# Security Basics: Auth, Roles और Network Access — MongoDB Fundamentals: Documents, Queries और Indexes

Source: https://www.geekswithgeeks.com/hi/mongodb/mongo-security

> Authentication, role-based users, सीमित network binding और TLS से MongoDB सुरक्षित करें, और उसे कभी सार्वजनिक रूप से expose न करें।

## कभी खुला न चलाएँ

बिना authentication और public IP वाला MongoDB server खोज लिया जाएगा और मिटा दिया जाएगा। Authentication चालू करें, केवल private interfaces पर bind करें (`bindIp`), port 27017 पर firewall लगाएँ और clients व servers के बीच TLS उपयोग करें।

## Least-privilege user बनाएँ

अपने app में admin account के बजाय एक database तक सीमित user बनाएँ।

```javascript
use shop
db.createUser({
  user: "shop_app",
  pwd: passwordPrompt(),
  roles: [{ role: "readWrite", db: "shop" }]
})

// connect with credentials
// mongodb://shop_app@localhost:27017/shop?authSource=shop
```

Connection strings को environment variables में रखें, source control में कभी नहीं। बहुत खुले custom roles के बजाय `read` और `readWrite` जैसे built-in roles चुनें।

त्वरित जाँच

**Quiz:** कौन-सी setting MongoDB को private network interfaces तक सीमित करती है?

- [x] bindIp
- [ ] journal
- [ ] oplogSize
- [ ] profile

*Answer:* bindIp. `bindIp` तय करता है कि mongod किन interfaces पर सुनता है।
