DeployBoard / DeployBoard/deployboard-python

Add Access Controls to Mongo

Aperta
#24 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
database enhancement
Lingua principale
Python
Stelle
10
Fork
1
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

By default, Mongo comes with Access Controls disabled. We should enable them for the db container we provide in docker-compose. In a real production environment, users may be using something like MongoDB Atlas, or AWS's DocumentDB which would require some Access Control configuration on that end. In case users decide `docker-compose up` is just enough for their environment, we should provide some level of Access Control on the provided Mongo container for security and data integrity.

The current version of the db_seed.py script is really just for testing the database. We should probably rename that file to something like db_seed_dev.py and create a new db_seed.py file that would initialize the database with an account, a first user, and a database user that the application would use.

See this doc from Mongo for more information on Access Controls: https://docs.mongodb.com/manual/tutorial/enable-authentication/

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Start by reading docker-compose and the current db_seed.py script, then review MongoDB's authentication documentation linked in the issue. Verify how the provided container and seed script are used before changing them. Done means the development container has access controls enabled, the database is initialized with the described account and users, and the testing seed script is separated as requested.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
docker-compose, mongodb, python
Ambito
database, devops, security
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
38/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.