MongoDB (Percona Server)
Tested with: MongoDB (Percona Server) 8.0 on Databasezy · zb CLI 0.1
MongoDB (Percona Server) is Percona’s build of MongoDB Community, with full MongoDB server compatibility. Pick it when you need MongoDB features that FerretDB does not cover.
Overview
Section titled “Overview”Each instance is a single-member Percona Server for MongoDB replica set managed by the Percona Operator for MongoDB,
with sharding turned off. High availability and read replicas are not offered yet: connections reach the instance
through one host with directConnection=true, and that host must always be the primary. It starts with a database called app and a user called app, defined in the admin authentication
database with the readWrite and dbOwner roles on app. Operator system users stay inside the cell.
Connections go through one gateway hostname, so drivers must connect directly to that host
(directConnection=true) instead of discovering the replica set’s internal member addresses. Every snippet below
does this.
| Status | Available |
|---|---|
| Category | Document |
| Versions | 8.0, 7.0 (newest is the default) |
| Protocol and port | MongoDB wire protocol on 27017 |
| Runtime | Operator-backed (Percona Operator for MongoDB) |
| Backups | mongodump (logical dump) |
| Point-in-time recovery | No |
| Pause | Scale to zero |
| Free plan | No, paid plans only |
| Licence | SSPL (Percona build) |
When to use it
Section titled “When to use it”- Existing MongoDB applications that use features FerretDB does not support, such as change streams, less common aggregation stages or MongoDB-specific index types.
- Moving off MongoDB Atlas or a self-hosted MongoDB server without changing application code.
Pick FerretDB for new document workloads: it runs on the Free plan and is Apache-2.0 licensed.
Create an instance
Section titled “Create an instance”- Open the portal and choose New instance.
- Pick MongoDB (Percona Server) and a version (8.0, 7.0).
- Choose a size and region. Secure placement is listed only after your organization has signed the BAA.
- Check the hourly price and monthly estimate, then confirm. The Connect tab fills in when the instance is ready.
zb instances create --engine mongodb --engine-version 8.0 \ --size s1 --region us-east --name mongodb-demo --wait
# Reveal the credentials once and store them in your secret managerzb instances credentials reveal mongodb-democurl -sS https://api.databasezy.com/v1/orgs/$ZB_ORG/projects/$ZB_PROJECT/instances \ -H "Authorization: Bearer $ZB_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "engine": "mongodb", "engine_version": "8.0", "size": "s1", "region": "us-east", "name": "mongodb-demo"}'
The response is 201 with the instance in status requested, or 202 when a
team approval policy applies. See the REST API reference.
Connect
Section titled “Connect”Endpoint and credentials
Section titled “Endpoint and credentials”| Host | mongo-<id>.<region>.databasezy.com, for example mongo-7f3k.us-east.databasezy.com |
|---|---|
Port 27017 | MongoDB wire protocol |
| TLS | Required on every port; plaintext is refused. Verify the server: tls=true; add the CA bundle if your driver does not use the OS trust store. |
| Credentials | Username app and a generated password, presented as SCRAM-SHA-256, authentication database admin. Shown once at creation; reveal or rotate it from the Connect tab. |
Use tls=true, authSource=admin, authMechanism=SCRAM-SHA-256 and directConnection=true. The gateway certificate is
publicly trusted; pass the CA bundle only if your driver does not read the OS trust store.
Drivers and clients
Section titled “Drivers and clients”MongoDB (Percona Server) listens on port 27017 (MongoDB wire protocol). Versions: 8.0, 7.0. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.
