Firestore with MongoDB compatibility
Firestore with MongoDB compatibility is Firestore's Enterprise edition answering the MongoDB wire protocol, so MongoDB drivers and tools work against a serverless, replicated Google database. The GCP Web App Blueprint stores the application's documents there, one database per stage, and the application signs in with its workload identity instead of a password.
What it does
A Firestore Enterprise database with MongoDB-compatible data access accepts MongoDB drivers on port 443 over TLS. It is serverless: there is no instance to size, and storage and operations are billed as used. A regional database is replicated across zones of its region. Point-in-time recovery (PITR) keeps seven days of versions to read or restore from; scheduled backups keep daily copies for a retention period; delete protection refuses deletion of the database. Authentication can use MONGODB-OIDC, where the client presents a Google token and Firestore IAM decides access.
How BuiltForProd uses it
resource "google_firestore_database" "mongo" {
project = var.project_id
name = "${var.name_prefix}-mongo"
location_id = var.gcp_region
type = "FIRESTORE_NATIVE" # required for the Enterprise edition
database_edition = "ENTERPRISE"
mongodb_compatible_data_access_mode = "DATA_ACCESS_MODE_ENABLED"
point_in_time_recovery_enablement = var.pitr ? "POINT_IN_TIME_RECOVERY_ENABLED" : "POINT_IN_TIME_RECOVERY_DISABLED"
delete_protection_state = var.delete_protection ? "DELETE_PROTECTION_ENABLED" : "DELETE_PROTECTION_DISABLED"
# With delete protection the database also outlives a destroy of this unit (ABANDON).
deletion_policy = var.delete_protection ? "ABANDON" : "DELETE"
}
resource "google_firestore_backup_schedule" "daily" {
count = var.backup_retention_days > 0 ? 1 : 0
project = var.project_id
database = google_firestore_database.mongo.name
retention = "${var.backup_retention_days * 86400}s"
daily_recurrence {}
}
The firestore unit creates <prefix>-mongo (for example acme-usw1-prd-mongo) in the stage region. Per stage:
| Stage | firestore_pitr | firestore_backup_retention_days | firestore_delete_protection |
|---|---|---|---|
| dev | off | 0 (no backups) | off |
| staging | on (7 days) | 0 | off |
| prod | on (7 days) | 35, daily | on |
With delete protection on, the database also survives a destroy of the unit: OpenTofu abandons it instead of deleting it. PITR is billed as storage and backups as backup storage; at most 98 days of retention are allowed.
No password. The application's Kubernetes service account is bound through Workload Identity Federation for GKE, directly as an IAM principal, to roles/datastore.user on the stage project (app-namespace unit). The application authenticates with MONGODB-OIDC: its driver presents the pod's access token. Nothing secret is stored in state or in the cluster.
Connection values. The unit writes mongo--host, mongo--uri and mongo--database to Secret Manager in the stage project; the URI carries authMechanism=MONGODB-OIDC, tls=true and retryWrites=false, no credential. The External Secrets Operator maps them to MONGO_URI and MONGO_DATABASE in the pods.
Network. The default-deny NetworkPolicy of the chart allows TCP 443 to the Firestore endpoints, reached through Private Google Access.
A password-based SCRAM user for tools that cannot use OIDC is not managed in code, so no password passes through a pipeline.
Terms you will see
| Term | Meaning |
|---|---|
| Enterprise edition | The Firestore edition that offers MongoDB compatibility. |
| MONGODB-OIDC | MongoDB authentication with a token from the platform's identity. |
| PITR | Point-in-time recovery over the last seven days. |
| Scheduled backup | A daily copy kept for firestore_backup_retention_days. |
roles/datastore.user | The data-plane role the application identity holds. |
Where to read more
- GCP Web App Blueprint overview for the data stores.
- Memorystore for Valkey for the cache beside it.
- Recoverable for backup and recovery across the platform.