volumes and continuous availability requirements without relying on manual database sharding.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"What database capabilities are important for core banking systems?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-3\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Core banking systems require databases that provide scalability, high availability, strong transactional consistency, and support for distributed deployments. These capabilities help banks maintain accurate records and continuous transaction processing as workloads grow.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"}}},{\"__typename\":\"FaqItem\",\"title\":\"Can banks modernize their database without replacing their core banking system?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Yes. Database modernization can address infrastructure-level scalability and availability requirements without replacing the core application’s business logic. For Temenos Core, TAFJ provides the configuration path for integrating CockroachDB as the underlying database.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"How does CockroachDB improve scalability and resilience for Temenos Core?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"CockroachDB provides Temenos Core with horizontal database scalability, automated resilience, and serializable ACID transactions without manual sharding. Joint testing showed near-linear scaling in the tested configurations while supporting high-volume, multi-currency, and Close of Business workloads.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}}]}},{\"__typename\":\"TemplateBlog\",\"seo\":{\"__typename\":\"MetaSeo\",\"pageTitle\":\"A2A Agent State and Data Consistency | CockroachDB\",\"pageDescription\":\"Learn how A2A agent state needs serializable consistency, durable memory, and scoped access to keep multi-agent systems resilient across boundaries.\",\"openGraphImage\":{\"__typename\":\"Asset\",\"description\":\"Two AI agents exchanging data above constrained database infrastructure, representing the state and consistency layer beneath A2A communication.\",\"title\":\"CockroachDB A2A open standard Blog\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3REYvldUgwVXYUIb6QLRUs/3b8601c85f2c3e1853d6813f8c240cd9/CockroachDB_A2A_open_standard_Blog.png\",\"width\":1920,\"height\":1080},\"noIndex\":false,\"noFollow\":null,\"canonicalUrl\":null,\"seoSchemaJson\":null},\"internalName\":\" A2A Is Now an Open Standard. The Data Layer Underneath It Isn't.\",\"sys\":{\"__typename\":\"Sys\",\"spaceId\":\"00voh0j35590\",\"publishedAt\":\"2026-08-19T22:33:56.717Z\",\"firstPublishedAt\":\"2026-08-19T16:00:55.261Z\",\"environmentId\":\"ab43b007-3cfb-450c-b575-1282ff083a83\",\"publishedVersion\":95},\"title\":\" A2A Is Now an Open Standard. The Data Layer Underneath It Isn't.\",\"slug\":\"a2a-agent-state-data-layer\",\"publishDate\":\"2026-08-19T00:00:00.000Z\",\"lastUpdatedDate\":null,\"tags\":[\"AI\"],\"thumbnailImage\":{\"__typename\":\"Asset\",\"description\":\"Two AI agents exchanging data above constrained database infrastructure, representing the state and consistency layer beneath A2A communication.\",\"title\":\"CockroachDB A2A open standard Blog\",\"url\":\"https://images.ctfassets.net/00voh0j35590/3REYvldUgwVXYUIb6QLRUs/3b8601c85f2c3e1853d6813f8c240cd9/CockroachDB_A2A_open_standard_Blog.png\",\"width\":1920,\"height\":1080},\"excerpt\":\"In April 2025, Google released a protocol for agent-to-agent communication. Within three months, Google had donated it to the Linux Foundation...\",\"buttonText\":\"Read now\",\"authorsCollection\":{\"__typename\":\"TemplateBlogAuthorsCollection\",\"items\":[{\"__typename\":\"EntityPerson\",\"fullName\":\"Quentin Packard\",\"link\":\"/author/quentin-packard\",\"bio\":\"Quentin Packard is GM of Americas at Cockroach Labs.\",\"headshot\":{\"__typename\":\"Asset\",\"description\":\"Profile image of Quentin Packard, VP Americas Sales, Cockroach Labs\",\"title\":\"Quentin Packard VP Americas Sales Cockroach Labs\",\"url\":\"https://images.ctfassets.net/00voh0j35590/19NVU4gn6nxNM4T9TUTQPl/dd24b4ef2ed0ebb04ffcfad986a73d45/Quentin_Packard_VP_Americas_Sales_Cockroach_Labs.jpg\",\"width\":1592,\"height\":1598},\"role\":null,\"linkedInUrl\":null,\"githubUrl\":null,\"company\":null}]},\"darkFooter\":false,\"blogDetail\":{\"__typename\":\"TemplateBlogBlogDetail\",\"json\":{\"data\":{},\"content\":[{\"data\":{\"target\":{\"sys\":{\"id\":\"1og3cz5LS5rU8F1vM9K4EW\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In April 2025, \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/\"},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Google released a protocol\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" for agent-to-agent communication. Within three months, Google had donated it to the Linux Foundation, where AWS, Cisco, Microsoft, Salesforce, SAP, and ServiceNow signed on to govern it. By December, Anthropic and OpenAI had put MCP and AGENTS.md under the same roof through the Agentic AI Foundation. Azure, Amazon Bedrock AgentCore, and Google Cloud have integrated A2A natively, and more than 150 organizations now support it. Release to Linux Foundation-governed 1.0 took  eleven months. The communication layer now has an owner.