0Pricing
MongoDB Academy · Урок

Управление доступом на основе ролей: встроенные и пользовательские роли

Учащиеся назначат встроенные роли, такие как readWrite и dbAdmin, и создадут пользовательские роли с минимально необходимым набором действий для служебных учётных записей.

«Управление доступом на основе ролей: встроенные и пользовательские роли» — бесплатный урок MongoDB Academy на CoddyKit. Это урок 2 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения MongoDB Academy, и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс MongoDB Academy содержит 4 уроков всего.

Части этого урока еще не переведены и отображаются на английском.

What Is Role-Based Access Control?

Role-Based Access Control (RBAC) is MongoDB's authorization model. Instead of granting individual permissions directly to users, you assign roles — named collections of privileges — to users. This makes permission management scalable: update a role and every user holding that role inherits the change automatically. MongoDB ships with a rich set of built-in roles covering the most common access patterns.

Built-In Database Roles

MongoDB provides several database-level roles that apply to a specific database. The most commonly used are: read (read all collections), readWrite (read + insert/update/delete), dbAdmin (schema management, index creation), and userAdmin (create/modify users in that database). These roles are database-scoped — a user with readWrite on myApp cannot access otherApp.

// Create a user with readWrite on one database only
use myApp
db.createUser({
  user: 'appUser',
  pwd: 'SecurePass!',
  roles: [
    { role: 'readWrite', db: 'myApp' }
  ]
})

// Create a user with dbAdmin (can manage indexes but not data)
db.createUser({
  user: 'dbaUser',
  pwd: 'DbaPass!',
  roles: [
    { role: 'dbAdmin', db: 'myApp' }
  ]
})

Built-In Cluster-Wide Roles

Some built-in roles span all databases on a MongoDB instance. readAnyDatabase and readWriteAnyDatabase grant their respective permissions across every database. dbAdminAnyDatabase allows schema management everywhere. The most powerful is root, which has full access to everything — use it only for initial setup and emergency recovery, never for application accounts.

// Grant read-only access to all databases (reporting tool)
use admin
db.createUser({
  user: 'globalReporter',
  pwd: 'ReportPass!',
  roles: [
    { role: 'readAnyDatabase', db: 'admin' }
  ]
})

// The root role — avoid for applications
// roles: [{ role: 'root', db: 'admin' }]  // too powerful!

The Principle of Least Privilege

Every MongoDB user should have exactly the permissions they need — no more. An API that only reads products should have read, not readWrite. A background job that archives documents should only be able to query and delete from the archive collection — not from all collections. Applying least privilege limits the blast radius of a compromised credential.

// Tightly scoped user for a product listing API
use admin
db.createUser({
  user: 'productListingApi',
  pwd: 'ProductApiPass!',
  roles: [
    { role: 'read', db: 'catalog' }  // read-only on catalog DB only
  ]
})

Creating Custom Roles

When built-in roles are too broad, create a custom role using db.createRole(). A role definition lists specific privileges — each privilege is an action (e.g., find, insert, createIndex) on a resource (a specific database, collection, or cluster). Custom roles can also inherit from existing roles using the roles array.

// Custom role: can read orders and update order status only
use myApp
db.createRole({
  role: 'orderProcessor',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'orders' },
      actions: ['find', 'update']
    }
  ],
  roles: []  // no inherited roles
})

Assigning Custom Roles to Users

Assign a custom role the same way you assign built-in roles — include it in the roles array when creating a user or grant it later with db.grantRolesToUser(). A user can hold multiple roles simultaneously, combining their permissions. MongoDB computes the union of all privileges from all assigned roles when authorizing each operation.

// Create user and assign custom role
use myApp
db.createUser({
  user: 'fulfillmentWorker',
  pwd: 'FulfillPass!',
  roles: [
    { role: 'orderProcessor', db: 'myApp' }
  ]
})

// Grant an additional role to an existing user
db.grantRolesToUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

Revoking Roles and Modifying Access

When an employee changes roles or a service is decommissioned, revoke unnecessary permissions promptly. db.revokeRolesFromUser() removes specific roles from a user without deleting the account. db.updateUser() lets you replace the entire roles array. Regularly audit users and their assigned roles with db.getUsers() to catch privilege creep.

