# Mongodb cipher lock down kubernetes helm chart

**URL:** <https://forums.percona.com/t/mongodb-cipher-lock-down-kubernetes-helm-chart/34823>\
**Category:** Awards & Recognition\
**Tags:** mongodb\
**Created:** [November 6, 2024, 7:41pm UTC](https://forums.percona.com/t/mongodb-cipher-lock-down-kubernetes-helm-chart/34823 "2024-11-06T19:41:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Henry\_Smearman](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/henry_smearman/32/18339_2.png) [@Henry\_Smearman](https://forums.percona.com/u/Henry_Smearman)\
**Post date:** [November 6, 2024, 7:41pm UTC](https://forums.percona.com/t/mongodb-cipher-lock-down-kubernetes-helm-chart/34823/1 "2024-11-06T19:41:26Z")

</div>

Hello,

Im installing mongodb using percona-helm-charts-psmdb-operator-1.17.1/charts/psmdb-db/values.yaml file and want to be able to lock down my instance to only allow certain ciphers and block TLS1 and TLS1\_1. I have this working in my mongoDB helm chart but cant find where to put it in the percona helm chart. In mongo I have this under spec

spec  
additionalMongodConfig  
net  
tls  
mode: PreferTLS  
disabledProtocols: TLS1\_0,TLS1\_1  
setParameter:  
opensslCipherConfig: “TLS\_AES\_256\_GCM\_SHA384”  
opensslCIpherSuiteConfig: “TLS\_AES\_256\_GCM\_SHA384”

Will this work in the percona chart ? if so what section in the values file would I add the settings ?

thanks!

---

<div class="post-metadata">

**Author:** ![Tomislav\_Plavcic](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/tomislav_plavcic/32/9717_2.png) [@Tomislav\_Plavcic](https://forums.percona.com/u/Tomislav_Plavcic)\
**Post date:** [November 7, 2024, 9:04am UTC](https://forums.percona.com/t/mongodb-cipher-lock-down-kubernetes-helm-chart/34823/2 "2024-11-07T09:04:31Z")

</div>

Hi @Henry_Smearman !

I believe you can accomplish this by specifying `tls.mode`: [percona-helm-charts/charts/psmdb-db/values.yaml at main · percona/percona-helm-charts · GitHub](https://github.com/percona/percona-helm-charts/blob/main/charts/psmdb-db/values.yaml#L57-L58)

And for disabled protocols and other stuff you can specify it in mongodb configuration under `replsets.rs0.configuration` key: [percona-helm-charts/charts/psmdb-db/values.yaml at main · percona/percona-helm-charts · GitHub](https://github.com/percona/percona-helm-charts/blob/main/charts/psmdb-db/values.yaml#L95-L99)  
where you can specify any additional options like in the normal mongo configuration file like:

```auto
replsets:
  rs0:
    configuration: |
      net:
        tls:
          disabledProtocols: "TLS1_0,TLS1_1"
      setParameter:
        opensslCipherConfig: "TLS_AES_256_GCM_SHA384"
        opensslCIpherSuiteConfig: "TLS_AES_256_GCM_SHA384"

```

I didn’t try this above, but based on the options in the helm chart it should work.

---

<div class="post-metadata">

**Author:** ![Henry\_Smearman](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/henry_smearman/32/18339_2.png) [@Henry\_Smearman](https://forums.percona.com/u/Henry_Smearman)\
**Post date:** [November 7, 2024, 4:46pm UTC](https://forums.percona.com/t/mongodb-cipher-lock-down-kubernetes-helm-chart/34823/3 "2024-11-07T16:46:14Z")

</div>

Thanks very much, that seems to have worked
