Security Migration
- Last Updated: October 6, 2026
- 1 minute read
- Progress Data Cloud
- Documentation
Security changes are often the hardest part of a migration. Plan them early and test them before cutover. Here are some steps to prepare for security migration:
- Prepare environment profiles—Set up cloud-specific configuration profiles before you move data.
- Update existing configuration—Replace hard-coded hosts, ports, base paths, and API keys with environment-specific values where needed.
- Export configuration and security settings—Capture the current MarkLogic configuration and security assets.
- Export configuration as code—Capture the app server definition, including the host, port, modules database, and request settings. Also capture databases, forests, indexes, transparent data encryption (TDE) settings, privileges, roles, users, external security settings, and scheduled tasks.
- Migrate keystore and certificates—Export and import the keystore, then verify that TLS endpoints still connect after restart.
- Plan for encryption—If you enable encryption at rest, set aside time for the restart, reindexing, and merge activity. Then check that the encrypted database size is within the expected range in the Admin interface.