Lesson 23 / 23

Security Basics: Auth, Roles & Network Access

Secure MongoDB with authentication, role-based users, restricted network binding and TLS, and never expose it publicly.

Never run open

A MongoDB server with no authentication and a public IP will be found and wiped. Enable authentication, bind to private interfaces only (bindIp), firewall port 27017 and use TLS between clients and servers.

Create a least-privilege user

Create a user limited to one database instead of using an admin account in your app.

use shop
db.createUser({
  user: "shop_app",
  pwd: passwordPrompt(),
  roles: [{ role: "readWrite", db: "shop" }]
})

// connect with credentials
// mongodb://shop_app@localhost:27017/shop?authSource=shop

Store connection strings in environment variables, never in source control. Prefer built-in roles such as read and readWrite over custom wide-open roles.

Quick check

Quick check: Which setting limits MongoDB to private network interfaces?

  • bindIp
  • journal
  • oplogSize
  • profile
Answer

bindIp — `bindIp` controls which interfaces mongod listens on.