Skip to content

Replica sets, Sentinel and Cluster

  • MongoDB
  • Redis / Valkey
  • CLI

Some deployments are several servers that announce each other: a MongoDB replica set, Redis Sentinel and Redis Cluster. The driver connects to one or more of them, learns the rest from the first that answers, and then connects to those by the names or addresses they announce. Querybara supports these topologies directly and through an SSH tunnel or a proxy.

Through the bastionQuerybara opens one SSH session per connection, shared by its tabs, checks host keys against a known_hosts file, hops through a jump host and a bastion into a private network, and reaches each member of a replica set or cluster by name through the same route.Private networkQuery tabTable dataER diagramSSHone sessionJump hostjump.exampleBastionbastion.exampleknown_hostsapp + CLIdb-1primarydb-2secondarydb-3secondaryNew host keyTrust it?tabtabtabSHA256:…sshsshSELECT …db-2:27017db-3:27017

Through the bastion

  1. A connection opens one SSH session, and every tab of that connection shares it.
  2. Each server’s host key is checked against known_hosts, the file the app and the CLI share. A new key asks you to trust it; a changed key blocks the connection.
  3. The session hops through the jump host to the bastion: a chain of SSH hops, one shared session per path.
  4. From the bastion, traffic reaches the database inside the private network. The database is never exposed.
  5. A replica set or cluster is reached node by node, by the names its servers announce, through the same route.

Under Connect with on the General tab, choose one of:

Connect with Fill in
Host list (replica set) Hosts: any members of the replica set (Add host for more); the driver finds the others. Optionally the Replica set name, such as rs0.
SRV record (mongodb+srv) SRV host name, such as cluster0.example.net. Querybara looks up the hosts (the _mongodb._tcp SRV record) and default options in DNS. Choosing it turns TLS on; you can turn it off on the TLS tab.
Connection URI A mongodb:// URI with several hosts or a replicaSet option, or a mongodb+srv:// URI.

With Host and port, Querybara discovers the replica set from that one member. Tick Direct connection on the Advanced tab to talk to that host only, for example a secondary, or a member known by an address the others do not use.

Connect with Fill in
Sentinel Sentinels (port 26379 to start; Add sentinel for more), and the Master name, such as mymaster. Querybara asks the Sentinels for the current master.
Cluster Seed nodes: any reachable nodes (Add seed for more). Querybara discovers the rest of the cluster from them.

Choose these under Connect with on the General tab. A cluster has only database 0, so Database number (on the Advanced tab) is not offered for Cluster.

Behind a bastion, the servers usually announce names or addresses that only resolve and route on the far side. Querybara reaches every server through the same SSH session or proxy, by the name the server announces, and lets the SSH server or proxy resolve it:

  • MongoDB sends each of the driver’s connections through a local SOCKS5 endpoint that only Querybara can use, into the tunnel. Each member’s certificate is checked against its own name.
  • Redis gives each node its own local forward into the tunnel, opened as nodes appear, including after a failover or a redirection to a node not seen before. With Verify certificate and host name, each node’s certificate is checked against the name it announced.

Node names, redirections and the topology views look the same as without a tunnel.

Set this up like any tunnel: tick Connect through an SSH tunnel on the SSH tab (with jump hosts if needed), or set a Proxy type on the Proxy tab. While a tunnel or proxy is on, that tab explains how the engine’s endpoints are reached through it.

Test Connection reports the SSH or proxy step when the first server accepts a connection, then the topology’s own steps: the Server version step reports the replica set or the cluster.

Every server connection is a separate channel on the one SSH session. The SSH server’s MaxSessions setting does not limit these, but a restrictive PermitOpen must allow every member or node.

  • Host and port on MongoDB talks to that one server through a tunnel.
  • A Unix socket, and a SQL URI with several hosts, cannot go through a tunnel or proxy.
  • Elasticsearch does not discover nodes through a tunnel or proxy: list a single node URL, or use a Cloud ID. The sniffing option is not used through a tunnel or proxy.

The same topologies work with --ssh and --proxy:

Terminal window
querybara test "mongodb://[email protected]:27017,db2.example.com:27017/shop?replicaSet=rs0" \
--ssh [email protected] --ssh-agent
querybara test redis-cluster-prod

A saved profile uses its own tunnel or proxy. See SSH tunnels.

Documents Querybara 0.1.1 · built frombc9f5aa