Skip to content

feature/implement-docdbflavor-and-tls-support - #12

Merged
cedricve merged 1 commit into
mainfrom
feature/implement-docdbflavor-and-tls-support
Aug 11, 2026
Merged

cedricve merged 1 commit into
mainfrom
feature/implement-docdbflavor-and-tls-support

Conversation

@cedricve

@cedricve cedricve commented Aug 11, 2026 •

Copy link
Copy Markdown
Member

Description

Summary

Add first-class DocumentDB support and configurable TLS handling to the MongoDB client configuration layer.

Motivation

Supporting both MongoDB and AWS DocumentDB currently requires callers to manually remember provider-specific behavior such as disabling retryable writes, avoiding MongoDB Stable API usage, and selecting compatible authentication mechanisms. These differences are easy to miss and can lead to runtime connection failures or inconsistent configuration across services.

This change centralizes those compatibility rules behind a new Flavor option, allowing the library to automatically apply the correct defaults for each backend. As a result, consumers get a safer and more consistent integration experience with less duplicated setup code.

The PR also strengthens TLS support by adding explicit TLS configuration, CA bundle loading, TLS 1.2 enforcement, and optional verification bypass for local testing scenarios. This improves security defaults while making secure DocumentDB deployments easier to configure correctly.

Improvements

  • Adds flavor-aware behavior for MongoDB and AWS DocumentDB
    • Disables Stable API for DocumentDB
    • Forces retryable writes off for DocumentDB
    • Applies backend-specific authentication defaults
  • Introduces TLS configuration support with:
    • TLS 1.2+ enforcement
    • Custom CA bundle loading
    • Optional insecure verification mode for local/test environments
  • Clarifies timeout handling by standardizing values as milliseconds
  • Refactors client option construction into reusable builders, improving maintainability and testability
  • Expands automated test coverage for:
    • Flavor normalization and validation
    • Retry write behavior
    • Stable API configuration
    • Authentication defaults
    • TLS configuration and certificate validation
  • Updates documentation and examples to reflect the new configuration model and secure deployment recommendations

Add flavor-aware MongoDB and DocumentDB client configuration, including Stable API, retry-write, and authentication defaults. Add TLS 1.2+ support with custom CA bundles and verification controls, plus documentation and tests.
@codecov

codecov Bot commented Aug 11, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.00000% with 8 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
pkg/database/mongodb.go 80.00% 4 Missing and 4 partials ⚠️

📢 Thoughts on this report? Let us know!

@cedricve
cedricve merged commit 4e6d4d9 into main Aug 11, 2026
6 checks passed
@cedricve
cedricve deleted the feature/implement-docdbflavor-and-tls-support branch August 11, 2026 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant