0Pricing
MongoDB Academy · 강의

역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할

학습자는 readWrite 및 dbAdmin과 같은 기본 제공 역할을 할당하고, 서비스 계정에 최소 권한 작업 집합을 적용하는 사용자 지정 역할을 생성합니다.

역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할은(는) CoddyKit의 무료 MongoDB Academy 강의입니다. 이것은 4개 중 2번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 MongoDB Academy 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. MongoDB Academy 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

What Is Role-Based Access Control?

Role-Based Access Control (RBAC) is MongoDB's authorization model. Instead of granting individual permissions directly to users, you assign roles — named collections of privileges — to users. This makes permission management scalable: update a role and every user holding that role inherits the change automatically. MongoDB ships with a rich set of built-in roles covering the most common access patterns.

Built-In Database Roles

MongoDB provides several database-level roles that apply to a specific database. The most commonly used are: read (read all collections), readWrite (read + insert/update/delete), dbAdmin (schema management, index creation), and userAdmin (create/modify users in that database). These roles are database-scoped — a user with readWrite on myApp cannot access otherApp.

// Create a user with readWrite on one database only
use myApp
db.createUser({
  user: 'appUser',
  pwd: 'SecurePass!',
  roles: [
    { role: 'readWrite', db: 'myApp' }
  ]
})

// Create a user with dbAdmin (can manage indexes but not data)
db.createUser({
  user: 'dbaUser',
  pwd: 'DbaPass!',
  roles: [
    { role: 'dbAdmin', db: 'myApp' }
  ]
})

Built-In Cluster-Wide Roles

Some built-in roles span all databases on a MongoDB instance. readAnyDatabase and readWriteAnyDatabase grant their respective permissions across every database. dbAdminAnyDatabase allows schema management everywhere. The most powerful is root, which has full access to everything — use it only for initial setup and emergency recovery, never for application accounts.

// Grant read-only access to all databases (reporting tool)
use admin
db.createUser({
  user: 'globalReporter',
  pwd: 'ReportPass!',
  roles: [
    { role: 'readAnyDatabase', db: 'admin' }
  ]
})

// The root role — avoid for applications
// roles: [{ role: 'root', db: 'admin' }]  // too powerful!

The Principle of Least Privilege

Every MongoDB user should have exactly the permissions they need — no more. An API that only reads products should have read, not readWrite. A background job that archives documents should only be able to query and delete from the archive collection — not from all collections. Applying least privilege limits the blast radius of a compromised credential.

// Tightly scoped user for a product listing API
use admin
db.createUser({
  user: 'productListingApi',
  pwd: 'ProductApiPass!',
  roles: [
    { role: 'read', db: 'catalog' }  // read-only on catalog DB only
  ]
})

Creating Custom Roles

When built-in roles are too broad, create a custom role using db.createRole(). A role definition lists specific privileges — each privilege is an action (e.g., find, insert, createIndex) on a resource (a specific database, collection, or cluster). Custom roles can also inherit from existing roles using the roles array.

// Custom role: can read orders and update order status only
use myApp
db.createRole({
  role: 'orderProcessor',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'orders' },
      actions: ['find', 'update']
    }
  ],
  roles: []  // no inherited roles
})

Assigning Custom Roles to Users

Assign a custom role the same way you assign built-in roles — include it in the roles array when creating a user or grant it later with db.grantRolesToUser(). A user can hold multiple roles simultaneously, combining their permissions. MongoDB computes the union of all privileges from all assigned roles when authorizing each operation.

// Create user and assign custom role
use myApp
db.createUser({
  user: 'fulfillmentWorker',
  pwd: 'FulfillPass!',
  roles: [
    { role: 'orderProcessor', db: 'myApp' }
  ]
})

// Grant an additional role to an existing user
db.grantRolesToUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

Revoking Roles and Modifying Access

When an employee changes roles or a service is decommissioned, revoke unnecessary permissions promptly. db.revokeRolesFromUser() removes specific roles from a user without deleting the account. db.updateUser() lets you replace the entire roles array. Regularly audit users and their assigned roles with db.getUsers() to catch privilege creep.

