Mapping S3 and Atlas Sources to a Virtual Namespace
Learners will configure a federated database instance that maps S3 prefixes and Atlas collections to virtual databases and collections.
Mapping S3 and Atlas Sources to a Virtual Namespace is a free MongoDB Academy lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the MongoDB Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Storage Configuration: The Core Concept
In Atlas Data Federation, the storage configuration is a JSON document that defines two things: stores (where the raw data lives — S3 buckets, Atlas clusters) and databases/collections (the virtual namespace that applications query). The mapping between them tells the query engine which store to read when you query a virtual collection.
Defining a Store: S3 Bucket
An S3 store definition names the store, specifies the AWS region and bucket name, and associates it with IAM credentials (via an Atlas cloud provider access role). You can optionally set a delimiter and prefix to scope the store to a particular S3 prefix. A single federated instance can have multiple stores pointing to different buckets or regions.
// S3 store definition in storage config
{
'stores': [{
'name': 's3ArchiveStore',
'provider': 'S3',
'region': 'us-east-1',
'bucket': 'mycompany-analytics-archive',
'delimiter': '/',
'additionalStorageClasses': ['STANDARD_IA', 'GLACIER']
}]
}Defining a Store: Atlas Cluster
An Atlas cluster store connects a federated instance to a live Atlas replica set. You reference it by the cluster name within the same Atlas project. This lets you write pipelines that read from live operational collections in the cluster alongside archived S3 data, enabling hybrid queries without any data duplication.
// Atlas cluster store definition
{
'stores': [{
'name': 'liveClusterStore',
'provider': 'atlas',
'clusterName': 'MyProdCluster',
'projectId': 'proj123abc'
}]
}Mapping Collections to S3 Paths
A virtual collection is mapped to a store and a path pattern. The path is a glob pattern that tells Data Federation which S3 objects belong to this collection. The pattern can include literal path segments or wildcards. The query engine will scan all matching objects when the collection is queried.
// Map virtual collection to S3 path pattern
{
'databases': [{
'name': 'analytics',
'collections': [{
'name': 'events_2024',
'dataSources': [{
'storeName': 's3ArchiveStore',
'path': '/data/events/2024/*'
}]
}]
}]
}Partition Attributes in Paths
Partition attributes encode metadata directly in the S3 path using curly-brace syntax: {year int}/{month int}/{day int}/. When a query filters on year, month, or day, Data Federation prunes — skips — all S3 objects whose path does not match the filter values. This is analogous to Hive partitioning and dramatically reduces bytes scanned.
// Path with partition attributes (Data Federation parses the directory structure)
{
'dataSources': [{
'storeName': 's3ArchiveStore',
'path': '/events/{year int}/{month int}/{day int}/*.json'
}]
}
// Query that uses partition pruning:
db.events.find({ year: 2025, month: 3 })
// Data Federation only reads /events/2025/3/ prefixMapping Multiple Sources to One Collection
A single virtual collection can be mapped to multiple data sources — for example, an S3 archive plus a live Atlas collection. Queries merge results from all sources transparently. This is useful for a 'full history' collection where recent data is in Atlas and older data is archived in S3, yet applications query both through a single namespace.
{
'collections': [{
'name': 'orders',
'dataSources': [
{
'storeName': 'liveClusterStore',
'database': 'mydb',
'collection': 'orders' // live Atlas data
},
{
'storeName': 's3ArchiveStore',
'path': '/orders/archive/*.parquet' // S3 archive
}
]
}]
}Wildcard Collections: Schema-on-Read
You can define a wildcard collection (*) that maps all files in an S3 prefix to dynamically named virtual collections. When you query a collection name that matches the wildcard pattern, Data Federation derives the path from the collection name. This is useful for partitioned data lakes where you have thousands of prefix-based 'tables' and cannot enumerate them all in the config.
// Wildcard: each year-month subdirectory becomes a virtual collection
{
'collections': [{
'name': '*',
'dataSources': [{
'storeName': 's3ArchiveStore',
'path': '/data/{collectionName string}/'
}]
}]
}
// Now query any 'table' by name:
db['orders-2024-01'].find({})
db['events-2025-03'].aggregate([...])Updating the Storage Configuration
You can update the storage configuration at any time through the Atlas UI, the Atlas Admin API, or mongosh. Changes take effect immediately — you do not need to restart the federated instance. This lets you add new S3 paths, remap collections to different stores, or add new Atlas cluster sources without any downtime.
// Update storage config via Admin API
// PATCH /api/atlas/v1.0/groups/{groupId}/dataFederation/{name}
// Body: updated storage config JSON
// Or via mongosh using the Atlas admin command
db.adminCommand({
setQueryableEncryptionBackend: 1,
dataFederationConfig: { /* new config */ }
})Testing Your Mapping
After defining the storage configuration, test it by connecting to the federated instance with mongosh and listing databases and collections. Use show dbs, show collections, and a simple find() to verify the mapping is correct. Check that the correct files are being read by inspecting the first few documents returned.
// Connect to federated instance and test
// mongosh 'mongodb+srv://federated.mongodb.net/'
show dbs // lists virtual databases
use analytics
show collections // lists virtual collections
db.events_2024.findOne()
// Verify the document shape matches your S3 filesIAM Role vs Access Key Auth for S3
Atlas Data Federation accesses S3 via AWS IAM. The recommended approach is to use an IAM role delegated to Atlas's AWS account (Atlas Cloud Provider Access) rather than storing access key/secret pairs. The role is granted read access to the S3 bucket via an IAM policy, and Atlas assumes the role when executing queries. This is more secure than long-lived access keys.
// Minimal S3 IAM policy for Data Federation read access
// {
// 'Version': '2012-10-17',
// 'Statement': [{
// 'Effect': 'Allow',
// 'Action': ['s3:GetObject', 's3:ListBucket'],
// 'Resource': [
// 'arn:aws:s3:::mycompany-analytics-archive',
// 'arn:aws:s3:::mycompany-analytics-archive/*'
// ]
// }]
// }Namespace Aliasing and Multiple Views
You can create multiple virtual collections that point to the same underlying S3 prefix with different path patterns — effectively creating multiple views of the same data. For example, one collection exposes all data, another exposes only the current year's partition, and a third maps only Parquet files while excluding JSON. This lets you control what each application tier sees.
Quick Check
Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.
Lesson Recap
In this lesson you learned: stores define where raw data lives (S3 buckets or Atlas clusters) and virtual databases/collections define the namespace applications query, partition attributes in S3 paths enable pruning that dramatically reduces bytes scanned, and a single virtual collection can merge data from multiple stores simultaneously. Next up we write cross-source aggregation pipelines.
Frequently asked questions
Is the “Mapping S3 and Atlas Sources to a Virtual Namespace” lesson free?
Yes — the full text of “Mapping S3 and Atlas Sources to a Virtual Namespace” is free to read here on the web, and the MongoDB Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the MongoDB Academy course, upgrade to CoddyKit PRO.
What will I learn in “Mapping S3 and Atlas Sources to a Virtual Namespace”?
Learners will configure a federated database instance that maps S3 prefixes and Atlas collections to virtual databases and collections. You practise MongoDB Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start MongoDB Academy?
No prior experience is required. MongoDB Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Mapping S3 and Atlas Sources to a Virtual Namespace” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this MongoDB Academy lesson?
Yes. Every MongoDB Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- What Is Atlas Data Federation?
- Mapping S3 and Atlas Sources to a Virtual Namespace
- Running Cross-Source Aggregation Pipelines
- Partitioning S3 Data for Query Performance