The setup i am trying to success is to have a node process which create databases, and other servers access those databases with a secure way.
So my idea was to create the database from node with a user and pass. Then open the server mongodb port to open access and lock the mongo admin user. If that theory is good:
- How to make user with mongoose so that database will be accessible only with that user?
- On the
/etc/mongodb.confshould i only addbind_ip = 0.0.0.0and that's all?
PS: i am using Ubuntu 16:04 and latest Mongodb.
Edit: 13/08/17
What i have success until now is to addUser = db.createUser({user: "admin",pwd: "admin",roles: [ { role: "userAdminAnyDatabase", db: "admin" } ]}); for admin database, connect with it while database is under --auth and trying to create other database via that connection, like below.
var adminConnection = mongoose.createConnection('mongodb://admin:admin@localhost:27017/admin', {
useMongoClient: true
});
console.log(typeof adminConnection.db.executeDbAdminCommand);//function