Infrastructure
How DOSE is deployed
DOSE runs two services on Azure Kubernetes Service (AKS), backed by Azure Blob Storage, Azure Event Hub, MongoDB Atlas, and an external Kafka cluster:
Both services use Managed Identity for all Azure service access — no long-lived credentials in configuration files.
Shared libraries
Three libraries are shared across DOSE services. Any service that adds the dependency gets the capability automatically:
| Library | What it provides |
|---|---|
RxDose-MongoRepo-lib | Reactive database access — job and record entities, services, and audit log |
RxDose-Validator-lib | JSON Schema validation of DOSE record payloads |
RxDose-KafkaUtil-lib | Kafka producer and consumer configuration, CloudEvent publishing, mTLS setup |
Database migrations
All database changes — new collections, indexes, TTL rules — are managed as versioned migrations in RxDose-Mongo-Script. This is a hard rule: no index or schema change is ever made directly in a service or library.
Migrations are organized by release:
migrations/
2026/sep/r/1/ ← release migrations
2026/sep/r/1/h/1/ ← hotfix migrations
The migration pipeline runs automatically via GitHub Actions.
Security model
| What | How |
|---|---|
| Client file upload | Client uploads directly to blob using a 30-minute SAS URL — File Manager never handles raw file bytes |
| Service-to-Azure | Managed Identity (MSI) — no secrets in config |
| MongoDB | Connection strings stored in Azure Key Vault, injected at startup |
| Kafka (mTLS) | JKS keystore and truststore injected as environment variables — never committed to source |
| RxClaim CAT API | OAuth2 Client Credentials + JWT Bearer; token cached in memory |
CI/CD
GitHub Actions manages both the service deployment pipeline and the database migration pipeline. Deployments target Azure Kubernetes Service.