Encrypt the data at rest

  • which versions are you using (SonarQube, Scanner, Plugin, and any relevant extension)
    Sonarqube 7.6
  • what are you trying to achieve: Stig sonqrqube application server
  • what have you tried so far to achieve this

Does sonarqube encrypt the data at rest? To be specific, is the database encrypted?

Hello - thanks for posting. I’m not sure if you’re referring to the embedded H2 database that comes with SonarQube or the database you installed as part of the SonarQube setup?

Note that the H2 database is provided solely for initial testing . It is neither intended nor supported for production use. You will not be able to upgrade with this database.

For production use, SQ supports 3 database options: Microsoft SQL Server, Oracle and PostgreSQL. You can get the details here. Regardless of your choice, you supply the production database and look after its care and feeding. :grinning: Whether you choose to encrypt the data is up to you.



FYI, from SonarQube 8.5 you’ll find new releases in the Iron Bank.