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The state layer doesn't. A2A defines how agents send tasks and return results. It says nothing about where the state those tasks depend on actually lives, who owns it, or what happens when two agents touch it at once. In \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/database-for-ai-applications/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"production multi-agent systems\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", those aren't protocol details; they're architecture decisions that determine whether shared state stays consistent, durable, governable, and auditable. The coordination point is the database, not the task message, and that's exactly what the protocol leaves undefined. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"What is A2A, and how is it different from MCP? \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A enables horizontal agent-to-agent connection: It defines how one agent delegates work to another across vendors, teams, and infrastructure stacks, without either side needing to know how the other works internally.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"MCP, Anthropic's Model Context Protocol, is vertical: it defines how a single agent connects to external tools and data sources within its own context window.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The two protocols address different layers of the same problem:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"MCP\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"A2A\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Agent to tools and data sources\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Agent to agent\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Vertical connection\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Horizontal coordination\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Single context window\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Multiple context windows\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Internal to your system\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Crosses organizational and vendor boundaries\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Solves: What tools can my agent use?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Solves: How do agents delegate to other agents?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"}],\"nodeType\":\"table\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Production multi-agent systems use both. An orchestrating agent uses A2A to route a task to a specialist. The specialist uses MCP to call the tools it needs to complete it. They're not competing standards. They're different layers of the same architecture.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Neither protocol addresses what must happen at the data and state layer underneath both of them.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"What AGENTS.md standardizes, and what it leaves out \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"AGENTS.md reinforces the same architectural pattern as MCP and A2A: it standardizes an interface while leaving durable state outside the standard. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In August 2025, OpenAI, Google, Cursor, Factory, and Sourcegraph shipped \",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"AGENTS.md\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\", a plain Markdown file that tells a coding agent how to operate in a repository: build commands, conventions, test procedure, boundaries. A README for agents. Within months it was in more than 60,000 open source projects, and by December OpenAI had donated it to the Agentic AI Foundation, the same Linux Foundation body Anthropic, OpenAI, and Block formed to steward MCP alongside it.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"So the agent stack now has three open standards, one per interface. MCP defines how an agent reaches tools and data. A2A defines how agents delegate to each other. AGENTS.md defines how an agent receives its operating instructions.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Notice what all three have in common. Each standardizes a contract, and each deliberately says nothing about state. AGENTS.md is the purest example: it's a static file. It can tell an agent what to do. It can't remember what the agent did. No memory of previous runs, no record of decisions made, no identity, no audit trail. The spec keeps it that way on purpose: plain Markdown, no required fields, no schema. (Claude Code is a useful data point here: as of this writing it still reads its own CLAUDE.md rather than AGENTS.md natively, a small reminder that even the instruction layer hasn't fully consolidated, let alone the state layer underneath it.)\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"That's three layers of the stack settling on the same design choice: standardize the interface, leave the state to you. Durable memory, shared state, identity, and auditability all  land on the data layer underneath. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Why A2A makes the database problem harder\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A makes the database problem harder because agents can coordinate across organizational boundaries without sharing a state store, consistency model, or view into each other's internals. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"With a single agent using MCP, the infrastructure problem is more tractable: one agent, one context window, one consistency model. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"When an orchestrator delegates to a specialist at a different organization, that specialist is autonomous. It may use a different database, memory layer, transaction model, and consistency guarantee entirely. A2A makes the agents interoperable at the communication layer; it does not make their state models interoperable. