DeployBoard / DeployBoard/deployboard-python

Add Access Controls to Mongo

Open
#24 0 comments 0 reactions 0 assignees View on GitHub
database enhancement
Dominant language
Python
Stars
10
Forks
1
PR merge metrics
No merged PRs in 30d

Description

By default, Mongo comes with Access Controls disabled. We should enable them for the db container we provide in docker-compose. In a real production environment, users may be using something like MongoDB Atlas, or AWS's DocumentDB which would require some Access Control configuration on that end. In case users decide `docker-compose up` is just enough for their environment, we should provide some level of Access Control on the provided Mongo container for security and data integrity.

The current version of the db_seed.py script is really just for testing the database. We should probably rename that file to something like db_seed_dev.py and create a new db_seed.py file that would initialize the database with an account, a first user, and a database user that the application would use.

See this doc from Mongo for more information on Access Controls: https://docs.mongodb.com/manual/tutorial/enable-authentication/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading docker-compose and the current db_seed.py script, then review MongoDB's authentication documentation linked in the issue. Verify how the provided container and seed script are used before changing them. Done means the development container has access controls enabled, the database is initialized with the described account and users, and the testing seed script is separated as requested.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker-compose, mongodb, python
Domain
database, devops, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.