0Pricing
MongoDB Academy · Aula

Controle de acesso baseado em funções: funções integradas e personalizadas

Os alunos atribuirão funções integradas, como readWrite e dbAdmin, e criarão funções personalizadas com conjuntos de ações de privilégio mínimo para contas de serviço.

Controle de acesso baseado em funções: funções integradas e personalizadas é uma aula grátis de MongoDB Academy no CoddyKit. Esta é a aula 2 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de MongoDB Academy, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de MongoDB Academy inclui 4 aulas no total.

Partes desta aula ainda não foram traduzidas e aparecem em inglês.

What Is Role-Based Access Control?

Role-Based Access Control (RBAC) is MongoDB's authorization model. Instead of granting individual permissions directly to users, you assign roles — named collections of privileges — to users. This makes permission management scalable: update a role and every user holding that role inherits the change automatically. MongoDB ships with a rich set of built-in roles covering the most common access patterns.

Built-In Database Roles

MongoDB provides several database-level roles that apply to a specific database. The most commonly used are: read (read all collections), readWrite (read + insert/update/delete), dbAdmin (schema management, index creation), and userAdmin (create/modify users in that database). These roles are database-scoped — a user with readWrite on myApp cannot access otherApp.

// Create a user with readWrite on one database only
use myApp
db.createUser({
  user: 'appUser',
  pwd: 'SecurePass!',
  roles: [
    { role: 'readWrite', db: 'myApp' }
  ]
})

// Create a user with dbAdmin (can manage indexes but not data)
db.createUser({
  user: 'dbaUser',
  pwd: 'DbaPass!',
  roles: [
    { role: 'dbAdmin', db: 'myApp' }
  ]
})

Built-In Cluster-Wide Roles

Some built-in roles span all databases on a MongoDB instance. readAnyDatabase and readWriteAnyDatabase grant their respective permissions across every database. dbAdminAnyDatabase allows schema management everywhere. The most powerful is root, which has full access to everything — use it only for initial setup and emergency recovery, never for application accounts.

// Grant read-only access to all databases (reporting tool)
use admin
db.createUser({
  user: 'globalReporter',
  pwd: 'ReportPass!',
  roles: [
    { role: 'readAnyDatabase', db: 'admin' }
  ]
})

// The root role — avoid for applications
// roles: [{ role: 'root', db: 'admin' }]  // too powerful!

The Principle of Least Privilege

Every MongoDB user should have exactly the permissions they need — no more. An API that only reads products should have read, not readWrite. A background job that archives documents should only be able to query and delete from the archive collection — not from all collections. Applying least privilege limits the blast radius of a compromised credential.

// Tightly scoped user for a product listing API
use admin
db.createUser({
  user: 'productListingApi',
  pwd: 'ProductApiPass!',
  roles: [
    { role: 'read', db: 'catalog' }  // read-only on catalog DB only
  ]
})

Creating Custom Roles

When built-in roles are too broad, create a custom role using db.createRole(). A role definition lists specific privileges — each privilege is an action (e.g., find, insert, createIndex) on a resource (a specific database, collection, or cluster). Custom roles can also inherit from existing roles using the roles array.

// Custom role: can read orders and update order status only
use myApp
db.createRole({
  role: 'orderProcessor',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'orders' },
      actions: ['find', 'update']
    }
  ],
  roles: []  // no inherited roles
})

Assigning Custom Roles to Users

Assign a custom role the same way you assign built-in roles — include it in the roles array when creating a user or grant it later with db.grantRolesToUser(). A user can hold multiple roles simultaneously, combining their permissions. MongoDB computes the union of all privileges from all assigned roles when authorizing each operation.

// Create user and assign custom role
use myApp
db.createUser({
  user: 'fulfillmentWorker',
  pwd: 'FulfillPass!',
  roles: [
    { role: 'orderProcessor', db: 'myApp' }
  ]
})

// Grant an additional role to an existing user
db.grantRolesToUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

Revoking Roles and Modifying Access

When an employee changes roles or a service is decommissioned, revoke unnecessary permissions promptly. db.revokeRolesFromUser() removes specific roles from a user without deleting the account. db.updateUser() lets you replace the entire roles array. Regularly audit users and their assigned roles with db.getUsers() to catch privilege creep.

