Database Manual / Self-Managed Deployments / Administration / Configuration & Maintenance

Run-time Database Configuration for Self-Managed Deployments自我管理部署的运行时数据库配置

The command line and configuration file interfaces provide MongoDB administrators with a large number of options and settings for controlling the operation of the database system. This document provides an overview of common configurations and examples of best-practice configurations for common use cases.命令行配置文件界面为MongoDB管理员提供了大量用于控制数据库系统操作的选项和设置。本文档概述了常见配置,并提供了常见用例的最佳实践配置示例。

While both interfaces provide access to the same collection of options and settings, this document primarily uses the configuration file interface.虽然这两个界面都提供了对相同选项和设置集合的访问,但本文档主要使用配置文件界面。

For package installations of MongoDB on Linux or macOS, an initialization script which uses this default configuration file is also provided. 对于Linux或macOS上MongoDB的软件包安装,还提供了一个使用此默认配置文件的初始化脚本。This initialization script can be used to start the mongod on these platforms in the following manner:此初始化脚本可用于在这些平台上以以下方式启动mongod

If you installed MongoDB using a TGZ or ZIP file, you will need to create your own configuration file. 如果您使用TGZZIP文件安装MongoDB,则需要创建自己的配置文件。A basic example configuration can be found later in this document. 本文档稍后将提供一个基本的示例配置Once you have created a configuration file, you can start a MongoDB instance with this configuration file by using either the --config or -f options to mongod. 创建配置文件后,您可以使用mongod--config-f选项使用此配置文件启动MongoDB实例。For example, on Linux:例如,在Linux上:

mongod --config /etc/mongod.conf
mongod -f /etc/mongod.conf

Modify the values in the mongod.conf file on your system to control the configuration of your database instance.修改系统上mongod.conf文件中的值,以控制数据库实例的配置。

Configure the Database配置数据库

Consider the following basic configuration:考虑以下基本配置:

processManagement:
fork: true
net:
bindIp: localhost
port: 27017
storage:
dbPath: /var/lib/mongo
systemLog:
destination: file
path: "/var/log/mongodb/mongod.log"
logAppend: true

For most standalone servers, this is a sufficient base configuration. It makes several assumptions, but consider the following explanation:对于大多数独立服务器来说,这是一个足够的基本配置。它做出了几个假设,但请考虑以下解释:

  • fork is true, which enables a daemon mode for mongod, which detaches (i.e. "forks") the MongoDB from the current session and allows you to run the database as a conventional server.true,它为mongod启用了守护进程模式,该模式将MongoDB与当前会话分离(即“分叉”),并允许您将数据库作为传统服务器运行。
  • bindIp is localhost, which forces the server to only listen for requests on the localhost IP. localhost,它强一致性务器只监听本地主机IP上的请求。Only bind to secure interfaces that the application-level systems can access with access control provided by system network filtering (i.e. "firewall").仅绑定到应用级系统可以通过系统网络筛选(即“防火墙”)提供的访问控制访问的安全接口。
  • port is 27017, which is the default MongoDB port for database instances. MongoDB can bind to any port. You can also filter access based on port using network filtering tools.27017,这是数据库实例的默认MongoDB端口。MongoDB可以绑定到任何端口。您还可以使用网络筛选工具根据端口筛选访问。

    Note

    UNIX-like systems require superuser privileges to attach processes to ports lower than 1024.类UNIX系统需要超级用户权限才能将进程连接到低于1024的端口。

  • quiet is true. This disables all but the most critical entries in output/log file, and is not recommended for production systems. true。这将禁用输出/日志文件中除最关键条目外的所有条目,不建议用于生产系统。If you do set this option, you can use setParameter to modify this setting during run time.如果设置了此选项,则可以在运行时使用setParameter修改此设置。
  • dbPath is /var/lib/mongo, which specifies where MongoDB will store its data files./var/lib/mongo,它指定MongoDB将存储其数据文件的位置。

    If you installed MongoDB on Linux using a package manager, such as yum or apt, the /etc/mongod.conf file provided with your MongoDB installation sets the following default dbPath, depending on your Linux distro:如果您使用包管理器(如yumapt)在Linux上安装了MongoDB,则随MongoDB安装提供的/etc/mongod.conf文件会根据Linux发行版设置以下默认dbPath

    Platform平台Package Manager包管理器Default 默认dbPath
    RHEL / CentOS and Amazonyum/var/lib/mongo
    SUSEzypper/var/lib/mongo
    Ubuntu and Debianapt/var/lib/mongodb
    macOSbrew/usr/local/var/mongodb

    The user account that mongod runs under will need read and write access to this directory.mongod运行的用户帐户需要对此目录具有读写权限。

