Chapter 01 · Graph Database Foundations, Neo4j Editions, Deployment Choices, and Lab Setup

Neo4j Community, Enterprise, Aura, and Infinigraph: Capability, Responsibility, and Cost Boundaries

Choose a Neo4j deployment by required capabilities and responsibility boundaries, not by treating Community, Enterprise, Aura, Desktop, and Infinigraph as interchangeable packaging.

Beginner → Intermediate90–110 minutesEdition and deployment decision labNeo4j 2026.07.1 / 5.26.30 LTS snapshotLast reviewed: September 2026

Learning outcomes

AtlasMart’s proof of concept now works on one Community container. Procurement asks whether production should use Community, self-managed Enterprise, Aura, Neo4j Desktop, or Infinigraph. Treating those names as “free, paid, cloud, and bigger” would hide the engineering boundary: each option changes available capabilities, licensing/terms, who operates the DBMS, how failures are handled, and what evidence can be reproduced locally.

01

Distinguish Community Edition, Enterprise Edition, Neo4j Desktop Developer use, AuraDB/AuraDS, and Infinigraph by capability and responsibility.

02

Explain which Chapter 01 observations are portable across deployments and which depend on edition, tier, topology, or managed-service boundaries.

03

Recognize clustering, online backup, RBAC, multi-database administration, and property sharding as edition/tier-sensitive rather than universal Neo4j behavior.

04

Use runtime and documentation evidence without executing Enterprise-only administrative commands against Community and calling the errors “Neo4j bugs.”

05

Produce a production-selection checklist that includes licensing, operational skill, RPO/RTO, security, portability, and exit strategy.

Current edition snapshot

Community is a fully functional single-instance Neo4j edition with Cypher, ACID transactions, Bolt, and drivers. Enterprise adds production capabilities such as clustering, online backup, and role-based access control. Infinigraph is a specialized Enterprise offering with automatic property sharding and requires a separate subscription; it is not available on Aura. Neo4j Desktop includes a Developer edition license intended for individual development use on a single machine. Aura is Neo4j’s fully managed cloud service. Re-check current feature matrices and contract terms before a real purchase.

Licensing is an architecture input, not legal advice.

Neo4j’s current legal overview identifies Community Edition as GPLv3 and separates Desktop, self-managed commercial software, and Aura service terms. The lesson describes technical and operational consequences only. Your organization must review the actual agreement that governs its use.

Five names, five different boundaries

Option What it is Chapter 01 consequence Do not infer
Community Edition Open-source self-managed Neo4j suitable for a single-instance deployment Best mandatory free/local baseline; one user database plus system; users have full implied access rather than Enterprise RBAC Clustered HA, Enterprise online backup, or least-privilege roles
Enterprise Edition Commercial self-managed edition extending Community capabilities Can add clustering, online backup, RBAC, multi-database administration and other Enterprise features That Neo4j operates your OS, JVM, network, backup jobs, capacity, or upgrades for you
Neo4j Desktop Desktop client/development environment that can run local DBMS instances and connect remotely Convenient developer workflow; Developer edition offers Enterprise capabilities for development under its license That a Desktop Developer license is a production Enterprise license
Aura Fully managed Neo4j cloud platform including AuraDB and data-science offerings Neo4j operates underlying service infrastructure; application still owns data model, queries, credentials, integration, and its recovery/security responsibilities Filesystem access, arbitrary server administration, or identical self-managed commands
Infinigraph Specialized Enterprise offering for sharded property databases/large-scale graph processing Changes physical scale architecture and requires Cypher 25/current supported topology That it is ordinary Enterprise with a flag, or an Aura feature

The most important word in the table is boundary. Cypher data access can look similar across deployments while administration, topology, backup, security, observability, plugin availability, and failure ownership differ substantially. Application portability is therefore not the same as operational portability.

Community: excellent learning baseline, intentionally limited production surface

Community provides the core graph database: property graph storage, Cypher, ACID transactions, indexes/Community-supported constraints, Bolt, Browser, Cypher Shell, and official drivers. It is suitable for the course because the majority of modeling/query semantics can be learned without a commercial license. The current Cypher documentation distinguishes Community from Enterprise in multi-database and security behavior: Community has the system database and one user database, and it supports multiple users but not Enterprise role-based privilege separation; users have implied administrator-level access.

This matters for labs. Creating a second Community user does not demonstrate least privilege. Likewise, SHOW DATABASES and SHOW SERVERS belong to Enterprise administration surfaces and must not be mandatory evidence in a Community-only lab. Instead, Community evidence should use commands that exist there, such as CALL dbms.components(), SHOW CURRENT USER, relevant SHOW SETTINGS, and normal graph queries.

Cypher · Community-safe identity and setting probes
CALL dbms.components() YIELD name, versions, edition RETURN name, versions, edition;SHOW CURRENT USER;SHOW SETTINGS 'db.query.default_language' YIELD name, value RETURN name, value;

Enterprise: more capability means more operator responsibility, not less

Self-managed Enterprise is still self-managed. It adds features needed by many production systems: clustering/failover, online backup, RBAC and broader security controls, multi-database administration, and other enterprise operations. But AtlasMart still owns machine/VM/container security, supported JVMs, certificates, storage, capacity headroom, monitoring, backup schedules and copies, restore drills, patching, topology changes, and incident response unless another managed layer is contracted separately.