mongodb://app:<password>@mongo-7f3k.us-east.databasezy.com:27017/app?tls=true&tlsCAFile=databasezy-ca.pem&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=trueimport { MongoClient } from "mongodb";
const uri = `mongodb://app:${process.env.ZB_PASSWORD}@mongo-7f3k.us-east.databasezy.com:27017/app` + "?tls=true&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true";export const client = new MongoClient(uri, { tlsCAFile: "databasezy-ca.pem", // omit if the OS trust store already has the CA maxPoolSize: 10,});await client.connect();console.log(await client.db("app").command({ ping: 1 }));Tested with: MongoDB (Percona Server) 8.0 · mongodb 6.10 (Node driver)
import osfrom pymongo import MongoClient
uri = ( f"mongodb://app:{os.environ['ZB_PASSWORD']}@mongo-7f3k.us-east.databasezy.com:27017/app" "?authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true")client = MongoClient(uri, tls=True, tlsCAFile="databasezy-ca.pem", maxPoolSize=10)print(client.app.command("ping"))Tested with: MongoDB (Percona Server) 8.0 · pymongo 4.10
package main
import ( "context" "fmt" "os"
"go.mongodb.org/mongo-driver/v2/bson" "go.mongodb.org/mongo-driver/v2/mongo" "go.mongodb.org/mongo-driver/v2/mongo/options")
func main() { uri := fmt.Sprintf("mongodb://app:%s@mongo-7f3k.us-east.databasezy.com:27017/app"+ "?tls=true&tlsCAFile=databasezy-ca.pem&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true&maxPoolSize=10", os.Getenv("ZB_PASSWORD")) client, err := mongo.Connect(options.Client().ApplyURI(uri)) if err != nil { panic(err) } defer client.Disconnect(context.Background())
var res bson.M if err := client.Database("app").RunCommand(context.Background(), bson.D{{Key: "ping", Value: 1}}).Decode(&res); err != nil { panic(err) } fmt.Println(res)}Tested with: MongoDB (Percona Server) 8.0 · mongo-go-driver v2.0
use mongodb::{bson::doc, options::ClientOptions, Client};
#[tokio::main]async fn main() -> mongodb::error::Result<()> { let pw = std::env::var("ZB_PASSWORD").expect("ZB_PASSWORD"); let uri = format!( "mongodb://app:{pw}@mongo-7f3k.us-east.databasezy.com:27017/app?tls=true&tlsCAFile=databasezy-ca.pem&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true&maxPoolSize=10" ); let opts = ClientOptions::parse(uri).await?; let client = Client::with_options(opts)?; let res = client.database("app").run_command(doc! { "ping": 1 }).await?; println!("{res}"); Ok(())}Tested with: MongoDB (Percona Server) 8.0 · mongodb 3.1 (rustls)
// One-time: keytool -importcert -noprompt -alias databasezy -file databasezy-ca.pem \// -keystore databasezy-truststore.p12 -storetype PKCS12 -storepass changeit// Run with: -Djavax.net.ssl.trustStore=databasezy-truststore.p12 -Djavax.net.ssl.trustStorePassword=changeitimport com.mongodb.client.MongoClients;import org.bson.Document;
public final class Db { public static void main(String[] args) { var uri = "mongodb://app:" + System.getenv("ZB_PASSWORD") + "@mongo-7f3k.us-east.databasezy.com:27017/app?tls=true&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true&maxPoolSize=10"; try (var client = MongoClients.create(uri)) { System.out.println(client.getDatabase("app").runCommand(new Document("ping", 1))); } }}Tested with: MongoDB (Percona Server) 8.0 · mongodb-driver-sync 5.2
using MongoDB.Bson;using MongoDB.Driver;
var pw = Environment.GetEnvironmentVariable("ZB_PASSWORD");var settings = MongoClientSettings.FromConnectionString( $"mongodb://app:{pw}@mongo-7f3k.us-east.databasezy.com:27017/app?tls=true&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true");settings.MaxConnectionPoolSize = 10;// The CA is verified against the OS trust store; add databasezy-ca.pem to it if needed.var client = new MongoClient(settings);Console.WriteLine(client.GetDatabase("app").RunCommand<BsonDocument>(new BsonDocument("ping", 1)));Tested with: MongoDB (Percona Server) 8.0 · MongoDB.Driver 3.1
<?phprequire "vendor/autoload.php";
