Skip to main content

Azure Cosmos DB for MongoDB vCore

Azure Cosmos DB for MongoDB vCore is a managed, MongoDB-compatible database on dedicated compute. The Azure Web App Blueprint runs one cluster per stage, <prefix>-mongo, reachable only through a private endpoint and only with Microsoft Entra tokens.

What it does​

A cluster has a compute tier (M10, M30 and up), a storage size and one or more shards. High availability keeps a standby replica in another availability zone and fails over to it. Clients authenticate either with a username and password (native authentication) or with a Microsoft Entra token through the MongoDB OIDC mechanism. Public access can be disabled in favor of private endpoints, and the service reports a connection string, often in mongodb+srv:// form.

How BuiltForProd uses it​

The mongo-cluster unit creates <prefix>-mongo with MongoDB 8.0, one shard and public network access disabled. Its private endpoint pe-<prefix>-mongo sits in the stage's snet-endpoints and registers in the central privatelink.mongocluster.cosmos.azure.com zone; see Private Link.

No password exists. The cluster accepts Microsoft Entra principals only. The application's workload identity id-<prefix>-app is a database user, and the API connects with pymongo's MONGODB-OIDC mechanism: a callback asks the pod's Workload ID credential for an Entra token whenever the driver needs one. Nothing to rotate, nothing in the vault, nothing in OpenTofu state. native_auth = true adds a password administrator for tools that cannot present tokens; its generated password is then stored in the application vault as mongo--password and, as the module states, in state.

Stagemongo_compute_tier (stack comment)mongo_high_availabilitymongo_storage_gb
devM10, ~$70–90/monthoff32
stagingM30, ~$270/monthon: zone-redundant standby, doubles compute128
prodM30, ~$270/monthon128

What the application reads. The unit writes mongo--host, mongo--port (10260) and mongo--srv to the stage's application vault, and the External Secrets Operator maps them to MONGO_HOST, MONGO_PORT and MONGO_SRV. When the service reports an SRV string, the client connects with mongodb+srv:// and no port, and the central zone resolves the shard hosts to the private endpoint. The pods' NetworkPolicy allows TCP 10260 to the snet-endpoints prefix only.

Operate. Request logs (vCoreMongoRequests) and all metrics go to the stage application workspace. delete_locks puts a CanNotDelete lock on the cluster in prod.

Terms you will see​

TermMeaning
Compute tierThe cluster size: M10 in dev, M30 in staging and prod.
High availabilityA standby replica in another zone, ZoneRedundantPreferred.
MONGODB-OIDCThe MongoDB authentication mechanism that presents an Entra token.
Native authenticationUsername and password; off unless native_auth is set.
SRV connection stringmongodb+srv://, which lists the hosts through DNS.

Where to read more​