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"So what's the consistency guarantee across the full workflow?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The A2A protocol defines how the task is sent and how the result is returned. It says nothing about state management, memory handling, or data consistency during execution. That's intentional. The spec explicitly keeps agent internals opaque from one another.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"That opacity is what makes interoperability work. Everything that follows is the bill for it.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"How A2A affects shared state and transaction consistency \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A agents have no transaction model between them. The protocol defines how their messages move, not how concurrent reads and writes to shared state remain consistent. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"In traditional distributed systems, services coordinating on shared data can use \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/distributed-transactions-what-why-and-how-to-build-a-distributed-transactional-application/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"distributed transactions\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", two-phase commit, or saga patterns to define what happens if one service fails mid-operation.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"When an A2A orchestrator agent distributes subtasks to specialist agents running in parallel, the protocol provides no equivalent state management guarantee. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Here's the anomaly concretely. Two agents both check whether a task is claimed, both see that it isn't, and both claim it. Both agents' transactions are open at the same time:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"2B6fRpSfyipKe62MlaqWa1\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/read-committed\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Read Committed\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" doesn't error here because each statement reads from its own snapshot: nothing ties Agent 2's earlier read of claimed = false to its later write, so the overwrite is legal. At SERIALIZABLE, CockroachDB treats that earlier read as part of the transaction's consistency contract. When the underlying data changes, the second transaction aborts with a \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/232-read-committed-no-more-anomaly-tables/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"retryable error\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" instead of silently overwriting Agent 1's claim. The isolation level of the shared store, not the protocol, determines whether this conflict is detected before it becomes corrupted shared state that downstream agents may continue acting on.  \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The obvious rejoinder: careful SQL avoids this at any isolation level. A conditional write (UPDATE ... SET claimed = true WHERE task_id = ... AND claimed = false, checking rows affected) or SELECT FOR UPDATE closes this particular hole. True, and beside the point. That fix assumes every access path was written by someone who saw the race coming. \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/agentic-ai-coming-for-your-database/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Agentic systems\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" are exactly where that assumption dies: agents compose queries at runtime, retry on their own schedule, and multiply access paths faster than any review can audit them. \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/glossary/distributed-db/serializable-isolation/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Serializable isolation\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" makes this class of concurrency failure the store's responsibility rather than relying on every access path to anticipate it.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A second objection: isn't this what durable workflow engines like Temporal already solve? \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Partly. A workflow engine checkpoints execution so a crashed process can resume, which is necessary but not the guarantee an A2A workflow needs. Temporal's event history can tell you what your activities did. It doesn't govern shared data outside that execution boundary: what another organization's agent accessed, whether concurrent writes remain consistent, or whether months later a compliance team can query what data was touched and under whose identity. Those are queryable, joinable, access-controlled data questions. Agent state across an A2A boundary is data-shaped, not workflow-shaped.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A workflow engine is a reasonable place to checkpoint your own agent's execution. It isn't a substitute for the shared, governed data layer two independent organizations need to reason about each other's state.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"How A2A handles context transfer, and what it leaves to agent memory \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A lets one agent  send a task description and selected context to another, but it doesn't solve shared agent memory. When agents need context beyond what travels with the task, they need durable external storage both sides can query. