CloudQuery published the MongoDB destination plugin plugins-destination-mongodb-v3.2.0 on 17 September 2026. The operator visible change is Atlas Workload Identity Federation through the driver MONGODB-OIDC mechanism, added in pull request 23247. The rest of the compare against plugins-destination-mongodb-v3.1.1 is dependency pins on a stable tag.
The full release notes and downloads are on the GitHub release page. The compare range is dated 15 September 2026. GitHub published the tag two days later.
Workload identity federation on the destination spec ¶
Commit 1f03550 adds workload_identity_federation on the destination spec in plugins/destination/mongodb/client/spec/spec.go. The struct is in plugins/destination/mongodb/client/spec/workload_identity_federation.go. The field is optional and mutually exclusive with aws_credentials. Validate returns an error when both are set, before the client dials MongoDB.
When the block is present, New in plugins/destination/mongodb/client/client.go builds the credential in oidcCredential and calls SetAuth after ApplyURI. SetAuth overwrites credentials parsed from the connection string. A password left in connection_string is ignored. Drop the user and password from the URI when federation is on, so the file matches the credential the process sends.
environment is required. Allowed values are k8s, azure, and gcp. The spec comment describes k8s as a Kubernetes service account token and names EKS. azure is an Azure managed identity. gcp is a Google service account. Any other string fails validation.
token_resource is the audience configured on the Atlas deployment. Azure and GCP require it. Kubernetes rejects it. The docs example audience is api://my-audience.
username is the Azure managed identity client id. It is valid only for azure. GCP and Kubernetes reject a set username. Omit username on Azure only when the VM has a single managed identity. With several identities, set username to the client id Atlas should see. oidcCredential copies environment into the driver property ENVIRONMENT, copies token_resource into TOKEN_RESOURCE when the audience is set, and copies username onto the credential for the Azure flow. The auth mechanism is auth.MongoDBOIDC.
The spec comment requires a dedicated M10 or larger cluster running MongoDB 7.0.11 or later, with Workload Identity Federation configured for the matching identity provider. That line is documentation. The plugin ships no probe of cluster tier or server version. A smaller cluster or an older server fails at connect, with the error Atlas returns.
The pull request reports two in cluster syncs with no password in the URI. The k8s flow ran on EKS with the service account token. The gcp flow ran on GKE and read the identity token from the GCE metadata server. Unit tests cover the three environments, mutual exclusion with aws_credentials, and the JSON shape in schema.json. Those tests check validation and credential mapping. They open no connection to Atlas.
A Kubernetes destination spec in the shape the docs now describe:
kind: destination
spec:
name: mongodb
spec:
connection_string: "mongodb+srv://<cluster-host>/"
database: "my_db"
workload_identity_federation:
environment: k8s
Azure adds token_resource and may set username. GCP adds token_resource and leaves username unset. The commented fields sit in plugins/destination/mongodb/docs/_configuration.md. plugins/destination/mongodb/docs/overview.md repeats the mutual exclusion with aws_credentials and the same M10 and MongoDB 7.0.11 requirement.
A spec that still sets aws_credentials and leaves federation empty keeps the previous MONGODB-AWS path. New takes the federation branch only when that pointer is set and AWS credentials are absent. Each spec carries one of the two auth blocks. Jobs that need both mechanisms need two destination configs.
MongoDB driver, Arrow, and plugin SDK pins ¶
Writes still go through go.mongodb.org/mongo-driver/v2. #23210 moves the module to v2.8.0. #23311 moves it to v2.8.1. The OIDC path uses the driver machine flow, so this pin is the code that exchanges the workload token. The release notes stop at the version numbers.
Arrow remains the batch format on the plugin boundary. #23163 updates github.com/apache/arrow-go/v18 to v18.7.0. github.com/cloudquery/plugin-sdk/v4 goes to v4.96.2 in #23277 and to v4.96.3 in #23330. The notes list versions only. If a sync fails on batch decode or on the plugin handshake after the upgrade, those two pins are the first diff. github.com/stretchr/testify moves to v1.12.1 in #23322. That module is for tests. Write behavior stays the same.
gRPC, pytest, Go 1.26.6, and the AWS SDK ¶
#23149 is marked SECURITY and updates google.golang.org/grpc to v1.82.1. Plugin processes talk to the CloudQuery CLI over gRPC, so the pin sits on that control path. The release text names no CVE and no affected RPC.
Pytest v9.0.3 is marked SECURITY twice, in #23069 and #23114. Both lines use the same summary. Pytest stays in the test toolchain and is absent from the published destination binary.
The Go module directive moves to v1.26.5 in #23182 and then to v1.26.6 in #23344. Source builds of this tag need Go 1.26.6 or newer. A sync host that only runs the published binary can keep its existing toolchain.
aws-sdk-go-v2 is bumped nine times, from #23106 through #23349. Every line uses the same summary. The notes leave the AWS API unnamed. IAM auth into Atlas still goes through aws_credentials and that SDK. Federation is a separate branch in New. A destination that still uses IAM auth should connect and write a small batch after the upgrade.
Where to get it ¶
- Release page: GitHub release page
- Repository: cloudquery/cloudquery
- Tag:
plugins-destination-mongodb-v3.2.0