Sign inSign up

detoxd/mongo

By detoxd

•Updated 6 months ago

Image
0

2.2K

detoxd/mongo repository overview

⁠MongoDB - Detoxd Hardened Image

⁠Overview

MongoDB is a document-oriented NoSQL database designed for scalability and developer agility. Created by MongoDB Inc. in 2007, it stores data in flexible, JSON-like documents where fields can vary from document to document. MongoDB is ideal for applications requiring flexible schemas, horizontal scaling, and high availability.

⁠Common Use Cases

  • Content Management - Storing articles, comments, metadata
  • Mobile Applications - Offline-first data sync
  • Real-time Analytics - Event logging and aggregation
  • IoT Applications - Time-series sensor data
  • E-commerce - Product catalogs, user profiles
  • Gaming - Player data, leaderboards

⁠Security Concerns

MongoDB has been notably targeted by ransomware:

  • No Authentication by Default - Older versions had auth disabled
  • Internet Exposure - Databases directly accessible from internet
  • Injection Attacks - NoSQL injection through query operators
  • Data Exposure - Unencrypted data and connections
  • Ransomware - "MongoDB Apocalypse" incidents

⁠What Detoxd Does

⁠System Hardening
  • Updates all Debian packages to latest versions
  • Removes unnecessary packages and development tools
  • Cleans package caches
  • Sets secure file permissions
⁠Security Improvements
  • Removes setuid/setgid bits from binaries
  • Removes unnecessary system users
  • Prepares for authentication enablement
⁠Network Security
  • Exposes only MongoDB port (27017)
  • Ready for SSL/TLS configuration
⁠mongod.conf Security Settings
security:
  authorization: enabled
  javascriptEnabled: false  # Disable if not needed

net:
  port: 27017
  bindIp: 127.0.0.1  # Only local connections
  ssl:
    mode: requireSSL
    PEMKeyFile: /etc/ssl/mongodb.pem
    CAFile: /etc/ssl/ca.pem

setParameter:
  authenticationMechanisms: SCRAM-SHA-256

auditLog:
  destination: file
  format: JSON
  path: /var/log/mongodb/audit.json
⁠Enable Authentication
// Create admin user
use admin
db.createUser({
  user: "adminUser",
  pwd: passwordPrompt(),  // Prompts for password
  roles: [
    { role: "userAdminAnyDatabase", db: "admin" },
    { role: "readWriteAnyDatabase", db: "admin" }
  ]
})

// Create application user with minimal privileges
use myapp
db.createUser({
  user: "appUser",
  pwd: passwordPrompt(),
  roles: [
    { role: "readWrite", db: "myapp" }
  ]
})

// Enable authentication
db.adminCommand({ setParameter: 1, authenticationMechanisms: ["SCRAM-SHA-256"] })
⁠Role-Based Access Control
// Create custom role with specific permissions
use myapp
db.createRole({
  role: "readWriteRestricted",
  privileges: [
    { resource: { db: "myapp", collection: "users" }, actions: ["find", "insert", "update"] },
    { resource: { db: "myapp", collection: "posts" }, actions: ["find"] }
  ],
  roles: []
})

⁠Environment Variables

MONGO_INITDB_ROOT_USERNAME=admin
MONGO_INITDB_ROOT_PASSWORD=your_secure_password
MONGO_INITDB_DATABASE=myapp

# Optional: Disable scripting
MONGO_DISABLE_JAVASCRIPT=true

⁠Docker Compose Example

version: '3.8'
services:
  mongodb:
    image: detoxd/mongo:8.0-detox.1
    environment:
      MONGO_INITDB_ROOT_USERNAME: admin
      MONGO_INITDB_ROOT_PASSWORD: ${MONGO_PASSWORD}
    volumes:
      - mongo_data:/data/db
      - ./mongod.conf:/etc/mongod.conf:ro
    command: ["mongod", "--config", "/etc/mongod.conf"]
    networks:
      - backend
    deploy:
      resources:
        limits:
          memory: 1G

⁠References

Tag summary

Content type

Image

Digest

sha256:355b8d729…

Size

298.3 MB

Last updated

6 months ago

docker pull detoxd/mongo:8.0-detox.1