// Revoke a specific role from a user
use myApp
db.revokeRolesFromUser('fulfillmentWorker', [
  { role: 'read', db: 'products' }
])

// Replace all roles for a user
db.updateUser('fulfillmentWorker', {
  roles: [{ role: 'read', db: 'myApp' }]  // demote to read-only
})

Collection-Level Privilege Granularity

Custom roles can be scoped to a specific collection rather than an entire database. This allows fine-grained access control where, for example, a service can only read the products collection but has no access to users or orders in the same database. Collection-level scoping is achieved by specifying a collection name in the resource document.

// Role scoped to a single collection
use myApp
db.createRole({
  role: 'catalogReader',
  privileges: [
    {
      resource: { db: 'myApp', collection: 'products' },
      actions: ['find']
    }
  ],
  roles: []
})

Cluster Administration Roles

Several built-in roles govern cluster-level operations rather than data access. clusterMonitor grants read access to monitoring commands (useful for metrics exporters). clusterAdmin allows managing shards, replica sets, and global operations — very powerful, restrict carefully. backup and restore roles grant the specific permissions needed for mongodump and mongorestore without full admin rights.

// Backup user — can dump data but not administer users
use admin
db.createUser({
  user: 'backupAgent',
  pwd: 'BackupPass!',
  roles: [
    { role: 'backup', db: 'admin' }
  ]
})

// Monitoring exporter user
db.createUser({
  user: 'prometheusExporter',
  pwd: 'MonitorPass!',
  roles: [
    { role: 'clusterMonitor', db: 'admin' },
    { role: 'read', db: 'local' }
  ]
})

Viewing Role Details and Inherited Privileges

Use db.getRole(roleName, { showPrivileges: true }) to see exactly which actions and resources a role grants, including inherited privileges from parent roles. This is essential for auditing — you can confirm that a custom role provides exactly the right permissions without accidentally granting broader access through inherited roles.

// Inspect a custom role's full privileges
use myApp
db.getRole('orderProcessor', { showPrivileges: true })

// List all custom roles in the current database
db.getRoles({ showBuiltinRoles: false })

// List all users and their roles
db.getUsers()

RBAC in MongoDB Atlas

MongoDB Atlas implements RBAC through its Database Access panel. You can create database users with built-in or custom roles via the Atlas UI, Atlas CLI, or Atlas API. Atlas also supports temporary users that expire automatically after a set time — ideal for short-lived developer access or incident response. Additionally, Atlas can integrate with AWS IAM and LDAP for enterprise identity management.

Quick Check

Test your understanding of MongoDB & NoSQL Databases concepts from this lesson.

Lesson Recap

In this lesson you learned: built-in roles like read, readWrite, and dbAdmin cover common access patterns at database scope, custom roles let you define collection-level privileges with only the exact actions required, and principle of least privilege — each user and service account should hold only the permissions it genuinely needs. Next up we cover encryption at rest and TLS in transit.

Часто задаваемые вопросы

Урок «Управление доступом на основе ролей: встроенные и пользовательские роли» бесплатный?

Да — полный текст урока «Управление доступом на основе ролей: встроенные и пользовательские роли» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс MongoDB Academy, подпишись на CoddyKit PRO. Курс MongoDB Academy содержит 4 уроков всего.

Чему я научусь в уроке «Управление доступом на основе ролей: встроенные и пользовательские роли»?

Учащиеся назначат встроенные роли, такие как readWrite и dbAdmin, и создадут пользовательские роли с минимально необходимым набором действий для служебных учётных записей. Ты практикуешь MongoDB Academy с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.

Нужен ли мне опыт, чтобы начать MongoDB Academy?

Предыдущий опыт не требуется. MongoDB Academy на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 2 из 4.

Сколько времени занимает урок «Управление доступом на основе ролей: встроенные и пользовательские роли»?

Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.

Можно ли писать и запускать код в этом уроке MongoDB Academy?

Да. Каждый урок MongoDB Academy включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.

Все уроки этого курса

  1. Механизмы аутентификации: SCRAM и x.509
  2. Управление доступом на основе ролей: встроенные и пользовательские роли
  3. Шифрование данных в состоянии покоя и TLS при передаче
  4. Шифрование полей на стороне клиента
← Назад к MongoDB Academy