diff --git a/docs/documentation/platform/dynamic-secrets/mongo-db.mdx b/docs/documentation/platform/dynamic-secrets/mongo-db.mdx new file mode 100644 index 000000000..3ff38c56c --- /dev/null +++ b/docs/documentation/platform/dynamic-secrets/mongo-db.mdx @@ -0,0 +1,112 @@ +--- +title: "Mongo DB" +description: "Learn how to dynamically generate Mongo DB Database user credentials." +--- + +The Infisical Mongo DB dynamic secret allows you to generate Mongo DB Database credentials on demand based on configured role. + +## Prerequisite +Create a user with the required permission in your SQL instance. This user will be used to create new accounts on-demand. + +## Set up Dynamic Secrets with Mongo DB + + + + Open the Secret Overview dashboard and select the environment in which you would like to add a dynamic secret. + + + ![Add Dynamic Secret Button](../../../images/platform/dynamic-secrets/add-dynamic-secret-button.png) + + + ![Dynamic Secret Modal](../../../images/platform/dynamic-secrets/dynamic-secret-modal-mongodb.png) + + + + Name by which you want the secret to be referenced + + + + Default time-to-live for a generated secret (it is possible to modify this value when a secret is generate) + + + + Maximum time-to-live for a generated secret + + + + Database host URL. + + + + Database port number. If your Mongo DB is cluster you can omit this. + + + + Username of the admin user that will be used to create dynamic secrets + + + + Password of the admin user that will be used to create dynamic secrets + + + + Name of the database for which you want to create dynamic secrets + + + + Human-readable label that identifies a group of privileges assigned to a database user. This value can either be a built-in role or a custom role. + - Enum: `atlasAdmin` `backup` `clusterMonitor` `dbAdmin` `dbAdminAnyDatabase` `enableSharding` `read` `readAnyDatabase` `readWrite` `readWriteAnyDatabase` ``. + + + + A CA may be required if your DB requires it for incoming connections. + + + ![Dynamic Secret Setup Modal](../../../images/platform/dynamic-secrets/dynamic-secret-mongodb.png) + + + + After submitting the form, you will see a dynamic secret created in the dashboard. + + + If this step fails, you may have to add the CA certificate. + + + ![Dynamic Secret](../../../images/platform/dynamic-secrets/dynamic-secret.png) + + + Once you've successfully configured the dynamic secret, you're ready to generate on-demand credentials. + To do this, simply click on the 'Generate' button which appears when hovering over the dynamic secret item. + Alternatively, you can initiate the creation of a new lease by selecting 'New Lease' from the dynamic secret lease list section. + + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-generate.png) + ![Dynamic Secret](/images/platform/dynamic-secrets/dynamic-secret-lease-empty.png) + + When generating these secrets, it's important to specify a Time-to-Live (TTL) duration. This will dictate how long the credentials are valid for. + + ![Provision Lease](/images/platform/dynamic-secrets/provision-lease.png) + + + Ensure that the TTL for the lease fall within the maximum TTL defined when configuring the dynamic secret. + + + + Once you click the `Submit` button, a new secret lease will be generated and the credentials from it will be shown to you. + + ![Provision Lease](/images/platform/dynamic-secrets/lease-values.png) + + + +## Audit or Revoke Leases +Once you have created one or more leases, you will be able to access them by clicking on the respective dynamic secret item on the dashboard. +This will allow you see the expiration time of the lease or delete a lease before it's set time to live. + +![Provision Lease](/images/platform/dynamic-secrets/lease-data.png) + +## Renew Leases +To extend the life of the generated dynamic secret leases past its initial time to live, simply click on the **Renew** as illustrated below. +![Provision Lease](/images/platform/dynamic-secrets/dynamic-secret-lease-renew.png) + + + Lease renewals cannot exceed the maximum TTL set when configuring the dynamic secret + diff --git a/docs/images/platform/dynamic-secrets/dynamic-secret-modal-mongodb.png b/docs/images/platform/dynamic-secrets/dynamic-secret-modal-mongodb.png new file mode 100644 index 000000000..7a862a379 Binary files /dev/null and b/docs/images/platform/dynamic-secrets/dynamic-secret-modal-mongodb.png differ diff --git a/docs/images/platform/dynamic-secrets/dynamic-secret-mongodb.png b/docs/images/platform/dynamic-secrets/dynamic-secret-mongodb.png new file mode 100644 index 000000000..5b692ac0e Binary files /dev/null and b/docs/images/platform/dynamic-secrets/dynamic-secret-mongodb.png differ diff --git a/docs/mint.json b/docs/mint.json index d22bf9038..5d14db36d 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -165,7 +165,8 @@ "documentation/platform/dynamic-secrets/aws-elasticache", "documentation/platform/dynamic-secrets/elastic-search", "documentation/platform/dynamic-secrets/aws-iam", - "documentation/platform/dynamic-secrets/mongo-atlas" + "documentation/platform/dynamic-secrets/mongo-atlas", + "documentation/platform/dynamic-secrets/mongo-db" ] }, {