MongoDB
MongoDB Atlas, on-premises, or Amazon DocumentDB.
Access mode: Read-only or read-write
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Connection string | mongodb+srv://<user>:<pass>@<cluster>.mongodb.net/<db> or standard mongodb:// URI. |
| Database(s) | List all databases. |
| Collection(s) | If scoping to specific collections, list them. Otherwise, all collections in the database. |
| Authentication | SCRAM-SHA-256 (default), X.509 certificates, LDAP, or AWS IAM (DocumentDB). |
| Access level | Read-only: readAnyDatabase or read role per database. Include listDatabases, listCollections. |
Network considerations
Atlas: Add Flume IPs to Atlas IP Access List (Network Access → IP Access List). Or use VPC Peering / Private Endpoint for zero-trust.
On-premises: VPN or SSH tunnel to reach mongod/mongos. Default port 27017.
DocumentDB: Lives in a VPC. Requires VPC peering or PrivateLink.
Replica sets: Provide all replica set member addresses (or the SRV record for Atlas). Flume’s driver handles failover.
Credential and auth management
Preferred: X.509 certificate auth. Provide client cert signed by your internal CA. No password to rotate.
Preferred: AWS IAM (DocumentDB). Flume authenticates via IAM role assumption. No database password.
Acceptable: SCRAM-SHA-256. Atlas default. Create dedicated database user with minimal roles.
Connection string: Include retryWrites=true&w=majority&tls=true for Atlas.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | mongosh --eval 'db.runCommand({ping: 1})' | {ok: 1} |
| Authentication + roles | db.runCommand({connectionStatus: 1}) | Shows authenticated user and roles |
| Database access | show dbs | Lists expected databases |
| Collection access | db.getCollectionNames() | Lists collections |
| Read test | db.<collection>.findOne() | Returns a document |
| Aggregate test | db.<collection>.aggregate([{$limit: 1}]) | Returns a result |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.