That makes sense, but what about auditing (in isolation) the read-only replicas?
I suppose I could implement my own hash-chain to verify the authenticity? (aka, no missing data)
I suppose I could implement my own hash-chain to verify the authenticity? (aka, no missing data)
In my country, all invoicing software must implement that (it's part of the SAF-T format that we must deliver to the IRS), and it took us less than ten lines of Ruby to do it. It's literally concatenating a few strings, then using some crypto library to hash and sign it.
Verification is just doing the same process, then checking if the signed hashes match.