Azure Cosmos DB for MongoDB vCore
Azure Cosmos DB for MongoDB vCore is a managed, MongoDB-compatible database on dedicated compute. The Azure Web App Blueprint runs one cluster per stage, <prefix>-mongo, reachable only through a private endpoint and only with Microsoft Entra tokens.
What it does
A cluster has a compute tier (M10, M30 and up), a storage size and one or more shards. High availability keeps a standby replica in another availability zone and fails over to it. Clients authenticate either with a username and password (native authentication) or with a Microsoft Entra token through the MongoDB OIDC mechanism. Public access can be disabled in favor of private endpoints, and the service reports a connection string, often in mongodb+srv:// form.
How BuiltForProd uses it
The mongo-cluster unit creates <prefix>-mongo with MongoDB 8.0, one shard and public network access disabled. Its private endpoint pe-<prefix>-mongo sits in the stage's snet-endpoints and registers in the central privatelink.mongocluster.cosmos.azure.com zone; see Private Link.
No password exists. The cluster accepts Microsoft Entra principals only. The application's workload identity id-<prefix>-app is a database user, and the API connects with pymongo's MONGODB-OIDC mechanism: a callback asks the pod's Workload ID credential for an Entra token whenever the driver needs one. Nothing to rotate, nothing in the vault, nothing in OpenTofu state. native_auth = true adds a password administrator for tools that cannot present tokens; its generated password is then stored in the application vault as mongo--password and, as the module states, in state.
| Stage | mongo_compute_tier (stack comment) | mongo_high_availability | mongo_storage_gb |
|---|---|---|---|
| dev | M10, ~$70–90/month | off | 32 |
| staging | M30, ~$270/month | on: zone-redundant standby, doubles compute | 128 |
| prod | M30, ~$270/month | on | 128 |
What the application reads. The unit writes mongo--host, mongo--port (10260) and mongo--srv to the stage's application vault, and the External Secrets Operator maps them to MONGO_HOST, MONGO_PORT and MONGO_SRV. When the service reports an SRV string, the client connects with mongodb+srv:// and no port, and the central zone resolves the shard hosts to the private endpoint. The pods' NetworkPolicy allows TCP 10260 to the snet-endpoints prefix only.
Operate. Request logs (vCoreMongoRequests) and all metrics go to the stage application workspace. delete_locks puts a CanNotDelete lock on the cluster in prod.
Terms you will see
| Term | Meaning |
|---|---|
| Compute tier | The cluster size: M10 in dev, M30 in staging and prod. |
| High availability | A standby replica in another zone, ZoneRedundantPreferred. |
MONGODB-OIDC | The MongoDB authentication mechanism that presents an Entra token. |
| Native authentication | Username and password; off unless native_auth is set. |
| SRV connection string | mongodb+srv://, which lists the hosts through DNS. |
Where to read more
- Azure Web App Blueprint overview for the data path of the API.
- Managed identities for the workload identity the API uses.
- Azure Managed Redis for the cache beside it.