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Anthropic frames context as a critical but finite resource. Managing it within a single long-running agent is already hard. However, \\\"relevant context\\\" is undefined by the A2A spec, so the receiving agent otherwise starts fresh.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"5ozBwF1gRPwD9UzE1xDqut\",\"type\":\"Link\",\"linkType\":\"Asset\"}}},\"content\":[],\"nodeType\":\"embedded-asset-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"subscript\"},{\"type\":\"italic\"}],\"value\":\"A2A transfers selected context between agents, leaving teams to determine how much state should persist across the handoff. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Anthropic's work on long-running agents points toward \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/agentic-ai-architecture-memory-control/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"durable external context storage\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" that agents query, rather than carry in-window. For multi-agent systems, that memory isn't only semantic recall or \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/distributed-vector-indexing-cockroachdb/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"vector retrieval\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\". It can also include operational state: what work has completed, what decisions were made, which resources were touched, and what another agent can safely act on next. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Across an A2A boundary, that raises a harder question: Where does shared context live when agents from different organizations build on each other's work, and who owns it? Closing that gap takes a store both sides can query directly, not a bigger task message. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"How A2A complicates identity across organizational boundaries \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A doesn't define the identity a third-party specialist should use when it acts on another agent's behalf. Credential pass-through and independent identity are the two obvious models, and both create problems. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Within a single organization, agents need per-session identities, \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://docs.cockroachlabs.com/docs/stable/security-reference/authorization\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"scoped credentials\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", and explicit delegation chains that narrow permissions at each hop. Across an organizational boundary, the question gets harder: Under what identity does that specialist act? \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Credential pass-through.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" The orchestrator passes its identity to the specialist. The specialist acts under your organization's credentials. Any error or breach in the specialist's system now has the blast radius of your organization's data access scope.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Independent identity.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" The specialist operates under its own identity entirely. Your organization no longer controls how that identity is scoped or enforced, making cross-boundary access governance dependent on the specialist's system. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"What your security model assumes\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"What A2A creates without intentional design\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Your orchestrating agent has a per-session identity and scoped credentials\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Third-party specialist agent’s identity model is undefined by the protocol; you don’t know what it can access, under whose credentials, or how its permissions are scoped\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Internal sub-agents receive narrowed permissions at each delegation hop\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Permissions cannot be narrowed across vendor boundaries; each delegation hop depends on trust, not enforcement\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Full audit trail is reconstructible under your control\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Audit trail across the boundary is the specialist's problem. Your workflow depends on their output.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"table-cell\"}],\"nodeType\":\"table-row\"}],\"nodeType\":\"table\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\\nThe missing capability is enforceable delegation: a way to give the specialist only the authority required for one task, preserve who delegated that authority, and revoke or expire it when the work ends. The emerging pattern is explicit delegation, covered in the Patterns section below. It requires a token service that understands A2A task scope. The protocol doesn't provide one.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[],\"nodeType\":\"hr\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Related \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-6\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/guides/3-ai-use-cases/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"value\":\"Built for AI: Scaling IAM, Metadata Management, and Vector Search on One Database\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\" — how AI leaders like Ory/OpenAI and CoreWeave unify identity, metadata, and vector search on one distributed SQL platform. \",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[],\"nodeType\":\"hr\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Why A2A complicates observability across organizational boundaries \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A doesn't guarantee a complete audit trail across organizational boundaries. Each organization can run a different observability system, and the protocol doesn't require them to agree on what execution data to log or share.