$uri = sprintf("mongodb://app:%[email protected]:27017/app?authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true", getenv("ZB_PASSWORD"));$client = new MongoDB\Client($uri, ["tls" => true, "tlsCAFile" => "databasezy-ca.pem", "maxPoolSize" => 10]);var_dump($client->selectDatabase("app")->command(["ping" => 1])->toArray()[0]);Tested with: MongoDB (Percona Server) 8.0 · mongodb/mongodb 1.20 · ext-mongodb 1.20
require "mongo"
client = Mongo::Client.new( "mongodb://app:#{ENV.fetch('ZB_PASSWORD')}@mongo-7f3k.us-east.databasezy.com:27017/app?authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true", ssl: true, ssl_ca_cert: "databasezy-ca.pem", max_pool_size: 10)puts client.database.command(ping: 1).firstTested with: MongoDB (Percona Server) 8.0 · mongo 2.21
mongosh "mongodb://app:$ZB_PASSWORD@mongo-7f3k.us-east.databasezy.com:27017/app?tls=true&authSource=admin&authMechanism=SCRAM-SHA-256&directConnection=true" --tlsCAFile databasezy-ca.pem
# orzb connect mongodb-7f3kTested with: MongoDB (Percona Server) 8.0 · mongosh 2.3
Any official MongoDB driver that supports your server version works, as do mongosh, MongoDB Compass and the database
tools (mongodump, mongorestore, mongoexport). Atlas-only connection features such as mongodb+srv:// seed lists
are not used: connect to the host and port on the Connect tab. The FerretDB connection guide
covers driver options and pooling in more depth.
See Connecting to Databasezy for the CA bundle, the IP allow-list and credential rotation, which work the same for every engine.
Migrate in
Section titled “Migrate in”| Source | How | Continuous sync | Guide status |
|---|---|---|---|
| Railway | Connection string | No | Coming soon · phase 2 |
| DigitalOcean Managed Databases | Connection string | No | Coming soon · phase 2 |
| MongoDB Atlas | Connection string | No | Available |
| Self-hosted server | Connection string, Local tools (zb migrate --from local) | No | Available |
| Local files and dumps | File upload, Local tools (zb migrate --from local) | No | Available |
| Docker container | Local tools (zb migrate --from local) | No | Available |
| Another Databasezy instance | Instance to instance | No | Coming soon · phase 2 |
MongoDB sources are copied with mongodump and mongorestore, including indexes. There is no continuous sync, so plan
a short write freeze for busy collections before cutover. Moving between FerretDB and MongoDB in either direction is an
instance-to-instance migration; see engine conversions.
How migrations work explains preflight, verification and cutover, and engine conversions covers moves between compatible engines.
Backups and restore
Section titled “Backups and restore”Backups are logical: mongodump of the replica set, taken by the backup agent and streamed to object storage. Percona
Backup for MongoDB and oplog capture are not enabled yet, so there is no point-in-time recovery; a restore returns the
data as of a scheduled or manual backup.
MongoDB (Percona Server) backups use mongodump (logical dump). They run inside the instance's namespace, stream straight to the cell's object storage and are checksummed on upload. How often they run and how long they are kept follows your plan's backup policy. A backup is always taken before a resize or a version upgrade.
Point-in-time recovery is not available for MongoDB (Percona Server). A restore returns the data as of a scheduled or manual backup. Restores create a new instance by default and leave the original untouched; an in-place restore asks you to type the instance name and takes a pre-change backup first.
zb backups create mongodb-demo --label before-release # manual snapshotzb backups list mongodb-demozb backups restore mongodb-demo <backup-id> --name mongodb-demo-restorePause and scale to zero
Section titled “Pause and scale to zero”MongoDB (Percona Server) can scale to zero. A paused instance has no running pods and bills no compute; its storage and backups are kept and billed as usual. Connections are refused until you resume it.
zb instances pause mongodb-demozb instances resume mongodb-demoSee Pause and resume for schedules, wake times and billing while paused.