  • systemLog.path is /var/log/mongodb/mongod.log which is where mongod will write its output. systemLog.path/var/log/mongodb/mongod.log,这是mongod将写入其输出的地方。If you do not set this value, mongod writes all output to standard output (e.g. stdout.)如果不设置此值,mongod会将所有输出写入标准输出(例如stdout
  • logAppend is true, which ensures that mongod does not overwrite an existing log file following the server start operation.logAppendtrue,这确保了mongod在服务器启动操作后不会覆盖现有的日志文件。

Given the default configuration, some of these values may be redundant. However, in many situations explicitly stating the configuration increases overall system intelligibility.给定默认配置,其中一些值可能是多余的。然而,在许多情况下,明确说明配置可以提高整体系统的可理解性。

Security Considerations安全注意事项

The following configuration options are useful for limiting access to a mongod instance:以下配置选项对于限制对mongod实例的访问非常有用:

net:
bindIp: localhost,10.8.0.10,192.168.4.24,/tmp/mongod.sock
security:
authorization: enabled
net.bindIp

This example provides four values to the bindIp option:此示例为bindIp选项提供了四个值:

  • localhost, the localhost interface;,本地主机接口;
  • 10.8.0.10, a private IP address typically used for local networks and VPN interfaces;,通常用于本地网络和VPN接口的私有IP地址;
  • 192.168.4.24, a private network interface typically used for local networks; and,通常用于本地网络的专用网络接口;和
  • /tmp/mongod.sock, a Unix domain socket path.,Unix域套接字路径。

Because production MongoDB instances need to be accessible from multiple database servers, it is important to bind MongoDB to multiple interfaces that are accessible from your application servers. At the same time it's important to limit these interfaces to interfaces controlled and protected at the network layer.因为生产MongoDB实例需要从多个数据库服务器访问,所以将MongoDB绑定到可以从应用服务器访问的多个接口非常重要。同时,重要的是将这些接口限制在网络层控制和保护的接口上。

security.authorization
Setting this option to true enables the authorization system within MongoDB. If enabled you will need to log in by connecting over the localhost interface for the first time to create user credentials.将此选项设置为true将启用MongoDB中的授权系统。如果启用,您将需要首次通过localhost接口连接登录以创建用户凭据。

Replication and Sharding Configuration复制和分片配置

Replication Configuration复制配置

Replica set configuration is straightforward, and only requires that the replSetName have a value that is consistent among all members of the set. Consider the following:副本集配置很简单,只需要replSetName的值在集的所有成员之间保持一致。请考虑以下几点:

replication:
replSetName: set0

Use descriptive names for sets. Once configured, use mongosh to add hosts to the replica set.为集合使用描述性名称。配置后,使用mongosh将主机添加到副本集中。

To enable authentication for the replica set using keyfiles , add the following keyFile option 要使用键文件启用副本集的身份验证,请添加以下keyFile选项[1]:

security:
keyFile: /srv/mongodb/keyfile

Setting keyFile enables authentication and specifies a keyfile for the replica set member to use when authenticating to each other.设置keyFile启用身份验证,并指定副本集成员在相互身份验证时使用的键文件。

Tip

The Replica Set Security section for information on configuring authentication with replica sets.有关使用副本集配置身份验证的信息,请参阅副本集安全部分

The Replication document for more information on replication in MongoDB and replica set configuration in general.有关MongoDB中的复制和副本集配置的更多信息,请参阅复制文档。

[1] Sharded clusters and replica sets can use X.509 for membership verification instead of keyfiles. 分片集群和副本集可以使用X.509进行成员身份验证,而不是使用键文件。For details, see X.509.有关详细信息,请参阅X.509

Sharding Configuration分片配置

Sharding requires mongod instances with different mongod configurations for the config servers and the shards. The config servers store the cluster's metadata, while the shards store the data.分片需要配置服务器和分片具有不同mongod配置的mongod实例。配置服务器存储集群的元数据,而分片存储数据。

To configure the config server mongod instances, in the configuration file, specify configsvr for the sharding.clusterRole setting.要配置配置服务器mongod实例,请在配置文件中为sharding.clusterRole设置指定configsvr

Note

Config servers must be deployed as a replica set.配置服务器必须作为副本集部署。

 sharding:
clusterRole: configsvr
net:
bindIp: 10.8.0.12
port: 27001
replication:
replSetName: csRS

To deploy config servers as a replica set, the config servers must run the WiredTiger Storage Engine. Initiate the replica set and add members.要将配置服务器部署为副本集,配置服务器必须运行WiredTiger存储引擎Initiate副本集并添加成员。

To configure the shard mongod instances, specify shardsvr for the sharding.clusterRole setting, and if running as a replica set, the replica set name:要配置分片 mongod实例,请为sharding.clusterRole设置指定shardsvr,如果作为副本集运行,则指定副本集名称:

sharding:
clusterRole: shardsvr
replication:
replSetName: shardA

If running as a replica set, initiate the shard replica set and add members.如果作为副本集运行,则initiate分片副本集并添加成员。

