Skip to main content

Firestore with MongoDB compatibility

Firestore with MongoDB compatibility is Firestore's Enterprise edition answering the MongoDB wire protocol, so MongoDB drivers and tools work against a serverless, replicated Google database. The GCP Web App Blueprint stores the application's documents there, one database per stage, and the application signs in with its workload identity instead of a password.

What it does​

A Firestore Enterprise database with MongoDB-compatible data access accepts MongoDB drivers on port 443 over TLS. It is serverless: there is no instance to size, and storage and operations are billed as used. A regional database is replicated across zones of its region. Point-in-time recovery (PITR) keeps seven days of versions to read or restore from; scheduled backups keep daily copies for a retention period; delete protection refuses deletion of the database. Authentication can use MONGODB-OIDC, where the client presents a Google token and Firestore IAM decides access.

How BuiltForProd uses it​

GCP/acme-gcp-blueprint-webapp-infra/modules/firestore/main.tf (lines 22-44)
resource "google_firestore_database" "mongo" {
project = var.project_id
name = "${var.name_prefix}-mongo"
location_id = var.gcp_region
type = "FIRESTORE_NATIVE" # required for the Enterprise edition

database_edition = "ENTERPRISE"
mongodb_compatible_data_access_mode = "DATA_ACCESS_MODE_ENABLED"

point_in_time_recovery_enablement = var.pitr ? "POINT_IN_TIME_RECOVERY_ENABLED" : "POINT_IN_TIME_RECOVERY_DISABLED"
delete_protection_state = var.delete_protection ? "DELETE_PROTECTION_ENABLED" : "DELETE_PROTECTION_DISABLED"
# With delete protection the database also outlives a destroy of this unit (ABANDON).
deletion_policy = var.delete_protection ? "ABANDON" : "DELETE"
}

resource "google_firestore_backup_schedule" "daily" {
count = var.backup_retention_days > 0 ? 1 : 0
project = var.project_id
database = google_firestore_database.mongo.name
retention = "${var.backup_retention_days * 86400}s"

daily_recurrence {}
}

The firestore unit creates <prefix>-mongo (for example acme-usw1-prd-mongo) in the stage region. Per stage:

Stagefirestore_pitrfirestore_backup_retention_daysfirestore_delete_protection
devoff0 (no backups)off
stagingon (7 days)0off
prodon (7 days)35, dailyon

With delete protection on, the database also survives a destroy of the unit: OpenTofu abandons it instead of deleting it. PITR is billed as storage and backups as backup storage; at most 98 days of retention are allowed.

No password. The application's Kubernetes service account is bound through Workload Identity Federation for GKE, directly as an IAM principal, to roles/datastore.user on the stage project (app-namespace unit). The application authenticates with MONGODB-OIDC: its driver presents the pod's access token. Nothing secret is stored in state or in the cluster.

Connection values. The unit writes mongo--host, mongo--uri and mongo--database to Secret Manager in the stage project; the URI carries authMechanism=MONGODB-OIDC, tls=true and retryWrites=false, no credential. The External Secrets Operator maps them to MONGO_URI and MONGO_DATABASE in the pods.

Network. The default-deny NetworkPolicy of the chart allows TCP 443 to the Firestore endpoints, reached through Private Google Access.

A password-based SCRAM user for tools that cannot use OIDC is not managed in code, so no password passes through a pipeline.

Terms you will see​

TermMeaning
Enterprise editionThe Firestore edition that offers MongoDB compatibility.
MONGODB-OIDCMongoDB authentication with a token from the platform's identity.
PITRPoint-in-time recovery over the last seven days.
Scheduled backupA daily copy kept for firestore_backup_retention_days.
roles/datastore.userThe data-plane role the application identity holds.

Where to read more​