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"For an agentic workflow, observability means more than infrastructure health or database metrics. Reconstructing execution can require the task, tool calls, data accessed, identity used, state changes, and result to remain correlated across the handoff. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Even a useful single-agent audit trail is demanding: every tool call, input, output, identity, and cost, in order. But one team controls the full execution. An A2A pipeline can cross organizations and observability systems, making a complete reconstruction dependent on what each side records and exposes.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Consider a loan-processing pipeline that delegates compliance verification to a third-party agent over A2A. The orchestrating agent handles document intake and risk scoring; the specialist performs the compliance check. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Then a regulatory exam asks a straightforward question: for a set of flagged applications, what customer data did the compliance verification step access, and under what credentials?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The orchestrating agent's logs are complete: task sent, result received, status completed. The specialist agent's internal execution is opaque by design: what data it queried, what rules it applied, under what identity it accessed applicant records. That opacity is what makes A2A interoperable across organizations.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"It's also what makes the honest audit answer \\\"we don't know.\\\" Reconstructing the specialist's behavior from partial evidence isn't good enough for a regulator. The fix is negotiating cross-boundary logging with the specialist vendor before the first production task runs, not after the exam.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Patterns for the data layer across A2A boundaries \",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Three patterns are emerging for A2A systems that cross organizational boundaries: shared external memory for context transfer, checkpoint-based state management for fault tolerance, and explicit delegation with automatic expiry for identity. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"These patterns are already appearing in production. \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.linuxfoundation.org/press/a2a-protocol-surpasses-150-organizations-lands-in-major-cloud-platforms-and-sees-enterprise-production-use-in-first-year\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"The Linux Foundation's one-year report on A2A\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" cites deployments spanning supply chain, financial services, insurance, and IT operations. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Shared external memory layers handle context transfer. Rather than serializing context into task messages, teams build a shared, queryable store both sides of the A2A boundary can access. Done carelessly, this is a 20-year-old integration antipattern: two organizations pointing application code at the same tables with no contract between them is exactly how the identity and audit problems above compound instead of resolving. Done deliberately, it isn't table sharing. It's a governed context store with a schema contract for context objects, \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/fine-grained-access-control-row-level-security/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"row-level access policies\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" enforced at the database layer, and consistency strong enough that one agent can't silently corrupt what another depends on. Who hosts it is itself a design decision: orchestrator-hosted, specialist-hosted, or hosted by a neutral third party. Each choice shifts who holds root access, who pays for it, and whose auditors sign off. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"That store must preserve the properties established above under real cross-organizational workloads: serializable access to shared state, durable checkpoints that \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/multi-region-database-architecture-sql-placement-locality/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"survive a region failure\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", and database-level access enforcement. None of that is protocol-layer work. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Checkpoint-based state management handles fault tolerance. A workflow engine can make execution durable; the shared store has to make the state that execution depends on durable and consistent. If a specialist fails mid-task, the orchestrator needs the last consistent state to retry or compensate. That means persisting enough state after significant operations to resume from a known-good point rather than re-running the full workflow from scratch. Transport-layer delivery guarantees are not sufficient for this.