You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为MongoDB用户创建自定义规则及配置仅读写不可删除用户

Hey folks! I’ve been there—spending way too long digging up how to tweak MongoDB user permissions exactly how you need them. Let’s break down your two questions clearly, so you can get this sorted quickly.

1. How to Create Custom Rules for MongoDB Users?

MongoDB lets you build custom roles tailored to specific needs, instead of relying only on built-in roles. Here’s the step-by-step:

  • First, switch to the admin database (this is where user/role management lives):

    use admin
    
  • Use db.createRole() to define your custom role. This takes two key parameters:

    • privileges: A list of specific actions the role can perform, plus the resources (databases/collections) they apply to.
    • roles: Any existing roles you want to inherit permissions from (can be empty if you’re building from scratch).

Example: Let’s create a role that can read from the analytics database and run aggregation queries:

db.createRole(
  {
    role: "analyticsReader",
    privileges: [
      { resource: { db: "analytics", collection: "" }, actions: ["find", "aggregate"] }
    ],
    roles: []
  }
)
  • Then assign this custom role to a user when creating them (or update an existing user):
db.createUser(
  {
    user: "jane_doe",
    pwd: "securePassword123",
    roles: [{ role: "analyticsReader", db: "admin" }]
  }
)

2. How to Create a MongoDB User with Read-Write Access But No Document Deletion Permissions?

Built-in roles like readWrite include delete permissions, which isn’t ideal if you want to prevent accidental data loss. The solution is to build a custom role that excludes delete actions.

Here’s how to do it:

  • Again, start in the admin database:

    use admin
    
  • Create a custom role that allows read, insert, and update—but blocks delete operations. We’ll specify exactly which actions we want to grant:

db.createRole(
  {
    role: "readWriteNoDelete",
    privileges: [
      // Allow read access
      { resource: { db: "your_database", collection: "" }, actions: ["find"] },
      // Allow write access (insert/update)
      { resource: { db: "your_database", collection: "" }, actions: ["insert", "update", "replace"] },
      // Optional: Allow index management if needed
      { resource: { db: "your_database", collection: "" }, actions: ["createIndex", "dropIndex"] }
    ],
    roles: []
  }
)
  • Now create a user with this custom role:
db.createUser(
  {
    user: "safe_writer",
    pwd: "StrongPwd456!",
    roles: [{ role: "readWriteNoDelete", db: "admin" }]
  }
)

Important note: Replace your_database with the actual name of your database. If you want this role to apply to all databases, you can use { db: "", collection: "" } as the resource, but it’s better to keep permissions as granular as possible for security.

内容的提问来源于stack exchange,提问作者gokul kandasamy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 16:37:29