Limits, versions and lifecycle
Section titled “Limits, versions and lifecycle”Versions and lifecycle
Section titled “Versions and lifecycle”- Supported versions:
8.0,7.0. New instances default to8.0; pick another at creation with --engine-version or in the portal. - Minor and patch releases are applied for you in the maintenance window, always after a pre-change backup.
- New majors are added within 60 days of the upstream release. A major reaches end of life on Databasezy six months after upstream ends support, with notices 90, 30 and 7 days ahead.
- Moving between majors is a new instance plus an instance-to-instance migration, so you can test the new version before cutting over.
Sizes and limits
Section titled “Sizes and limits”MongoDB (Percona Server) is not offered on the Free plan; it runs on the paid sizes below. The size sets the CPU, memory, storage ceiling and connection limit; the gateway refuses connections over the limit with a protocol error. Storage grows in steps up to the ceiling, and you can resize at any time.
| Size | vCPU | Memory | Max storage | Max connections | ≈ $ / month |
|---|---|---|---|---|---|
s0 | 0.25 | 1 GiB | 20 GB | 60 | $10 |
s1 | 0.5 | 2 GiB | 50 GB | 100 | $15 |
s2 | 1 | 4 GiB | 200 GB | 200 | $60 |
m2 | 2 | 8 GiB | 500 GB | 400 | $110 |
m4 | 4 | 16 GiB | 1 TB | 800 | $210 |
l8 | 8 | 32 GiB | 4 TB | 1,500 | $410 |
l16 | 16 | 64 GiB | 8 TB | 3,000 | $960 |
xl32 | 32 | 128 GiB | 16 TB | 5,000 | $1,870 |
Full details, including hourly prices and burst CPU, are in the size catalogue; plan quotas are in limits and quotas.
The size’s connection limit is enforced at the gateway; each driver keeps its own pool, so set maxPoolSize well below
it when several services share an instance. Sharding is not offered. Atlas services (Atlas Search, Vector Search,
Triggers, Data API, App Services) are not part of the server and are not available.
Licence
Section titled “Licence”Databasezy runs MongoDB (Percona Server) under the SSPL (Percona build) licence, as listed in the engine catalogue. Your data and schemas are yours whatever the server's licence; the licence governs the server software we run.
Security
Section titled “Security”- TLS on every connection. TLS 1.2 is the minimum and TLS 1.3 is preferred; plaintext is never
offered. Verify the server, not just the encryption: use
tls=true with the CA bundle. See TLS and the CA bundle. - IP allow-list. The gateway checks the client address before authentication, on every plan.
Manage it under Network → Allow-list in the portal or with
PUT /v1/orgs/{org}/instances/{id}/network. - Credentials. Generated inside the cell, shown once, never stored by the control plane. Rotate them with an overlap window so nothing breaks.
- Secure hosting. Secure placement (HIPAA-ready) is a per-instance option once your organization has signed the BAA: dedicated nodes, customer-managed keys and immutable backups. See Secure hosting and the BAA.
- Staff access. Databasezy staff cannot read your data without a grant you issue. See data confidentiality.
Is this MongoDB Atlas?
Section titled “Is this MongoDB Atlas?”No. It is the database server. Atlas products such as Atlas Search, Triggers and App Services are not included.
Why does the connection string need directConnection=true?
Section titled “Why does the connection string need directConnection=true?”The instance is a replica set, and without that option drivers try to reach each member by its internal address, which
is not reachable from outside the cell. With directConnection=true the driver uses the gateway hostname only.
Can I move from FerretDB to MongoDB later?
Section titled “Can I move from FerretDB to MongoDB later?”Yes, with an instance-to-instance migration using mongodump and mongorestore.
Can I get a replica set with automatic failover?
Section titled “Can I get a replica set with automatic failover?”Not yet. Every connection goes through one gateway host with directConnection=true, so a multi-member replica set
needs that host to follow the primary through elections, which is not built yet. Until then an instance has one member;
use backups for recovery.
Is MongoDB on the Free plan?
Section titled “Is MongoDB on the Free plan?”No. It is a paid-plan engine. FerretDB is the Free plan option for MongoDB-compatible workloads.