---
title: "How to install MongoDB on an Ubuntu VPS with authentication | StreetHosting"
description: "Install MongoDB 8.0 from the official repository on Ubuntu 24.04, enable authentication, create a user per database and close port 27017 with bindIp and UFW."
url: "https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps"
type: "page"
language: "en-US"
---

VPS · 10 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# MongoDB on an Ubuntu VPS: official install and secure access

Fresh out of the box, MongoDB accepts local connections with no password, and a misconfigured bindIp leaves it wide open to the internet. Here is how to install 8.0 from the official repository, enable authentication and give each application a user that can only reach its own database.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Databases](https://streethosting.com.br/en/guides/topics/databases)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20install%20MongoDB%20on%20an%20Ubuntu%20VPS%20with%20authentication&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps "Share on LinkedIn") [](https://wa.me/?text=How%20to%20install%20MongoDB%20on%20an%20Ubuntu%20VPS%20with%20authentication%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-mongodb-ubuntu-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps.md)

In this guide 8 sections

* [Requirements and the AVX check](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#requisitos)
* [Install from the official repository](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#instalar)
* [Create the admin user](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-admin)
* [Enable authentication](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#autenticacao)
* [One user per database for the application](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-app)
* [bindIp, firewall and remote access](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#acesso-remoto)
* [Common errors and maintenance](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#erros-comuns)
* [Which VPS to use for MongoDB](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#onde-rodar)

Quick answer

To **install MongoDB on an Ubuntu VPS**, use the official `mongodb-org` repository (version 8.0 on Ubuntu 24.04), create an admin user, enable `security.authorization` in `/etc/mongod.conf` and keep `bindIp` at 127.0.0.1. Each application connects with its own user, with permissions only on its own database. Before anything else, confirm that the VPS CPU exposes the AVX instruction set, without which MongoDB will not start.

## Requirements and the AVX check[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#requisitos)

The official repository has MongoDB 8.0 packages for Ubuntu 24.04 (noble), 22.04 (jammy) and 20.04, on `x86_64` and ARM64. This guide uses 24.04; on 22.04 just swap `noble` for `jammy` in the repository line.

The requirement that catches most people off guard is the CPU. Since version 5.0, MongoDB binaries are compiled assuming the AVX instruction set. The official documentation calls for an Intel Core from the Haswell generation or newer and, on AMD, Bulldozer or newer. On a VPS, though, what matters is not just the physical processor: it is the instruction set the hypervisor passes through to the virtual machine. That is why the check is done inside the VPS itself:

`grep -o -w avx /proc/cpuinfo | sort -u`

If the command prints `avx`, you can move on. If it prints nothing, mongod will die on startup with the error _Illegal instruction_, and no configuration fixes that. On StreetHosting VPS, both lines qualify: the Ryzen 9 9950X (Zen 5 architecture) and the Xeon E5-2680 v4 (Broadwell, which came after Haswell) have AVX and AVX2. Run the command anyway: it is the way to confirm what your VM actually sees.

The second requirement is memory. MongoDB uses the WiredTiger engine, which by default reserves an internal cache equal to the larger of 256 MB and half of the RAM left after subtracting 1 GB. The rest of the memory does not sit idle: the operating system uses it as a file cache, which MongoDB also benefits from. The table shows what that means at each VPS size.

| VPS RAM | Default WiredTiger cache | Suggested use                                          |
| ------- | ------------------------ | ------------------------------------------------------ |
| 2 GB    | about 0.5 GB             | Tests and small bots                                   |
| 4 GB    | about 1.5 GB             | Personal project or MVP with the application alongside |
| 8 GB    | about 3.5 GB             | Production with a database of a few GB                 |
| 16 GB   | about 7.5 GB             | Larger database or a VPS dedicated to MongoDB          |

For disk, NVMe makes a real difference for databases because every acknowledged write goes through the journal. The documentation recommends XFS for WiredTiger data; on a VPS the root disk usually comes as ext4, which works fine for small and medium projects. The difference between storage types is covered in [HDD, SSD and NVMe on a server](https://streethosting.com.br/en/guides/infrastructure/hdd-vs-ssd-vs-nvme).

