# Security Basics: Auth, Roles & Network Access — MongoDB Fundamentals: Documents, Queries and Indexes

Source: https://www.geekswithgeeks.com/en/mongodb/mongo-security

> Secure MongoDB with authentication, role-based users, restricted network binding and TLS, and never expose it publicly.

## Never run open

A MongoDB server with no authentication and a public IP will be found and wiped. Enable authentication, bind to private interfaces only (`bindIp`), firewall port 27017 and use TLS between clients and servers.

## Create a least-privilege user

Create a user limited to one database instead of using an admin account in your app.

```javascript
use shop
db.createUser({
  user: "shop_app",
  pwd: passwordPrompt(),
  roles: [{ role: "readWrite", db: "shop" }]
})

// connect with credentials
// mongodb://shop_app@localhost:27017/shop?authSource=shop
```

Store connection strings in environment variables, never in source control. Prefer built-in roles such as `read` and `readWrite` over custom wide-open roles.

Quick check

**Quiz:** Which setting limits MongoDB to private network interfaces?

- [x] bindIp
- [ ] journal
- [ ] oplogSize
- [ ] profile

*Answer:* bindIp. `bindIp` controls which interfaces mongod listens on.
