
MongoDB
Protect access to MongoDB services through Pomerium TCP routes.
Overview
MongoDB is a document database that uses its own wire protocol over TCP, normally on port 27017. Client discovery in replica sets and sharded clusters can return several advertised hosts.
MongoDB can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to MongoDB. MongoDB remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.
Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.
Use a direct or single-endpoint connection only when it matches the MongoDB topology. For a cluster, design and test a route for every required advertised endpoint.
Example
A developer starts a local Pomerium tunnel for a private standalone MongoDB endpoint and points the MongoDB client to the loopback port. MongoDB keeps database authentication and role permissions.
Considerations
- Replica-set and sharded-cluster clients discover several advertised endpoints. One local tunnel does not cover that topology.
- Preserve MongoDB TLS and database authentication. Test the exact client discovery mode before deployment.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