## Install from the official repository[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#instalar)

Ubuntu does not package current MongoDB. Old tutorials tell you to install the system's own `mongodb` package, which is not maintained by MongoDB and does not even exist in recent releases. The right path is the `mongodb-org` repository:

`sudo apt update sudo apt install -y gnupg curl curl -fsSL https://pgp.mongodb.com/server-8.0.asc | sudo gpg -o /usr/share/keyrings/mongodb-server-8.0.gpg --dearmor echo "deb [ arch=amd64,arm64 signed-by=/usr/share/keyrings/mongodb-server-8.0.gpg ] https://repo.mongodb.org/apt/ubuntu noble/mongodb-org/8.0 multiverse" | sudo tee /etc/apt/sources.list.d/mongodb-org-8.0.list sudo apt update sudo apt install -y mongodb-org sudo systemctl enable --now mongod sudo systemctl status mongod`

What each part does: the GPG key lets apt verify that the packages really came from MongoDB, and `signed-by` restricts that key to this repository, so it does not become valid for the whole system. The `mongodb-org` metapackage brings the `mongod` server, the `mongosh` shell and the backup tools, such as `mongodump`. The service does not start on its own after installation, which is why `enable --now` turns it on right away and on every boot.

Test the local connection with `mongosh --eval "db.runCommand({ ping: 1 })"`. A response with `ok: 1` confirms the server is up. The paths you will use from here on are the configuration file `/etc/mongod.conf`, the data in `/var/lib/mongodb` and the log in `/var/log/mongodb/mongod.log`.

The repository line pins the 8.0 series. `apt upgrade` brings fixes within that series but never jumps to another major version unless you deliberately change the repository. That prevents a surprise database upgrade during a routine update.

## Create the admin user[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-admin)

At this point MongoDB accepts any local connection with no password. The first step is to create an administrator, while authentication is still off. Enter the shell with `mongosh` and run:

`use admin db.createUser({ user: "admin", pwd: passwordPrompt(), roles: [ { role: "userAdminAnyDatabase", db: "admin" }, { role: "readWriteAnyDatabase", db: "admin" } ] })`

`passwordPrompt()` asks for the password interactively, so it never lands in the mongosh history. The `userAdminAnyDatabase` role allows creating and removing users in any database, and `readWriteAnyDatabase` allows reading and writing data. There is a `root` role with full power, but it is rarely needed in day to day work.

## Enable authentication[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#autenticacao)

Creating the user is not enough: without the authorization option, MongoDB keeps accepting anonymous connections. Open the file with `sudo nano /etc/mongod.conf` and set the network and security blocks like this:

`net: port: 27017 bindIp: 127.0.0.1 security: authorization: enabled`

The file is YAML: indentation uses two spaces, never a tab, and the `security` block usually ships commented out with `#` on install. One space too many or too few keeps the service from starting. Restart and test:

`sudo systemctl restart mongod mongosh --eval "db.adminCommand({ listDatabases: 1 })" mongosh -u admin --authenticationDatabase admin`

The second command has to fail with an authentication error: that is the proof that anonymous access is gone. The third one asks for the password and opens the shell as administrator. The `--authenticationDatabase` parameter tells which database the user was created in, and it shows up again in the application's connection.

## One user per database for the application[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-app)

The application should never use the administrator. If the code leaks or suffers an injection, the damage stays limited to what the application user can do. Logged in as admin, create the database and its user:

`use loja db.createUser({ user: "loja_app", pwd: passwordPrompt(), roles: [ { role: "readWrite", db: "loja" } ] })`

The _loja_ database actually comes into existence when the first collection receives data. The application connection string looks like this:

`mongodb://loja_app:SENHA@127.0.0.1:27017/loja?authSource=loja`

`authSource` points to the database where the user was created. If you created the user in _admin_ and forgot this parameter, the driver tries to authenticate against the wrong database and returns _Authentication failed_. Store the string in a `.env` file with restricted permissions, outside the Git repository. An example from a real project is in [connecting a Discord bot to a database](https://streethosting.com.br/en/guides/discord-bots/connect-discord-bot-to-database).

| Role                 | What it allows                                             | When to use it                             |
| -------------------- | ---------------------------------------------------------- | ------------------------------------------ |
| read                 | Read data from one database                                | Reports, metrics dashboards, BI reads      |
| readWrite            | Read and write data, create collections and indexes        | Application user                           |
| dbAdmin              | Administrative tasks on the database, without reading data | Index maintenance and statistics           |
| backup               | Read everything mongodump needs                            | Dedicated user for scheduled backups       |
| userAdminAnyDatabase | Manage users in any database                               | Human administrator, never the application |

Passwords containing `@`, `:` or `/` break the connection string unless they are encoded. To avoid the problem, generate passwords with only letters and digits using `openssl rand -hex 24`.

