Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen
Lernende weisen integrierte Rollen wie readWrite und dbAdmin zu und erstellen benutzerdefinierte Rollen mit Aktionssets nach dem Prinzip der geringsten Berechtigungen für Servicekonten.
Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen ist eine kostenlose MongoDB Academy-Lektion auf CoddyKit. Dies ist Lektion 2 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des MongoDB Academy-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der MongoDB Academy-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
What Is Role-Based Access Control?
Role-Based Access Control (RBAC) is MongoDB's authorization model. Instead of granting individual permissions directly to users, you assign roles — named collections of privileges — to users. This makes permission management scalable: update a role and every user holding that role inherits the change automatically. MongoDB ships with a rich set of built-in roles covering the most common access patterns.
Built-In Database Roles
MongoDB provides several database-level roles that apply to a specific database. The most commonly used are: read (read all collections), readWrite (read + insert/update/delete), dbAdmin (schema management, index creation), and userAdmin (create/modify users in that database). These roles are database-scoped — a user with readWrite on myApp cannot access otherApp.
// Create a user with readWrite on one database only
use myApp
db.createUser({
user: 'appUser',
pwd: 'SecurePass!',
roles: [
{ role: 'readWrite', db: 'myApp' }
]
})
// Create a user with dbAdmin (can manage indexes but not data)
db.createUser({
user: 'dbaUser',
pwd: 'DbaPass!',
roles: [
{ role: 'dbAdmin', db: 'myApp' }
]
})Built-In Cluster-Wide Roles
Some built-in roles span all databases on a MongoDB instance. readAnyDatabase and readWriteAnyDatabase grant their respective permissions across every database. dbAdminAnyDatabase allows schema management everywhere. The most powerful is root, which has full access to everything — use it only for initial setup and emergency recovery, never for application accounts.
// Grant read-only access to all databases (reporting tool)
use admin
db.createUser({
user: 'globalReporter',
pwd: 'ReportPass!',
roles: [
{ role: 'readAnyDatabase', db: 'admin' }
]
})
// The root role — avoid for applications
// roles: [{ role: 'root', db: 'admin' }] // too powerful!The Principle of Least Privilege
Every MongoDB user should have exactly the permissions they need — no more. An API that only reads products should have read, not readWrite. A background job that archives documents should only be able to query and delete from the archive collection — not from all collections. Applying least privilege limits the blast radius of a compromised credential.
// Tightly scoped user for a product listing API
use admin
db.createUser({
user: 'productListingApi',
pwd: 'ProductApiPass!',
roles: [
{ role: 'read', db: 'catalog' } // read-only on catalog DB only
]
})Creating Custom Roles
When built-in roles are too broad, create a custom role using db.createRole(). A role definition lists specific privileges — each privilege is an action (e.g., find, insert, createIndex) on a resource (a specific database, collection, or cluster). Custom roles can also inherit from existing roles using the roles array.
// Custom role: can read orders and update order status only
use myApp
db.createRole({
role: 'orderProcessor',
privileges: [
{
resource: { db: 'myApp', collection: 'orders' },
actions: ['find', 'update']
}
],
roles: [] // no inherited roles
})Assigning Custom Roles to Users
Assign a custom role the same way you assign built-in roles — include it in the roles array when creating a user or grant it later with db.grantRolesToUser(). A user can hold multiple roles simultaneously, combining their permissions. MongoDB computes the union of all privileges from all assigned roles when authorizing each operation.
// Create user and assign custom role
use myApp
db.createUser({
user: 'fulfillmentWorker',
pwd: 'FulfillPass!',
roles: [
{ role: 'orderProcessor', db: 'myApp' }
]
})
// Grant an additional role to an existing user
db.grantRolesToUser('fulfillmentWorker', [
{ role: 'read', db: 'products' }
])Revoking Roles and Modifying Access
When an employee changes roles or a service is decommissioned, revoke unnecessary permissions promptly. db.revokeRolesFromUser() removes specific roles from a user without deleting the account. db.updateUser() lets you replace the entire roles array. Regularly audit users and their assigned roles with db.getUsers() to catch privilege creep.
