The command line and configuration file interfaces provide MongoDB administrators with a large number of options and settings for controlling the operation of the database system. This document provides an overview of common configurations and examples of best-practice configurations for common use cases.命令行和配置文件界面为MongoDB管理员提供了大量用于控制数据库系统操作的选项和设置。本文档概述了常见配置,并提供了常见用例的最佳实践配置示例。
While both interfaces provide access to the same collection of options and settings, this document primarily uses the configuration file interface.虽然这两个界面都提供了对相同选项和设置集合的访问,但本文档主要使用配置文件界面。
If you installed MongoDB with a package manager such as如果您在Linux上使用yumorapton Linux orbrewon macOS, or with the MSI installer on Windows, a default configuration file has been provided as part of your installation:yum或apt等包管理器安装MongoDB,在macOS上使用brew安装MongoDB,或者在Windows上使用MSI安装程序安装MongoDB,则默认配置文件已作为安装的一部分提供:Platform平台Method方法Configuration File配置文件Linux apt,yum, orzypperPackage Manager/etc/mongod.confmacOS brewPackage Manager/usr/local/etc/mongod.conf(on Intel processors), or/opt/homebrew/etc/mongod.conf(on Apple M1 processors)Windows MSI Installer <install directory>\bin\mongod.cfgIf you installed MongoDB through a downloaded如果您是通过下载的TGZorZIPfile, you must create your own configuration file.TGZ或ZIP文件安装MongoDB的,则必须创建自己的配置文件。The basic example configuration is a good place to start.基本示例配置是一个很好的起点。
For package installations of MongoDB on Linux or macOS, an initialization script which uses this default configuration file is also provided. 对于Linux或macOS上MongoDB的软件包安装,还提供了一个使用此默认配置文件的初始化脚本。This initialization script can be used to start the 此初始化脚本可用于在这些平台上以以下方式启动mongod on these platforms in the following manner:mongod:
On Linux systems that use the systemd init system (the在使用systemctlcommand):systemdinit系统(systemctl命令)的Linux系统上:sudo systemctl start mongodOn Linux systems that use the SystemV init init system (the在使用SystemV init init系统(servicecommand):service命令)的Linux系统上:sudo service mongod startOn macOS, using the在macOS上,使用brewpackage manger:brew包管理器:brew services start mongodb-community@8.3
If you installed MongoDB using a 如果您使用TGZ or ZIP file, you will need to create your own configuration file. TGZ或ZIP文件安装MongoDB,则需要创建自己的配置文件。A basic example configuration can be found later in this document. 本文档稍后将提供一个基本的示例配置。Once you have created a configuration file, you can start a MongoDB instance with this configuration file by using either the 创建配置文件后,您可以使用--config or -f options to mongod. mongod的--config或-f选项使用此配置文件启动MongoDB实例。For example, on Linux:例如,在Linux上:
mongod --config /etc/mongod.conf
mongod -f /etc/mongod.conf
Modify the values in the 修改系统上mongod.conf file on your system to control the configuration of your database instance.mongod.conf文件中的值,以控制数据库实例的配置。
Configure the Database配置数据库
Consider the following basic configuration:考虑以下基本配置:
processManagement:
fork: true
net:
bindIp: localhost
port: 27017
storage:
dbPath: /var/lib/mongo
systemLog:
destination: file
path: "/var/log/mongodb/mongod.log"
logAppend: true
For most standalone servers, this is a sufficient base configuration. It makes several assumptions, but consider the following explanation:对于大多数独立服务器来说,这是一个足够的基本配置。它做出了几个假设,但请考虑以下解释:
forkis是true, which enables a daemon mode formongod, which detaches (i.e. "forks") the MongoDB from the current session and allows you to run the database as a conventional server.true,它为mongod启用了守护进程模式,该模式将MongoDB与当前会话分离(即“分叉”),并允许您将数据库作为传统服务器运行。bindIpis是localhost, which forces the server to only listen for requests on the localhost IP.localhost,它强一致性务器只监听本地主机IP上的请求。Only bind to secure interfaces that the application-level systems can access with access control provided by system network filtering (i.e. "firewall").仅绑定到应用级系统可以通过系统网络筛选(即“防火墙”)提供的访问控制访问的安全接口。portis是27017, which is the default MongoDB port for database instances. MongoDB can bind to any port. You can also filter access based on port using network filtering tools.27017,这是数据库实例的默认MongoDB端口。MongoDB可以绑定到任何端口。您还可以使用网络筛选工具根据端口筛选访问。Note