## bindIp, firewall and remote access[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#acesso-remoto)

`bindIp` is the list of addresses on the VPS itself that MongoDB listens on. It is not an allowlist of clients, and that is the most common mistake: putting the IP of your home computer or of the application server there, which makes the service fail to start. With `127.0.0.1`, only programs running on the same VPS can connect. There are three typical situations.

### Application on the same VPS[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#mesma-vps)

Keep `bindIp: 127.0.0.1` and do not open any port. It is the safest scenario and also the one with the lowest latency between application and database.

### Managing it from Compass[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#compass)

Instead of opening the port, create an SSH tunnel from your computer and point Compass at the local address:

`ssh -N -L 27017:127.0.0.1:27017 usuario@IP_DA_VPS # in Compass: mongodb://admin@127.0.0.1:27017/?authSource=admin`

### Application on another server[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#outro-servidor)

Add to `bindIp` an address that belongs to the database VPS itself, preferably the one on a VPN interface, and open the port in the firewall only for the IP of the application server:

`# /etc/mongod.conf net: port: 27017 bindIp: 127.0.0.1,10.8.0.1 # firewall sudo ufw allow from IP_DO_SERVIDOR_APP to any port 27017 proto tcp sudo ufw status numbered`

In the example, 10.8.0.1 is the address of the VPS inside a [WireGuard](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps) tunnel, which keeps database traffic encrypted between the two servers. The firewall rules follow the same reasoning as the [UFW on Ubuntu VPS guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps).

Never use `bindIpAll: true` or `0.0.0.0` without a firewall. Bots scan port 27017 around the clock, and open MongoDB databases have already been wiped en masse by campaigns that leave behind nothing but a ransom note. If you run MongoDB in Docker, publish the port as `127.0.0.1:27017:27017`, because ports published by Docker bypass the UFW rules.

## Common errors and maintenance[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#erros-comuns)

* **Service dies with status=4/ILL:** no AVX in the VM. Check with the command from the first section. No configuration tweak works around it.
* **Service will not start after editing mongod.conf:** almost always YAML indentation. Find the cause with `sudo journalctl -u mongod -n 50` and in `/var/log/mongodb/mongod.log`.
* **Permission failure after running mongod by hand:** running `sudo mongod` creates files owned by root inside the data directory, and the service, which runs as the _mongodb_ user, can no longer open them. Fix it with `sudo chown -R mongodb:mongodb /var/lib/mongodb /var/log/mongodb`.
* **ORM requires a replica set:** transactions spanning several documents, used by tools like Prisma, only work on a replica set. You can turn the single server into a replica set with one node by setting `replSetName` in the file and running `rs.initiate()` in the shell. With authentication on, MongoDB also requires a `keyFile` for internal authentication; follow the official tutorial on replica sets with access control.
* **Warnings when opening mongosh:** messages about Transparent Huge Pages and system limits are performance recommendations, not errors. In the 8.0 series the guidance on THP changed compared to older versions, so check the production notes page before copying tweaks from older tutorials.

For backups, create a user with only the _backup_ role in the admin database and schedule `mongodump` with compressed output:

`# /root/.mongodump.yaml (chmod 600), holds only the password password: SENHA_DO_USUARIO_BACKUP # command for cron mongodump --username backup --authenticationDatabase admin --config /root/.mongodump.yaml --gzip --archive=/var/backups/mongodb/mongo_$(date +%F).archive.gz`

The config file keeps the password off the command line, where it would show up in the process list. Create the `/var/backups/mongodb` directory first, schedule it with cron and ship the copies off the VPS using the method from the [automated backup with restic](https://streethosting.com.br/en/guides/vps/vps-backup-restic-cron) guide. Restoring uses `mongorestore` with a user that holds the _restore_ role. Test a restore into a separate database every now and then: a backup that has never been restored is just a hope.

