Skip to main content

Infrastructure

How DOSE is deployed​

DOSE runs two services on Azure Kubernetes Service (AKS), backed by Azure Blob Storage, Azure Event Hub, MongoDB Atlas, and an external Kafka cluster:

Both services use Managed Identity for all Azure service access — no long-lived credentials in configuration files.

Shared libraries​

Three libraries are shared across DOSE services. Any service that adds the dependency gets the capability automatically:

LibraryWhat it provides
RxDose-MongoRepo-libReactive database access — job and record entities, services, and audit log
RxDose-Validator-libJSON Schema validation of DOSE record payloads
RxDose-KafkaUtil-libKafka producer and consumer configuration, CloudEvent publishing, mTLS setup

Database migrations​

All database changes — new collections, indexes, TTL rules — are managed as versioned migrations in RxDose-Mongo-Script. This is a hard rule: no index or schema change is ever made directly in a service or library.

Migrations are organized by release:

migrations/
2026/sep/r/1/ ← release migrations
2026/sep/r/1/h/1/ ← hotfix migrations

The migration pipeline runs automatically via GitHub Actions.

Security model​

WhatHow
Client file uploadClient uploads directly to blob using a 30-minute SAS URL — File Manager never handles raw file bytes
Service-to-AzureManaged Identity (MSI) — no secrets in config
MongoDBConnection strings stored in Azure Key Vault, injected at startup
Kafka (mTLS)JKS keystore and truststore injected as environment variables — never committed to source
RxClaim CAT APIOAuth2 Client Credentials + JWT Bearer; token cached in memory

CI/CD​

GitHub Actions manages both the service deployment pipeline and the database migration pipeline. Deployments target Azure Kubernetes Service.