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Explicit delegation with automatic expiry handles identity. The orchestrator issues a task-scoped credential, the specialist uses it for that task only, and it expires at completion. The audit trail covers both the issuance and the use. The implementation pattern for per-session, scoped credentials in a single-organization agent system is covered in detail in \\\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/ai-agent-identity-security/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Why Your AI Agent Has an Identity Problem\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\".\\\" The same principles apply across an A2A boundary, with the added complexity that you don't control the other side's enforcement.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[],\"nodeType\":\"hr\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Related\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-6\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/guides/architects-playbook-ai-ready-systems/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"The Architect's Playbook for Building AI-Ready Systems\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" — practical architectures for vector workloads, real-time consistency, agent memory, and global scale on distributed SQL.  \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[],\"nodeType\":\"hr\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"When You Don't Need A2A (or Any of This)\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Not every multi-agent system has this problem. You can skip A2A, and most of the data-layer work above, if any of the following describes your system.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Every agent runs inside one organization, on one framework.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" Sub-agents in a single LangGraph, ADK, or OpenAI Agents SDK app share a runtime. Your framework's state management and your database's transactions already cover them; A2A adds a network boundary you don't need.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"One agent, many tools.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" That's MCP's job. Wiring A2A between components that could be tool calls adds latency and failure modes without adding capability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Specialists only read.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" If delegated agents never write shared state, the consistency problem collapses to caching and staleness. Identity and audit still apply. Transactions mostly don't.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"The workflow is disposable.\",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\" Prototypes re-run from scratch. Checkpointing is overhead until re-running has a cost.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The condition that changes the answer is an organizational boundary plus writes: the first time an agent you don't operate writes state your workflow depends on, everything above applies.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Questions to Answer Before You Build on A2A\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"If you're designing a multi-agent system that uses A2A, the infrastructure questions to answer before you write protocol code:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Who owns the shared state between agents, and under what consistency model?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What context travels with an A2A task, and how does the receiving agent access the rest?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What identity governs each agent in the workflow, and how does delegation narrow at each hop?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What does a complete audit record look like across your full A2A pipeline?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"What happens to in-flight state if an agent mid-workflow goes down?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"ordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"For third-party specialist agents, also ask:\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"6. What's the data access boundary between your system and the specialist, and who enforces it at the database layer rather than at the application layer?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"7. How do you build a useful audit trail across an organizational boundary where you don't control the other side's logging and identity model?\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The communication layer has an owner now. What remains is the data infrastructure underneath it: shared state, durable context, identity across boundaries, and observability at the handoff.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/agentic-ai-database-architecture/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Serializable isolation\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\", survival across region failure, and database-enforced access policy are requirements that distributed SQL is built to address. Memori, a SQL-native memory engine for agents, provides the governed context layer described above on CockroachDB.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Most of that work is being figured out in production incidents. Architecture reviews are cheaper.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Ready to go deeper?\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The identity and governance challenges in multi-agent systems within a single organization are covered here: \\\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/ai-agent-identity-security/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Why Your AI Agent Has an Identity Problem\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\".