UNIX-like systems require superuser privileges to attach processes to ports lower than 1024.类UNIX系统需要超级用户权限才能将进程连接到低于1024的端口。quietis为true. This disables all but the most critical entries in output/log file, and is not recommended for production systems.true。这将禁用输出/日志文件中除最关键条目外的所有条目,不建议用于生产系统。If you do set this option, you can use如果设置了此选项,则可以在运行时使用setParameterto modify this setting during run time.setParameter修改此设置。dbPathis是/var/lib/mongo, which specifies where MongoDB will store its data files./var/lib/mongo,它指定MongoDB将存储其数据文件的位置。If you installed MongoDB on Linux using a package manager, such as如果您使用包管理器(如yumorapt, the/etc/mongod.conffile provided with your MongoDB installation sets the following defaultdbPath, depending on your Linux distro:yum或apt)在Linux上安装了MongoDB,则随MongoDB安装提供的/etc/mongod.conf文件会根据Linux发行版设置以下默认dbPath:Platform平台Package Manager包管理器Default默认dbPathRHEL / CentOS and Amazon yum/var/lib/mongoSUSE zypper/var/lib/mongoUbuntu and Debian apt/var/lib/mongodbmacOS brew/usr/local/var/mongodbThe user account thatmongodruns under will need read and write access to this directory.mongod运行的用户帐户需要对此目录具有读写权限。systemLog.pathis/var/log/mongodb/mongod.logwhich is wheremongodwill write its output.systemLog.path是/var/log/mongodb/mongod.log,这是mongod将写入其输出的地方。If you do not set this value,如果不设置此值,mongodwrites all output to standard output (e.g.stdout.)mongod会将所有输出写入标准输出(例如stdout)logAppendistrue, which ensures thatmongoddoes not overwrite an existing log file following the server start operation.logAppend为true,这确保了mongod在服务器启动操作后不会覆盖现有的日志文件。
Given the default configuration, some of these values may be redundant. However, in many situations explicitly stating the configuration increases overall system intelligibility.给定默认配置,其中一些值可能是多余的。然而,在许多情况下,明确说明配置可以提高整体系统的可理解性。
Security Considerations安全注意事项
The following configuration options are useful for limiting access to a 以下配置选项对于限制对mongod instance:mongod实例的访问非常有用:
net:
bindIp: localhost,10.8.0.10,192.168.4.24,/tmp/mongod.sock
security:
authorization: enabled
net.bindIpThis example provides four values to the此示例为bindIpoption:bindIp选项提供了四个值:localhost, the localhost interface;,本地主机接口;10.8.0.10, a private IP address typically used for local networks and VPN interfaces;,通常用于本地网络和VPN接口的私有IP地址;192.168.4.24, a private network interface typically used for local networks; and,通常用于本地网络的专用网络接口;和/tmp/mongod.sock, a Unix domain socket path.,Unix域套接字路径。
Because production MongoDB instances need to be accessible from multiple database servers, it is important to bind MongoDB to multiple interfaces that are accessible from your application servers. At the same time it's important to limit these interfaces to interfaces controlled and protected at the network layer.因为生产MongoDB实例需要从多个数据库服务器访问,所以将MongoDB绑定到可以从应用服务器访问的多个接口非常重要。同时,重要的是将这些接口限制在网络层控制和保护的接口上。security.authorizationSetting this option to将此选项设置为trueenables the authorization system within MongoDB. If enabled you will need to log in by connecting over thelocalhostinterface for the first time to create user credentials.true将启用MongoDB中的授权系统。如果启用,您将需要首次通过localhost接口连接登录以创建用户凭据。
Tip
Replication and Sharding Configuration复制和分片配置
Replication Configuration复制配置
Replica set configuration is straightforward, and only requires that the 副本集配置很简单,只需要replSetName的值在集的所有成员之间保持一致。请考虑以下几点:replSetName have a value that is consistent among all members of the set. Consider the following:
replication:
replSetName: set0
Use descriptive names for sets. Once configured, use 为集合使用描述性名称。配置后,使用mongosh to add hosts to the replica set.mongosh将主机添加到副本集中。
To enable authentication for the replica set using keyfiles , add the following 要使用键文件启用副本集的身份验证,请添加以下keyFile option keyFile选项[1]:
security:
keyFile: /srv/mongodb/keyfile
Setting 设置keyFile enables authentication and specifies a keyfile for the replica set member to use when authenticating to each other.keyFile启用身份验证,并指定副本集成员在相互身份验证时使用的键文件。
Tip
The Replica Set Security section for information on configuring authentication with replica sets.有关使用副本集配置身份验证的信息,请参阅副本集安全部分。
The Replication document for more information on replication in MongoDB and replica set configuration in general.有关MongoDB中的复制和副本集配置的更多信息,请参阅复制文档。
| [1] | |
Sharding Configuration分片配置
Sharding requires 分片需要配置服务器和分片具有不同mongod instances with different mongod configurations for the config servers and the shards. The config servers store the cluster's metadata, while the shards store the data.mongod配置的mongod实例。配置服务器存储集群的元数据,而分片存储数据。
To configure the config server 要配置配置服务器mongod instances, in the configuration file, specify configsvr for the sharding.clusterRole setting.mongod实例,请在配置文件中为sharding.clusterRole设置指定configsvr。
Note
Config servers must be deployed as a replica set.配置服务器必须作为副本集部署。
sharding:
clusterRole: configsvr
net:
bindIp: 10.8.0.12
port: 27001
replication:
replSetName: csRS