// Revoke a specific role from a user
use myApp
db.revokeRolesFromUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

// Replace all roles for a user
db.updateUser('fulfillmentWorker', {
  roles: [{ role: 'read', db: 'myApp' }]  // demote to read-only
})

Collection-Level Privilege Granularity

Custom roles can be scoped to a specific collection rather than an entire database. This allows fine-grained access control where, for example, a service can only read the products collection but has no access to users or orders in the same database. Collection-level scoping is achieved by specifying a collection name in the resource document.

// Role scoped to a single collection
use myApp
db.createRole({
  role: 'catalogReader',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'products' },
      actions: ['find']
    }
  ],
  roles: []
})

Cluster Administration Roles

Several built-in roles govern cluster-level operations rather than data access. clusterMonitor grants read access to monitoring commands (useful for metrics exporters). clusterAdmin allows managing shards, replica sets, and global operations — very powerful, restrict carefully. backup and restore roles grant the specific permissions needed for mongodump and mongorestore without full admin rights.

// Backup user — can dump data but not administer users
use admin
db.createUser({
  user: 'backupAgent',
  pwd: 'BackupPass!',
  roles: [
    { role: 'backup', db: 'admin' }
  ]
})

// Monitoring exporter user
db.createUser({
  user: 'prometheusExporter',
  pwd: 'MonitorPass!',
  roles: [
    { role: 'clusterMonitor', db: 'admin' },
    { role: 'read', db: 'local' }
  ]
})

Viewing Role Details and Inherited Privileges

Use db.getRole(roleName, { showPrivileges: true }) to see exactly which actions and resources a role grants, including inherited privileges from parent roles. This is essential for auditing — you can confirm that a custom role provides exactly the right permissions without accidentally granting broader access through inherited roles.

// Inspect a custom role's full privileges
use myApp
db.getRole('orderProcessor', { showPrivileges: true })

// List all custom roles in the current database
db.getRoles({ showBuiltinRoles: false })

// List all users and their roles
db.getUsers()

RBAC in MongoDB Atlas

MongoDB Atlas implements RBAC through its Database Access panel. You can create database users with built-in or custom roles via the Atlas UI, Atlas CLI, or Atlas API. Atlas also supports temporary users that expire automatically after a set time — ideal for short-lived developer access or incident response. Additionally, Atlas can integrate with AWS IAM and LDAP for enterprise identity management.

Quick Check

Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.

Lesson Recap

In this lesson you learned: built-in roles like read, readWrite, and dbAdmin cover common access patterns at database scope, custom roles let you define collection-level privileges with only the exact actions required, and principle of least privilege — each user and service account should hold only the permissions it genuinely needs. Next up we cover encryption at rest and TLS in transit.

Perguntas Frequentes

A aula “Controle de acesso baseado em funções: funções integradas e personalizadas” é grátis?

Sim — o texto completo de “Controle de acesso baseado em funções: funções integradas e personalizadas” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de MongoDB Academy, atualize para CoddyKit PRO. O curso de MongoDB Academy inclui 4 aulas no total.

O que vou aprender em “Controle de acesso baseado em funções: funções integradas e personalizadas”?

Os alunos atribuirão funções integradas, como readWrite e dbAdmin, e criarão funções personalizadas com conjuntos de ações de privilégio mínimo para contas de serviço. Você pratica MongoDB Academy com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.

Preciso ter experiência prévia para começar MongoDB Academy?

Nenhuma experiência prévia é necessária. MongoDB Academy no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 2 de 4.

Quanto tempo leva a aula “Controle de acesso baseado em funções: funções integradas e personalizadas”?

A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.

Posso escrever e executar código nesta aula de MongoDB Academy?

Sim. Cada aula de MongoDB Academy inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.

Todas as aulas deste curso

  1. Mecanismos de autenticação: SCRAM e x.509
  2. Controle de acesso baseado em funções: funções integradas e personalizadas
  3. Criptografia em repouso e TLS em trânsito
  4. Criptografia em nível de campo no lado do cliente
← Voltar para MongoDB Academy