MongoDB User Management
User management in MongoDB involves operations such as creating users, assigning roles, authentication, and login.
Below is a detailed explanation, including how to manage users using MongoDB Shell (mongo) or MongoDB Compass.
Managing Users with MongoDB Shell (mongo)
The following is a detailed explanation of user management using MongoDB Shell (mongosh), including the specific steps for creating users, assigning roles, authentication, and login.
1. Connect to MongoDB
First, open your terminal and use the mongosh command to connect to the MongoDB server:
mongosh --host <hostname> --port <port>
Explanation:
mongosh: Launches the MongoDB Shell command-line tool.--host <hostname>: Specifies the hostname or IP address of the MongoDB server.<hostname>: Hostname of the MongoDB server (e.g.,localhost) or IP address (e.g.,127.0.0.1)。
--port <port>: Specifies the port number of the MongoDB server.<port>: The port number on which the MongoDB server listens, default port is27017。
2. Switch to the Target Database
In MongoDB, users are created for a specific database. Use theusecommand to switch to the database where you want to create the user:
use <database_name>
- database_name- is the database to switch to.
3. Create a User
Use the db.createUser command to create a user and assign roles.
For example, to create a user named testuser with password password123 and grant the readWrite and dbAdmin roles:
db.createUser({
user: "testuser",
pwd: "password123",
roles: [
{ role: "readWrite", db: "<database_name>" },
{ role: "dbAdmin", db: "<database_name>" }
]
})4. Verify the User
After creating the user, you can use the db.auth command to verify the user's identity:
db.auth("testuser", "password123")5. Enable Authentication
To ensure only authenticated users can access MongoDB, you need to enable authentication.
Edit the MongoDB configuration file mongod.conf and add the following content:
security: authorization: "enabled"
Then restart the MongoDB service to apply the changes.
6. Log in as a User
After enabling authentication, you need to connect to MongoDB using the created user's credentials:
mongosh --host <hostname> --port <port> -u "testuser" -p "password123" --authenticationDatabase "<database_name>"
7. Delete a User
Use thedb.dropUsercommand to delete the specified user.
For example, to delete the user named testuser:
db.dropUser("testuser")
Example Operations
The following is a complete example workflow:
Start the MongoDB Shell and connect to the server:
mongosh --host localhost --port 27017
Switch to the testdb database:
use testdb
Create the testuser user:
db.createUser({
user: "testuser",
pwd: "password123",
roles: [{ role: "readWrite", db: "testdb" }]
})Enable authentication and restart the MongoDB instance
Edit the mongod.conf file and add the following content:
security: authorization: "enabled"
Restart the MongoDB service:
sudo systemctl restart mongod
Connect with authentication using the testuser user:
mongosh --host localhost --port 27017 -u "testuser" -p "password123" --authenticationDatabase "testdb"
Delete the testuser user:
db.dropUser("testuser") Other Extensions