\\\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"The broader infrastructure challenges that determine whether agentic AI ships to external production, including state management, thundering herd, blast radius, and observability: \\\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/agentic-ai-production-infrastructure/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"What Breaks When Agentic AI Reaches Production?\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\\\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Anthropic's framework on context engineering is the right starting point for thinking about what has to happen at the memory layer before, during, and after an A2A task handoff: \\\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"Effective context engineering for AI agents.\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\\\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"For a look at what durable, queryable agent memory looks like when these patterns are actually deployed, the Memori Labs integration walkthrough is a useful reference: \\\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/blog/agent-memory-database-cockroachdb-memori/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"CockroachDB + Memori Labs: Keeping Agent Context Alive.\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\"\\\"\\n\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"An AGENTS.md You Can Paste In\",\"nodeType\":\"text\"}],\"nodeType\":\"heading-2\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Paste this into a repo that has agents writing to a shared CockroachDB store. It encodes the pattern this post argues for, instead of just describing it.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"TcD9oEUJ0IzODn76cNSMX\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"bold\"}],\"value\":\"Props: \",\"nodeType\":\"text\"},{\"data\":{},\"marks\":[],\"value\":\"Thank you to Cockroach Labs' \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/author/david-bressler/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"}],\"value\":\"David Bressler\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[],\"value\":\" for review of this article. \",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"A2A handles communication between agents, while the data layer must keep their shared state consistent and resilient. Learn how CockroachDB supports consistent, resilient state for multi-agent systems. \",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.cockroachlabs.com/contact/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"underline\"},{\"type\":\"italic\"}],\"value\":\"Talk to an expert\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\".\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{\"target\":{\"sys\":{\"id\":\"5ubHv23Co4eNMwSJYxnzcb\",\"type\":\"Link\",\"linkType\":\"Entry\"}}},\"content\":[],\"nodeType\":\"embedded-entry-block\"},{\"data\":{},\"content\":[],\"nodeType\":\"hr\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"},{\"data\":{\"uri\":\"https://www.linkedin.com/in/qpackard/\"},\"content\":[{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\"Quentin Packard\",\"nodeType\":\"text\"}],\"nodeType\":\"hyperlink\"},{\"data\":{},\"marks\":[{\"type\":\"italic\"}],\"value\":\" is GM of Americas at Cockroach Labs, where he works with engineering and infrastructure leaders building production-grade agentic AI systems. He previously helped build Splunk's observability business and has worked across infrastructure automation, secrets management, and real-time data governance at HashiCorp and early-stage startups. His writing draws on direct conversations with enterprise teams navigating AI and data architecture in production.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"TemplateBlogBlogDetailLinks\",\"assets\":{\"__typename\":\"TemplateBlogBlogDetailAssets\",\"block\":[{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"1og3cz5LS5rU8F1vM9K4EW\",\"spaceId\":\"00voh0j35590\"},\"description\":\"Two AI agents exchanging data above constrained database infrastructure, representing the state and consistency layer beneath A2A communication.\",\"title\":\"CockroachDB A2A open standard Social Webp\",\"url\":\"https://images.ctfassets.net/00voh0j35590/1og3cz5LS5rU8F1vM9K4EW/b8bce50f82ed6539f3c485958a50f35b/CockroachDB_A2A_open_standard_Social_Webp.webp\",\"width\":1200,\"height\":675},{\"__typename\":\"Asset\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5ozBwF1gRPwD9UzE1xDqut\",\"spaceId\":\"00voh0j35590\"},\"description\":\"Diagram showing Agent A passing selected context through an A2A task message to Agent B, illustrating how too much context can overwhelm the receiving agent while too little can cause duplicated work or inconsistent decisions.\",\"title\":\"CockroachDB A2A open standard Social Diagram1\",\"url\":\"https://images.ctfassets.net/00voh0j35590/5ozBwF1gRPwD9UzE1xDqut/080a8fc354927ce0725af01feabdfbd9/CockroachDB_A2A_open_standard_Social_Diagram1.png\",\"width\":1922,\"height\":590}]},\"entries\":{\"__typename\":\"TemplateBlogBlogDetailEntries\",\"block\":[{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"2B6fRpSfyipKe62MlaqWa1\"},\"internalName\":\"A2A code box 1\",\"component\":\"resources\",\"description\":\"$11f\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentSingleInstance\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"TcD9oEUJ0IzODn76cNSMX\"},\"internalName\":\"A2A code box 2\",\"component\":\"resources\",\"description\":\"$120\",\"collapsible\":false,\"imageCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}},{\"__typename\":\"ComponentCta\",\"sys\":{\"__typename\":\"Sys\",\"id\":\"5ubHv23Co4eNMwSJYxnzcb\"},\"widthBox\":false,\"title\":\"Built for AI-driven scale\",\"description\":\"Unify operational data, vector search, and durable agent state in one resilient, distributed SQL database. Start with $400 in free credits.