// Revoke a specific role from a user
use myApp
db.revokeRolesFromUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

// Replace all roles for a user
db.updateUser('fulfillmentWorker', {
  roles: [{ role: 'read', db: 'myApp' }]  // demote to read-only
})

Collection-Level Privilege Granularity

Custom roles can be scoped to a specific collection rather than an entire database. This allows fine-grained access control where, for example, a service can only read the products collection but has no access to users or orders in the same database. Collection-level scoping is achieved by specifying a collection name in the resource document.

// Role scoped to a single collection
use myApp
db.createRole({
  role: 'catalogReader',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'products' },
      actions: ['find']
    }
  ],
  roles: []
})

Cluster Administration Roles

Several built-in roles govern cluster-level operations rather than data access. clusterMonitor grants read access to monitoring commands (useful for metrics exporters). clusterAdmin allows managing shards, replica sets, and global operations — very powerful, restrict carefully. backup and restore roles grant the specific permissions needed for mongodump and mongorestore without full admin rights.

// Backup user — can dump data but not administer users
use admin
db.createUser({
  user: 'backupAgent',
  pwd: 'BackupPass!',
  roles: [
    { role: 'backup', db: 'admin' }
  ]
})

// Monitoring exporter user
db.createUser({
  user: 'prometheusExporter',
  pwd: 'MonitorPass!',
  roles: [
    { role: 'clusterMonitor', db: 'admin' },
    { role: 'read', db: 'local' }
  ]
})

Viewing Role Details and Inherited Privileges

Use db.getRole(roleName, { showPrivileges: true }) to see exactly which actions and resources a role grants, including inherited privileges from parent roles. This is essential for auditing — you can confirm that a custom role provides exactly the right permissions without accidentally granting broader access through inherited roles.

// Inspect a custom role's full privileges
use myApp
db.getRole('orderProcessor', { showPrivileges: true })

// List all custom roles in the current database
db.getRoles({ showBuiltinRoles: false })

// List all users and their roles
db.getUsers()

RBAC in MongoDB Atlas

MongoDB Atlas implements RBAC through its Database Access panel. You can create database users with built-in or custom roles via the Atlas UI, Atlas CLI, or Atlas API. Atlas also supports temporary users that expire automatically after a set time — ideal for short-lived developer access or incident response. Additionally, Atlas can integrate with AWS IAM and LDAP for enterprise identity management.

Quick Check

Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.

Lesson Recap

In this lesson you learned: built-in roles like read, readWrite, and dbAdmin cover common access patterns at database scope, custom roles let you define collection-level privileges with only the exact actions required, and principle of least privilege — each user and service account should hold only the permissions it genuinely needs. Next up we cover encryption at rest and TLS in transit.

자주 묻는 질문

“역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할” 강의는 무료인가요?

네 — “역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 MongoDB Academy 강의 전체를 잠금 해제할 수 있습니다. MongoDB Academy 강의에는 총 4개의 강의가 포함되어 있습니다.

“역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할”에서 뭘 배우나요?

학습자는 readWrite 및 dbAdmin과 같은 기본 제공 역할을 할당하고, 서비스 계정에 최소 권한 작업 집합을 적용하는 사용자 지정 역할을 생성합니다. 브라우저에서 직접 실행하는 실습 코드로 MongoDB Academy을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

MongoDB Academy을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 MongoDB Academy은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 2번째 강의입니다.

“역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 MongoDB Academy 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 MongoDB Academy 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. 인증 메커니즘: SCRAM 및 x.509
  2. 역할 기반 액세스 제어: 기본 제공 역할 및 사용자 지정 역할
  3. 저장 데이터 암호화 및 전송 중 TLS
  4. 클라이언트 측 필드 수준 암호화
← MongoDB Academy(으)로 돌아가기