## Which VPS to use for MongoDB[](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#onde-rodar)

MongoDB is hungry for RAM, because everything that fits in the WiredTiger cache and the OS cache is served without touching the disk, and it is sensitive to disk latency on writes. On a [StreetHosting VPS](https://streethosting.com.br/en/vps) every plan runs on NVMe, sits in São Paulo, includes Anti-DDoS and gives root access on KVM virtualization. Both CPU lines have AVX.

| Use                                                      | Suggested plan                              | Monthly price |
| -------------------------------------------------------- | ------------------------------------------- | ------------- |
| Bot or MVP with a small dataset                          | Xeon 3 vCPU, 4 GB DDR4, 40 GB NVMe          | R$ 43.00      |
| Production application with the database on the same VPS | Xeon 6 vCPU, 8 GB DDR4, 80 GB NVMe          | R$ 77.00      |
| Dataset of a few dozen GB                                | Xeon 9 vCPU, 16 GB DDR4, 160 GB NVMe        | R$ 145.00     |
| Heavy aggregations and low latency per query             | Ryzen 9 9950X 4 vCPU, 8 GB DDR5, 80 GB NVMe | R$ 118.00     |

The [Xeon VPS](https://streethosting.com.br/en/vps/xeon) line delivers more RAM and vCPU per real spent, which suits databases. The Ryzen 9 9950X, with DDR5 and up to 5.7 GHz, pays off when queries do a lot of processing, such as long aggregations. If the database grows, the upgrade is done from the control panel, charges only the prorated difference for the cycle and requires rebooting the VM. After the reboot the default WiredTiger cache is recalculated for the new RAM, unless you have pinned `cacheSizeGB` in the file. To compare MongoDB with other databases when sizing, see [how to choose a VPS for a database](https://streethosting.com.br/en/guides/vps/choose-vps-for-database).

In this guide

* [Requirements and the AVX check](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#requisitos)
* [Install from the official repository](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#instalar)
* [Create the admin user](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-admin)
* [Enable authentication](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#autenticacao)
* [One user per database for the application](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#usuario-app)
* [bindIp, firewall and remote access](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#acesso-remoto)
* [Common errors and maintenance](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#erros-comuns)
* [Which VPS to use for MongoDB](https://streethosting.com.br/en/guides/vps/install-mongodb-ubuntu-vps#onde-rodar)

## Frequently asked questions

Which MongoDB version should I install on Ubuntu 24.04?

Use MongoDB 8.0 Community from MongoDB's official repository, which has packages for Ubuntu 24.04 (noble) and 22.04 (jammy). Avoid the mongodb package mentioned in old tutorials: it is not maintained by MongoDB and does not exist in current Ubuntu releases.

Why does MongoDB fail to start with Illegal instruction?

Since version 5.0 MongoDB requires a CPU with the AVX instruction set. If the processor or the virtualization layer does not expose AVX to the VM, mongod exits right at startup. Check with grep avx /proc/cpuinfo before installing.

Does MongoDB come with a password after installation?

No. By default it accepts local connections with no authentication. Create an admin user, enable security.authorization in /etc/mongod.conf and restart the service so that every connection requires a username and password.

How do I access MongoDB on the VPS from Compass without opening port 27017?

Use an SSH tunnel: ssh -N -L 27017:127.0.0.1:27017 usuario@IP\_DA\_VPS and point Compass at 127.0.0.1:27017 on your computer. The connection travels encrypted over SSH and the database port stays closed to the internet.

How much RAM does MongoDB need on a VPS?

The WiredTiger cache uses by default half of the RAM left after subtracting 1 GB, and the rest serves the OS file cache and the application. For small projects, 4 GB works; for production with the database and the application on the same VPS, 8 GB gives a comfortable margin.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon) [See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Intermediate How to choose a VPS for a database: RAM, CPU and NVMe A slow database is rarely fixed with more vCPUs: almost always it is short on RAM for the hot data or stuck on disk latency. Learn how to measure what your database actually consumes and pick the plan by the right number. 9 min Read guide](https://streethosting.com.br/en/guides/vps/choose-vps-for-database) [VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) [Discord bots Intermediate How to connect a Discord bot to a database Without a database, the bot forgets everything on restart. Connecting to a database like MongoDB gives levels, economy and settings persistent memory. See a secure connection and basic modeling. 3 min Read guide](https://streethosting.com.br/en/guides/discord-bots/connect-discord-bot-to-database)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