\\nTrusted by Fortune 50 financial institutions and teams in 40+ countries.\",\"buttonCollection\":{\"__typename\":\"ComponentCtaButtonCollection\",\"items\":[{\"__typename\":\"ComponentButton\",\"internalName\":\"[Blog CTA] Try CockroachDB — AI\",\"label\":\"Try CockroachDB\",\"url\":\"https://cockroachlabs.cloud/signup?referralId=try-crdb-ai\",\"longUrl\":null,\"type\":[\"primaryLight\"],\"size\":[\"sm\"],\"rounded\":[\"full\"],\"customStyle\":null,\"displayName\":null,\"icon\":null,\"file\":null,\"mobileLabelToIcon\":null}]},\"background\":null,\"theme\":\"light\",\"centered\":null,\"addBorder\":false,\"roundedEdges\":null,\"titleSize\":\"display-sm\",\"addButtonSeparator\":null,\"image\":null,\"imageItemCollection\":{\"__typename\":\"AssetCollection\",\"items\":[]}}]}}},\"aiSummary\":{\"__typename\":\"TemplateBlogAiSummary\",\"json\":{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"A2A standardizes how agents communicate, but production multi-agent systems still need a data layer for consistent shared state, durable memory, scoped access, and auditability. CockroachDB provides serializable isolation, resilient distributed state, and database-level access controls for that layer.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Serializable isolation prevents concurrent agents from silently corrupting shared state.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Multi-agent memory needs durable state beyond task messages and vector retrieval.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"},{\"data\":{},\"content\":[{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"Cross-boundary agents require scoped identity and end-to-end observability.\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"list-item\"}],\"nodeType\":\"unordered-list\"},{\"data\":{},\"content\":[{\"data\":{},\"marks\":[],\"value\":\"\",\"nodeType\":\"text\"}],\"nodeType\":\"paragraph\"}],\"nodeType\":\"document\"},\"links\":{\"__typename\":\"TemplateBlogAiSummaryLinks\",\"assets\":{\"__typename\":\"TemplateBlogAiSummaryAssets\",\"block\":[]},\"entries\":{\"__typename\":\"TemplateBlogAiSummaryEntries\",\"block\":[]}}},\"featuredBlog\":null,\"additionalFeatureCollection\":{\"__typename\":\"TemplateBlogAdditionalFeatureCollection\",\"items\":[]},\"tableStyling\":null,\"callOutEyebrow\":null,\"callOutTitle\":null,\"callOutDescription\":null,\"callOutButton\":null,\"isListing\":false,\"faqCollection\":{\"__typename\":\"TemplateBlogFaqCollection\",\"items\":[{\"__typename\":\"FaqItem\",\"title\":\"Why do multi-agent systems need serializable isolation?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Multi-agent systems need serializable isolation when multiple agents can concurrently read and write shared state. Serializable isolation detects conflicting transactions and forces a retry instead of allowing one agent to silently overwrite state another agent relied on.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"Can a workflow engine like Temporal manage shared state between AI agents?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"A workflow engine like Temporal can checkpoint execution and help an agent resume after failure, but it does not replace a governed shared data layer. Cross-agent state still needs consistency, access controls, queryability, and auditability, especially across organizational boundaries.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"Does agent memory need more than a vector database?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"Yes. Vector retrieval can provide semantic memory, but multi-agent systems also need durable operational state, such as completed work, decisions, accessed resources, and state another agent can safely act on. That state needs consistent, queryable storage beyond the agents' context windows.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}},{\"__typename\":\"FaqItem\",\"title\":\"When do multi-agent systems need a shared database?\",\"description\":{\"__typename\":\"FaqItemDescription\",\"json\":{\"nodeType\":\"document\",\"data\":{},\"content\":[{\"nodeType\":\"heading-3\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\",\"marks\":[{\"type\":\"bold\"}],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"A shared database becomes important when independently operated agents write state that other agents or workflows depend on. The key threshold is an organizational boundary plus shared writes, which introduces requirements for consistency, durable state, access control, and auditability.\",\"marks\":[],\"data\":{}}]},{\"nodeType\":\"paragraph\",\"data\":{},\"content\":[{\"nodeType\":\"text\",\"value\":\"\\n\",\"marks\":[],\"data\":{}}]}]}}}]}}]}]]}],[\"$\",\"$L15\",null,{\"darkBg\":false,\"footerData\":\"$121\"}]]}]\n"])</script></body></html><!-- This script is automatically inserted by Netlify for Real User Monitoring (RUM). -->
<script async id="netlify-rum-container" src="/.netlify/scripts/rum" data-netlify-cwv-token="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzaXRlX2lkIjoiZmFiODRjYjItYjA2Yi00YjdjLWFjZGItYTYzYTczMTlhYjQ4IiwiYWNjb3VudF9pZCI6IjViNGY5Y2FkYzZhZWQ2NDFlZDc4NDc3YSIsImRlcGxveV9pZCI6IjZhOTVjMDI3NDc4MzcwMDAwOWY5NmQwYSIsImlzcyI6Im5ldGxpZnkifQ.sdoOgJyrO_TpLm_V3rWBZbPef4yzauvWsRDXT4vDty4"></script>