Memory hook: Database permission and API permission both matter.
Must remember
- Data API builder (DAB) maps supported database objects to REST/GraphQL endpoints through configuration. Define entities, relationships, authentication and role permissions deliberately.
- Pagination, filtering, searching and caching affect API correctness and performance. Avoid exposing unrestricted tables or overly broad stored procedures merely because endpoint generation is easy.
- Deploy DAB with protected configuration, network access and managed identity where supported. Correlate application telemetry with database metrics using Application Insights, Log Analytics and Azure Monitor.
- Change Data Capture records supported change details; Change Tracking identifies changed rows with lighter semantics; change event streaming emits supported events. Choose by required history, payload and downstream processing.
- Azure Functions SQL triggers and Logic Apps can react to supported changes. Design idempotent consumers, checkpoints, retries and dead-letter/recovery behavior.
- Treat schema changes as API contract changes. Coordinate clients, functions, models and retrieval indexes when fields or event shapes evolve.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Need GraphQL over selected relational entities | DAB with explicit relationships and scoped permissions. |
| Need to know which rows changed without full historical values | Evaluate Change Tracking rather than assuming CDC is required. |
Traps
- An API gateway does not automatically enforce every database row-level rule correctly.
- An event arriving twice must not create two business transactions.
Active recall
1. What does a DAB entity represent?
A configured database object exposed with specified API behavior and permissions.
2. How does CDC differ from Change Tracking?
CDC captures richer change information; Change Tracking focuses on identifying changed rows.
3. Why bound API pagination?
To prevent expensive unbounded reads and large responses.
4. What should a change consumer persist?
A safe processing checkpoint and any deduplication state required by the workflow.
5. Why version API contracts?
Database evolution can otherwise break consumers silently.