To deploy config servers as a replica set, the config servers must run the WiredTiger Storage Engine. 要将配置服务器部署为副本集,配置服务器必须运行WiredTiger存储引擎。Initiate the replica set and add members.Initiate副本集并添加成员。
To configure the shard 要配置分片 mongod instances, specify shardsvr for the sharding.clusterRole setting, and if running as a replica set, the replica set name:mongod实例,请为sharding.clusterRole设置指定shardsvr,如果作为副本集运行,则指定副本集名称:
sharding:
clusterRole: shardsvr
replication:
replSetName: shardA
If running as a replica set, 如果作为副本集运行,则initiate the shard replica set and add members.initiate分片副本集并添加成员。
For the router (i.e. 对于路由器(即mongos), configure at least one mongos process with the following setting:mongos),使用以下设置配置至少一个mongos进程:
sharding:
configDB: csRS/10.8.0.12:27001
You can specify additional members of the config server replica set by specifying hostnames and ports in the form of a comma separated list after the replica set name.您可以通过在副本集名称后以逗号分隔的列表形式指定主机名和端口,来指定配置服务器副本集的其他成员。
Run Multiple Database Instances on the Same System在同一系统上运行多个数据库实例
In many cases running multiple instances of 在许多情况下,不建议在单个系统上运行多个mongod on a single system is not recommended. mongod实例。On some types of deployments [2] and for testing purposes you may need to run more than one 在某些类型的部署[2]中,出于测试目的,您可能需要在单个系统上运行多个mongod on a single system.mongod。
In these cases, use a base configuration for each instance, but consider the following configuration values:在这些情况下,为每个实例使用基本配置,但考虑以下配置值:
storage:
dbPath: /var/lib/mongo/db0/
processManagement:
pidFilePath: /var/lib/mongo/db0.pid
The dbPath value controls the location of the mongod instance's data directory. dbPath值控制mongod实例数据目录的位置。Ensure that each database has a distinct and well labeled data directory. 确保每个数据库都有一个不同且标记良好的数据目录。The pidFilePath controls where mongod process places it's process ID (PID) file. pidFilePath控制mongod进程将其进程ID(PID)文件放置在何处。As this tracks the specific 由于这会跟踪特定的mongod file, it is crucial that file be unique and well labeled to make it easy to start and stop these processes.mongod文件,因此文件必须是唯一的并且标记良好,以便轻松启动和停止这些过程。
Create additional init scripts and/or adjust your existing MongoDB configuration and init script as needed to control these processes.根据需要创建额外的init脚本和/或调整现有的MongoDB配置和init脚本来控制这些进程。
| [2] | mongod instances. mongod实例提供可接受的性能水平。 |
Diagnostic Configurations诊断配置
The following configuration options control various 以下配置选项用于控制各种mongod behaviors for diagnostic purposes:mongod行为以进行诊断:
operationProfiling.modesets the database profiler level.设置数据库分析器级别。The profiler is not active by default because of the possible impact on the profiler itself on performance. Unless this setting is on, queries are not profiled.默认情况下,分析器未处于活动状态,因为分析器本身可能会对性能产生影响。除非启用此设置,否则不会分析查询。operationProfiling.slowOpThresholdMsconfigures the threshold which determines whether a query is "slow" for the purpose of the logging system and the profiler.配置阈值,该阈值确定查询对于日志系统和分析器来说是否“缓慢”。The default value is 100 milliseconds. Set to a lower value if the logging system and the database profiler do not return useful results or set to a higher value to only log the longest running queries.默认值为100毫秒。如果日志系统和数据库分析器没有返回有用的结果,则设置为较低的值,或者设置为较高的值,仅记录运行时间最长的查询。Secondary members of a replica set now log oplog entries that take longer than the slow operation threshold to apply. These slow oplog messages:副本集的次要成员现在记录的oplog条目的应用时间超过了慢速操作阈值。这些缓慢的oplog消息:Are logged for the secondaries in the在诊断日志中记录次级故障。diagnostic log.Are logged under the在REPLcomponent with the textapplied op: <oplog entry> took <num>ms.REPL组件下记录,并应用文本applied op: <oplog entry> took <num>ms。Do not depend on the log levels (either at the system or component level)不依赖于日志级别(无论是在系统级别还是组件级别)Do not depend on the profiling level.不要依赖于分析级别。Are affected by受slowOpSampleRate.slowOpSampleRate的影响。
The profiler does not capture slow oplog entries.分析器不会捕获慢速oplog条目。systemLog.verbositycontrols the amount of logging output that控制mongodwrite to the log.mongod写入日志的日志输出量。Only use this option if you are experiencing an issue that is not reflected in the normal logging level.仅当您遇到未反映在正常日志记录级别中的问题时,才使用此选项。You can also specify verbosity level for specific components using the您还可以使用systemLog.component.<name>.verbositysetting.systemLog.component.<name>.verbosity设置为特定组件指定详细程度。For the available components, see有关可用组件,请参阅组件详细度设置。component verbosity settings.
For more information, see also Database Profiler and MongoDB Performance.有关更多信息,请参阅数据库分析器和MongoDB性能。