Elias.Lundmark
Mar 21, 2024
visibility 3406
star star star star star star
(2 votes)

Keeping local environments in sync with your Cloud environments

We recently announced that we are improving the scalability of SQL databases in DXP Cloud Services, this new architecture also enhances our overall security for SQL databases where we are aiming to harden technical controls to maintain confidentiality and integrity of our customers data. This change had an unintended consequence though – it disallows developers from connecting local development environments directly to SQL databases in DXP Cloud Services. We strongly advise against this practice, while the ease of use and flexibility is great, manually managing and storing connection strings and credentials for service users greatly increases the risk of these credentials falling into the wrong hands, allowing potential attackers to access or modify data.

To avoid these risks, our new architecture disallows direct connections from third-party sources to SQL Servers running in DXP Cloud Services. Instead, you should use the paasportal or the API to export your databases and content to use in your local development environments, which are more secure and reliable methods.

How to export content

Via the paasportal

  1. Navigate to https://paasportal.episerver.net and select the project you wish to export a database from
  2. Navigate to the Troubleshoot tab
  3. In the ‘Export Database’ section, select the environment you wish to export the database from, and how long the paasportal should retain this copy.
  4. Once the export is done, click the database file to download it as .bacpac. These files can then be used to import your database to a local SQL server, or an Azure SQL Server.

Via API with Powershell

  1. Navigate to https://paasportal.episerver.net and generate credentials as described here https://docs.developers.optimizely.com/digital-experience-platform/docs/authentication.
  2. Authenticate woth Connect-EpiCloud, Connect-EpiCloud -ClientKey <ClientKey> -ClientSecret <ClientSecret> -ProjectId <ProjectId>
  3. Start a database export with Start-EpiDatabaseExport, for example Start-EpiDatabaseExport -Environment Integration -DatabaseName epicms -Wait
  4. Fetch the download link for the .bacpac with Get-EpiDatabaseExport

Via the API you can also download BLOBs from the storage account, where Get-EpiStorageContainer allows you to list all storage containers and GetEpiStorageContainerSasLink creates a SAS URI that can be used to download BLOBs. For example,

 Get-EpiStorageContainerSasLink -ProjectId "2372b396-6fd2-40ca-a955-57871fc497c9" `

  -Environment "Integration" `

  -StorageContainer "mysitemedia" `

  -RetentionHours 2

Mar 21, 2024

Comments

Drew Douglas
Drew Douglas Mar 21, 2024 07:55 PM

This change to the accessibility of the SQL instances in the Integration environment is disappointing. Prior to us joining the project Opti Expert Services set up one of our customers with a development model that strongly prefers connecting to the Integration databse when running the solution locally. We've run successfully with local databases, but this change to DXP will require us to change messaging and other systems to keep local databases in sync with backend systems.

Eric
Eric Apr 3, 2024 09:48 PM

Never thought you should connect to DXP db:s at any point at all actually. Using client data should not be needed for development purpose. BUT if you use this and download a database a Disclaimer could be handy that if you download a client db you most likely will be deeling with PI data and therefore might be distributing information as a developer that your company most likely do not like you todo in case of a breach..

it’s crucial to stay informed and understand the ins and outs of personal data before downloading a client database is at least my opinion and if so have scripts ready to remove that information or have a Data Processing Agreement in place.. :) 

error Please login to comment.
Latest blogs
Upgrade Optimizely CMS 12 to .NET 10

If you are still running CMS 12 on .NET 8, it's time to upgrade!

Tomas Hensrud Gulla | Aug 17, 2026 |

What Your Optimizely DXP Is Serving to AI Crawlers - and the Three Levers You Actually Have

Unblocked bot traffic on Optimizely DXP is a billable page view, and the Cloudflare zone in front of your site is not yours to configure. Three...

Piotr | Aug 17, 2026 |

Migrating from AEM to Optimizely SaaS CMS: Solving the Architectural Hurdles

Migrating a digital footprint from Adobe Experience Manager (AEM) to Optimizely SaaS CMS is a major milestone for any enterprise modernizing its...

Vipin Banka | Aug 16, 2026

You’re not headless. You’re hybrid — and that’s the CMS 12 default.

For CMS 12 / Commerce teams with a React (or similar) storefront who keep hearing “just go headless” or “just move to Graph.” This is Part 1 of Fin...

Hanskumar Tripathi | Aug 13, 2026

Stott Security for Optimizely SaaS CMS

Introduction Stott Security  has been helping developers and editors manage Content Security Policies and security headers on  Optimizely PaaS CMS...

Mark Stott | Aug 13, 2026

Optimizely XML Resource Builder: A Visual Studio Extension for Language Resource Files

Anyone who has worked on a larger Optimizely solution will know the feeling. You add or update a page type, block type, or shared base class,

Adnan Zameer | Aug 13, 2026 |