Skip to content

Connecting to MongoDB

  • MongoDB

A MongoDB connection profile says where the servers are and how to sign in. You can connect to one server, to a list of replica set members, to an SRV name (mongodb+srv) or through a connection URI, and sign in with a user and password (SCRAM or LDAP) or with an X.509 client certificate.

  1. Open the Connection actions menu at the top of the side bar and choose New connection, or press Ctrl + Shift + N (Cmd + Shift + N on macOS).
  2. Pick the MongoDB card and choose Next, or double-click the card. To start from a URI instead, paste it into Paste a URI to fill the form and choose Fill from URI: the URI names the engine, so the form opens filled in.
  3. On the General tab, enter a Name, pick how Querybara reaches the servers under Connect with (see Endpoints) and fill in its fields.
  4. Still on General, pick how you sign in under Authentication (see Sign-in methods).
  5. On the Advanced tab, set the options you need.
  6. On the TLS tab, set the TLS mode, and the CA certificate, Client certificate and Client key if your server needs them. A new connection starts with TLS off; an SRV record, or tls or ssl in a pasted URI, turns it on.
  7. Choose Test Connection. Each step is shown as it runs: DNS lookup, TCP connect, SSH tunnel, TLS handshake, Authentication, Ping and Server version. The last step names the MongoDB version and the topology.
  8. Choose Save.

A tab that holds an invalid field shows a red dot, and Save or Test Connection opens it.

Connect with What you enter
Host and port Host and Port of one server.
Host list (replica set) Hosts: any members of the replica set (the driver finds the others), and an optional Replica set name such as rs0. Use Add host for more rows.
SRV record (mongodb+srv) SRV host name, such as cluster0.example.com.
Connection URI URI (without the password), such as mongodb://[email protected]:27017,db2.example.com:27017/catalog?replicaSet=rs0.

With SRV record (mongodb+srv), Querybara looks up the hosts (the _mongodb._tcp SRV record) and the default options in DNS, as a mongodb+srv:// URI does. The lookup happens on this computer, also when the servers are reached through an SSH tunnel or a proxy. An SRV record implies TLS, as in the MongoDB drivers: set TLS mode to Disable TLS only for a server that has none.

These fields are on the Advanced tab, for every endpoint except Connection URI, where the URI carries them.

Option What it does
Default database Optional. The database the connection starts in.
Read preference Driver default (primary), Primary, Primary preferred, Secondary, Secondary preferred or Nearest.
Direct connection With Host and port only. Talk to that host only instead of discovering the replica set from it.

Use Direct connection for a secondary, or for a member known by an address the other members do not use.

Authentication What you enter
None Nothing.
User and password Mechanism, User, the password and, except with a URI, the Authentication database (where the user is defined; empty uses admin).
X.509 client certificate The client certificate and key on the TLS tab. User is optional: the certificate’s subject, such as CN=app,OU=clients.

The Mechanism list offers SCRAM-SHA-256, SCRAM-SHA-1, LDAP (PLAIN) and Negotiate with the server. LDAP users are always in $external, so with LDAP (PLAIN) the authentication database is fixed to $external.

An X.509 sign-in also happens in $external. You can choose one PEM file that holds both the certificate and the key for Client certificate and Client key.

Host lists, SRV names and URIs that name several hosts or a replicaSet work through an SSH tunnel (jump hosts included) and through SOCKS5 and HTTP proxies. Each member is reached by the name it announces, resolved on the far side of the tunnel. A single host behind a tunnel connects with a direct connection.

SRV and TXT records are still looked up on this computer. If the SRV name does not resolve here, the connection fails with a hint: make the name resolvable on this computer, or use a host list.

See Replica sets, Sentinel and Cluster through tunnels.

querybara test runs the same stepwise check against a saved profile or a MongoDB URI:

Terminal window
querybara test "mongodb+srv://[email protected]/catalog"
querybara test "mongodb://[email protected]:27017/catalog" --ssh [email protected] --ssh-agent

It exits with 0 when every step passes and 1 when one fails, with a fix hint.

Documents Querybara 0.1.1 · built frombc9f5aa