Skip to main content
See All Integrations

MongoDB

Protect access to MongoDB services through Pomerium TCP routes.

Standard protected service pattern

Categories
Databases, Non-HTTP Services

Overview

MongoDB is a document database that uses its own wire protocol over TCP, normally on port 27017. Client discovery in replica sets and sharded clusters can return several advertised hosts.

MongoDB can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to MongoDB. MongoDB remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.

Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.

Use a direct or single-endpoint connection only when it matches the MongoDB topology. For a cluster, design and test a route for every required advertised endpoint.

Example

A developer starts a local Pomerium tunnel for a private standalone MongoDB endpoint and points the MongoDB client to the loopback port. MongoDB keeps database authentication and role permissions.

Considerations

  • Replica-set and sharded-cluster clients discover several advertised endpoints. One local tunnel does not cover that topology.
  • Preserve MongoDB TLS and database authentication. Test the exact client discovery mode before deployment.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to PostgreSQL services through Pomerium TCP routes.

  • Protect access to MySQL services through Pomerium TCP routes.

  • Connect DBeaver to protected database services through Pomerium TCP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo