Lesson 23 / 23
Security Basics: Auth, Roles & Network Access
Secure MongoDB with authentication, role-based users, restricted network binding and TLS, and never expose it publicly.
Never run open
A MongoDB server with no authentication and a public IP will be found and wiped. Enable authentication, bind to private interfaces only (bindIp), firewall port 27017 and use TLS between clients and servers.
Create a least-privilege user
Create a user limited to one database instead of using an admin account in your app.
use shop
db.createUser({
user: "shop_app",
pwd: passwordPrompt(),
roles: [{ role: "readWrite", db: "shop" }]
})
// connect with credentials
// mongodb://shop_app@localhost:27017/shop?authSource=shopStore connection strings in environment variables, never in source control. Prefer built-in roles such as read and readWrite over custom wide-open roles.
Quick check
Quick check: Which setting limits MongoDB to private network interfaces?
- bindIp
- journal
- oplogSize
- profile
Answer
bindIp — `bindIp` controls which interfaces mongod listens on.