// Revoke a specific role from a user
use myApp
db.revokeRolesFromUser('fulfillmentWorker', [
{ role: 'read', db: 'products' }
])
// Replace all roles for a user
db.updateUser('fulfillmentWorker', {
roles: [{ role: 'read', db: 'myApp' }] // demote to read-only
})Collection-Level Privilege Granularity
Custom roles can be scoped to a specific collection rather than an entire database. This allows fine-grained access control where, for example, a service can only read the products collection but has no access to users or orders in the same database. Collection-level scoping is achieved by specifying a collection name in the resource document.
// Role scoped to a single collection
use myApp
db.createRole({
role: 'catalogReader',
privileges: [
{
resource: { db: 'myApp', collection: 'products' },
actions: ['find']
}
],
roles: []
})Cluster Administration Roles
Several built-in roles govern cluster-level operations rather than data access. clusterMonitor grants read access to monitoring commands (useful for metrics exporters). clusterAdmin allows managing shards, replica sets, and global operations — very powerful, restrict carefully. backup and restore roles grant the specific permissions needed for mongodump and mongorestore without full admin rights.
// Backup user — can dump data but not administer users
use admin
db.createUser({
user: 'backupAgent',
pwd: 'BackupPass!',
roles: [
{ role: 'backup', db: 'admin' }
]
})
// Monitoring exporter user
db.createUser({
user: 'prometheusExporter',
pwd: 'MonitorPass!',
roles: [
{ role: 'clusterMonitor', db: 'admin' },
{ role: 'read', db: 'local' }
]
})Viewing Role Details and Inherited Privileges
Use db.getRole(roleName, { showPrivileges: true }) to see exactly which actions and resources a role grants, including inherited privileges from parent roles. This is essential for auditing — you can confirm that a custom role provides exactly the right permissions without accidentally granting broader access through inherited roles.
// Inspect a custom role's full privileges
use myApp
db.getRole('orderProcessor', { showPrivileges: true })
// List all custom roles in the current database
db.getRoles({ showBuiltinRoles: false })
// List all users and their roles
db.getUsers()RBAC in MongoDB Atlas
MongoDB Atlas implements RBAC through its Database Access panel. You can create database users with built-in or custom roles via the Atlas UI, Atlas CLI, or Atlas API. Atlas also supports temporary users that expire automatically after a set time — ideal for short-lived developer access or incident response. Additionally, Atlas can integrate with AWS IAM and LDAP for enterprise identity management.
Quick Check
Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.
Lesson Recap
In this lesson you learned: built-in roles like read, readWrite, and dbAdmin cover common access patterns at database scope, custom roles let you define collection-level privileges with only the exact actions required, and principle of least privilege — each user and service account should hold only the permissions it genuinely needs. Next up we cover encryption at rest and TLS in transit.
Häufig gestellte Fragen
Ist die Lektion „Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen“ kostenlos?
Ja — der vollständige Text von „Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des MongoDB Academy-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der MongoDB Academy-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen“?
Lernende weisen integrierte Rollen wie readWrite und dbAdmin zu und erstellen benutzerdefinierte Rollen mit Aktionssets nach dem Prinzip der geringsten Berechtigungen für Servicekonten. Du übst MongoDB Academy mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um MongoDB Academy zu starten?
Keine Vorkenntnisse erforderlich. MongoDB Academy auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 2 von 4.
Wie lange dauert die Lektion „Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser MongoDB Academy-Lektion Code schreiben und ausführen?
Ja. Jede MongoDB Academy-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Authentifizierungsmechanismen: SCRAM und x.509
- Rollenbasierte Zugriffskontrolle: Integrierte und benutzerdefinierte Rollen
- Verschlüsselung im Ruhezustand und TLS bei der Übertragung
- Verschlüsselung auf Feldebene auf der Clientseite