DeployBoard / DeployBoard/deployboard-python
Add Access Controls to Mongo
- Dominant language
- Python
- Stars
- 10
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
By default, Mongo comes with Access Controls disabled. We should enable them for the db container we provide in docker-compose. In a real production environment, users may be using something like MongoDB Atlas, or AWS's DocumentDB which would require some Access Control configuration on that end. In case users decide `docker-compose up` is just enough for their environment, we should provide some level of Access Control on the provided Mongo container for security and data integrity.
The current version of the db_seed.py script is really just for testing the database. We should probably rename that file to something like db_seed_dev.py and create a new db_seed.py file that would initialize the database with an account, a first user, and a database user that the application would use.
See this doc from Mongo for more information on Access Controls: https://docs.mongodb.com/manual/tutorial/enable-authentication/
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading docker-compose and the current db_seed.py script, then review MongoDB's authentication documentation linked in the issue. Verify how the provided container and seed script are used before changing them. Done means the development container has access controls enabled, the database is initialized with the described account and users, and the testing seed script is separated as requested.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker-compose, mongodb, python
- Domain
- database, devops, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100