<!-- llms-explorer concept facts · https://llms-explorer.com/tree/mongodb-security-architecture/ · pack 2026-09-08 · ~3963 tokens -->

# MongoDB Security Architecture

> ```

Parent: [MongoDB Expert Knowledge](https://llms-explorer.com/tree/mongodb-expert-knowledge/) · 16 facets · 69 facts · page: https://llms-explorer.com/tree/mongodb-security-architecture/

## TLS Requirements

- Atlas enforces TLS 1.2+ by default. For self-managed: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#tls-requirements)

## Network Access Controls

- IP Allowlist: CIDR-based ingress control — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- Private Endpoints (AWS PrivateLink / Azure Private Link / GCP PSC): recommended — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- Security Groups (AWS): alternative to IP allowlist — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- Block public access: enforce private endpoint only — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- net.bindIp: restrict mongod to specific interfaces — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- OS firewall: allow only required ports (27017 for mongod, 27018 for shards, 27019 for config) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)
- VPC security groups / network ACLs — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#network-access-controls)

## Built-in Role Hierarchy

- Principle of Least Privilege: Each application component gets only the minimum roles needed. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#built-in-role-hierarchy)

## Encryption at Rest

- Atlas: Default AES-256 encryption at rest using MongoDB-managed keys. For BYOK (Customer Key Management): — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#encryption-at-rest)

## Encryption in Transit

- All client connections: TLS 1.2+. Internal replication traffic: TLS optional on self-managed (required on Atlas). — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#encryption-in-transit)

## Field-Level Encryption (CSFLE / Queryable Encryption)

- For sensitive fields that must be encrypted even from DBA access: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#field-level-encryption-csfle-queryable-encryption)
  - CSFLE: Deterministic (queryable for equality) or Random (not queryable) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#field-level-encryption-csfle-queryable-encryption)
  - Queryable Encryption (7.0+): Equality + Range queries on encrypted fields — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#field-level-encryption-csfle-queryable-encryption)
- See mongodb-encryption for complete implementation guide. — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#field-level-encryption-csfle-queryable-encryption)

## SIEM Integration

- Route Atlas audit logs to SIEM: — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#siem-integration)
  - AWS Security Hub: Atlas → S3 → AWS Security Hub — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#siem-integration)
  - Splunk: Splunk Universal Forwarder → Atlas log pull API — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#siem-integration)
  - Microsoft Sentinel: MongoDB Atlas Data Connector in Sentinel Content Hub — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#siem-integration)
  - Datadog: MongoDB Atlas Datadog integration — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#siem-integration)

## Secrets Manager Integration

- AWS: Store MONGODB_URI in AWS Secrets Manager; use Lambda environment variable injection — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#secrets-manager-integration)
- Azure: Store in Azure Key Vault; inject via Managed Identity or App Configuration — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#secrets-manager-integration)
- GCP: Store in Secret Manager; inject via Workload Identity — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#secrets-manager-integration)
- HashiCorp Vault: MongoDB dynamic credentials plugin creates time-limited Atlas API keys — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#secrets-manager-integration)

## Atlas

- [ ] Enable MFA on all Atlas users — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Use Service Accounts instead of API Keys for programmatic access — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Configure IP allowlist with minimum required IPs (or private endpoints) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Enable "Block Public Access" (private endpoint only) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Enable encryption at rest (default) or BYOK for compliance — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Enable database auditing (M10+) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Use principle of least privilege for database users — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Enable Atlas Backup Compliance Policy (for regulated workloads) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)
- [ ] Configure Atlas resource policies (org-level guardrails) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#atlas)

## Self-Managed

- [ ] Enable authentication (security.authorization: enabled) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Disable localhost exception after creating first user — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Enable TLS for all connections — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Bind mongod to specific interfaces (net.bindIp) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Disable server-side JavaScript if not needed (security.javascriptEnabled: false) — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Enable audit logging for compliance — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Rotate credentials on schedule — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Apply OS-level firewall rules — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)
- [ ] Run mongod as non-root OS user — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#self-managed)

## Common Security Anti-Patterns

- 0.0.0.0/0 in Atlas IP allowlist: Opens cluster to the internet; never use in production — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)
- atlasAdmin or root role for application users: Applications should never have admin roles; use read/readWrite scoped to their databases — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)
- Storing MongoDB credentials in application code or git: Use secrets manager or environment variables — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)
- Not enabling MFA: Single-factor Atlas UI access is a security gap for admin accounts — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)
- X.509 certificates without a CA: Self-signed certs without a CA make certificate rotation extremely painful — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)
- Not rotating credentials: Leaked credentials remain valid indefinitely without rotation policies — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#common-security-anti-patterns)

## References

- MongoDB Security Architecture — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#references)
- Atlas Security Overview — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#references)
- Atlas Database Auditing — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#references)
- MongoDB Encryption at Rest — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#references)
- OIDC Authentication — [source](https://llms-explorer.com/sources/mdb-context-hub/mongodb-security-architecture/#references)

## Where this helps

- Hardening a new Atlas or self-managed MongoDB deployment before it goes into production, working through the Atlas and self-managed security checklists item by item. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Deciding how to protect specific sensitive fields (PII, financial data) from even database-administrator-level access, choosing between CSFLE and Queryable Encryption. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Wiring MongoDB audit logs into an existing SIEM (Splunk, Sentinel, Security Hub, Datadog) as part of a broader security-monitoring program. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Setting up secrets management for database credentials so they never end up hard-coded in application code or committed to git. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## How to apply this

- Work through the Atlas or self-managed security checklist as a pre-launch gate — MFA, least-privilege roles, IP allowlist or private endpoints, encryption at rest, and audit logging all need explicit configuration, not just defaults. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Route database credentials through a secrets manager (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, or HashiCorp Vault's dynamic-credentials plugin) instead of environment files or hard-coded connection strings. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Scope every application's database user to the minimum roles it actually needs (read/readWrite on specific databases), never atlasAdmin or root, following the principle of least privilege. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Choose CSFLE when a field only needs deterministic equality queries and Queryable Encryption (7.0+) when it needs equality plus range queries, both keeping the field unreadable to database administrators. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Common mistakes

- Leaving 0.0.0.0/0 in the Atlas IP allowlist, which opens the cluster to the entire internet and should never appear in a production configuration. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Granting atlasAdmin or root roles to application database users instead of scoping them to read/readWrite on their specific databases. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Storing MongoDB credentials directly in application code or committing them to git instead of using a secrets manager or injected environment variables. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Using self-signed X.509 certificates without a proper CA, which makes certificate rotation extremely painful down the line. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- Internal replication traffic is TLS-optional on self-managed deployments but required on Atlas, so a self-managed cluster can be quietly running unencrypted intra-cluster traffic even with client-facing TLS enabled. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- The localhost exception (unauthenticated access before the first user is created) must be explicitly disabled after setup, or a self-managed deployment can remain open longer than intended. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Database auditing on Atlas is only available on M10+ dedicated clusters, so shared-tier deployments have no built-in audit-logging option at all. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Field-Level Encryption protects specific fields from DBA-level access, but it's a distinct implementation project on top of baseline TLS and RBAC — standard encryption at rest and in transit does not by itself protect fields from administrator visibility. — [source](https://llms-explorer.com/tree/mongodb-security-architecture/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [MongoDB Security Architecture](https://llms-explorer.com/downloads/sources/mdb-context-hub/mongodb-security-architecture.md)