For the router (i.e. mongos), configure at least one mongos process with the following setting:对于路由器(即mongos),使用以下设置配置至少一个mongos进程:

sharding:
configDB: csRS/10.8.0.12:27001

You can specify additional members of the config server replica set by specifying hostnames and ports in the form of a comma separated list after the replica set name.您可以通过在副本集名称后以逗号分隔的列表形式指定主机名和端口,来指定配置服务器副本集的其他成员。

Tip

The Sharding section of the manual for more information on sharding and cluster configuration.有关分片和集群配置的更多信息,请参阅手册的分片部分。

Run Multiple Database Instances on the Same System在同一系统上运行多个数据库实例

In many cases running multiple instances of mongod on a single system is not recommended. 在许多情况下,不建议在单个系统上运行多个mongod实例。On some types of deployments [2] and for testing purposes you may need to run more than one mongod on a single system.在某些类型的部署[2]中,出于测试目的,您可能需要在单个系统上运行多个mongod

In these cases, use a base configuration for each instance, but consider the following configuration values:在这些情况下,为每个实例使用基本配置,但考虑以下配置值:

storage:
dbPath: /var/lib/mongo/db0/
processManagement:
pidFilePath: /var/lib/mongo/db0.pid

The dbPath value controls the location of the mongod instance's data directory. dbPath值控制mongod实例数据目录的位置。Ensure that each database has a distinct and well labeled data directory. 确保每个数据库都有一个不同且标记良好的数据目录。The pidFilePath controls where mongod process places it's process ID (PID) file. pidFilePath控制mongod进程将其进程ID(PID)文件放置在何处。As this tracks the specific mongod file, it is crucial that file be unique and well labeled to make it easy to start and stop these processes.由于这会跟踪特定的mongod文件,因此文件必须是唯一的并且标记良好,以便轻松启动和停止这些过程。

Create additional init scripts and/or adjust your existing MongoDB configuration and init script as needed to control these processes.根据需要创建额外的init脚本和/或调整现有的MongoDB配置和init脚本来控制这些进程。

[2] Single-tenant systems with SSD or other high performance disks may provide acceptable performance levels for multiple mongod instances. 具有SSD或其他高性能磁盘的单租户系统可以为多个mongod实例提供可接受的性能水平。Additionally, you may find that multiple databases with small working sets may function acceptably on a single system.此外,您可能会发现,具有小工作集的多个数据库可以在单个系统上正常运行。

Diagnostic Configurations诊断配置

The following configuration options control various mongod behaviors for diagnostic purposes:以下配置选项用于控制各种mongod行为以进行诊断:

  • operationProfiling.mode sets the database profiler level. 设置数据库分析器级别。The profiler is not active by default because of the possible impact on the profiler itself on performance. Unless this setting is on, queries are not profiled.默认情况下,分析器未处于活动状态,因为分析器本身可能会对性能产生影响。除非启用此设置,否则不会分析查询。
  • operationProfiling.slowOpThresholdMs configures the threshold which determines whether a query is "slow" for the purpose of the logging system and the profiler. 配置阈值,该阈值确定查询对于日志系统和分析器来说是否“缓慢”。The default value is 100 milliseconds. Set to a lower value if the logging system and the database profiler do not return useful results or set to a higher value to only log the longest running queries.默认值为100毫秒。如果日志系统和数据库分析器没有返回有用的结果,则设置为较低的值,或者设置为较高的值,仅记录运行时间最长的查询。

    Secondary members of a replica set now log oplog entries that take longer than the slow operation threshold to apply. These slow oplog messages:副本集的次要成员现在记录的oplog条目的应用时间超过了慢速操作阈值。这些缓慢的oplog消息:

    • Are logged for the secondaries in the diagnostic log.诊断日志中记录次级故障。
    • Are logged under the REPL component with the text applied op: <oplog entry> took <num>ms.REPL组件下记录,并应用文本applied op: <oplog entry> took <num>ms
    • Do not depend on the log levels (either at the system or component level)不依赖于日志级别(无论是在系统级别还是组件级别)
    • Do not depend on the profiling level.不要依赖于分析级别。
    • Are affected by slowOpSampleRate.slowOpSampleRate的影响。

    The profiler does not capture slow oplog entries.分析器不会捕获慢速oplog条目。

  • systemLog.verbosity controls the amount of logging output that mongod write to the log. 控制mongod写入日志的日志输出量。Only use this option if you are experiencing an issue that is not reflected in the normal logging level.仅当您遇到未反映在正常日志记录级别中的问题时,才使用此选项。

    You can also specify verbosity level for specific components using the systemLog.component.<name>.verbosity setting. 您还可以使用systemLog.component.<name>.verbosity设置为特定组件指定详细程度。For the available components, see component verbosity settings.有关可用组件,请参阅组件详细度设置

For more information, see also Database Profiler and MongoDB Performance.有关更多信息,请参阅数据库分析器MongoDB性能