Enterprise Docker images use an -enterprise suffix and require license acceptance. The course does not start one automatically because the mandatory path must remain free/local and contract-neutral. If a learner has valid Enterprise/evaluation rights, these are examples of edition-specific evidence rather than steps required to complete Chapter 01:

Cypher · optional Enterprise administration evidence
SHOW DATABASES YIELD name, type, access, currentStatus, default, home RETURN *;SHOW SERVERS YIELD name, address, state, health, hosting RETURN *;SHOW ROLES;SHOW USERS;

On a standalone Enterprise instance, SHOW SERVERS still describes the server topology available to the DBMS; in a cluster it becomes much more meaningful. Later chapters teach the current cluster model, where servers and databases are decoupled and databases have primary/secondary allocations. Do not back-port older “core/read replica” mental models without checking the current release.

Aura: managed infrastructure does not outsource application correctness

Aura is Neo4j’s fully managed cloud service. A driver can interact with Aura through the same broad Cypher/Bolt application model, usually using a secure neo4j+s:// URI supplied by the service. But a managed deployment removes or changes server-level controls: you do not treat Aura like a VM where you edit neo4j.conf, browse /data, or run arbitrary local neo4j-admin commands. Aura provides service-specific console/API, snapshots, metrics/logs, and tier-dependent controls.

AtlasMart still owns query correctness, graph modeling, indexes/constraints, application secrets, driver configuration, authorization choices exposed by the tier, data retention decisions, integration failure handling, and application-level recovery plans. Neo4j’s current Aura terms also make clear that customers retain responsibilities for secure configuration and appropriate backups. “Managed” should therefore be translated into a responsibility matrix, not “no operations.”

Responsibility Self-managed Community/Enterprise Aura
OS/JVM/server process lifecycle AtlasMart operates it Service-managed
Graph model and Cypher correctness AtlasMart AtlasMart
Application credentials and secret handling AtlasMart AtlasMart
Server config/filesystem Directly available, edition/platform dependent Abstracted/restricted by service
Backup mechanism Community offline dump/load; Enterprise can add online backup Service snapshot/export mechanisms, tier dependent
Capacity/topology knobs AtlasMart provisions and operates Service/tier-specific controls
Driver retries/timeouts/idempotency AtlasMart AtlasMart

Desktop Developer use is not a shortcut around Enterprise licensing

Neo4j Desktop 2.x is a developer client/application for local DBMS instances and remote connections. Current Desktop documentation says it includes a Developer edition with Enterprise capabilities for an individual named user on a single machine for development use. That is valuable for learning Enterprise commands without building production infrastructure, but it is intentionally not equivalent to a production Enterprise license or a multi-user production deployment.

A useful course pattern is therefore: Community Docker for mandatory reproducibility; Desktop as an optional GUI/developer experience; Enterprise/evaluation only when a chapter genuinely needs the feature and the learner has appropriate rights; Aura as an optional managed comparison; deterministic simulations for topology/backup/security concepts where direct reproduction would otherwise create a paywall.

Infinigraph changes the scale architecture

Infinigraph is not a larger Aura tier. The current Operations Manual describes it as a specialized Enterprise Edition with automatic sharding for property databases and graph analytics capabilities, requiring a separate subscription. Property sharding was introduced in the 2025.12 line and is explicitly unavailable on Aura. It requires Cypher 25. That combination is a strong example of why server line, Cypher version, edition, and deployment type must be recorded together.

The course will not simulate Infinigraph by pretending several Community containers implement the same semantics. When direct reproduction is unavailable, a later lesson can use topology diagrams, deterministic partition/shard examples, query routing traces from official documentation, and explicit “cannot reproduce identically in Community” labels.

Re-run the Community lab and classify the evidence

Keep the Chapter 01 Community container running. Collect evidence, then annotate each line with “portable application behavior,” “self-managed operational evidence,” or “edition-specific behavior.”

shell · evidence that remains valid for the mandatory baseline
docker exec atlasmart-neo4j cypher-shell -a neo4j://localhost:7687 -u neo4j -p atlasmart-course-2026 "CALL dbms.components() YIELD name, versions, edition RETURN name, versions, edition;"docker exec atlasmart-neo4j cypher-shell -a neo4j://localhost:7687 -u neo4j -p atlasmart-course-2026 "SHOW CURRENT USER;"docker inspect atlasmart-neo4j --format '{{.Config.Image}}'docker inspect atlasmart-neo4j --format '{{json .Mounts}}' 

CALL dbms.components() is application/admin-visible DBMS evidence. The Docker image and mounts are deployment evidence and have no Aura equivalent. SHOW CURRENT USER exists across relevant modes, but the meaning of its role/security columns depends on edition/tier. This classification habit prevents “works in my container” from becoming an undocumented production assumption.

Deliberately wrong approaches and their repairs

Wrong approach Concrete failure Repair
Use Desktop Developer edition as the production licensing plan Development rights are mistaken for commercial production rights Review the current Desktop/software agreements and obtain the appropriate production entitlement
Assume Aura gives shell access because the driver query works the same Runbooks depend on nonexistent filesystem/config access Use Aura’s documented console/API/service operations and keep self-managed runbooks separate
Run Enterprise-only SHOW SERVERS on Community and blame syntax Edition boundary is misdiagnosed as server instability Check feature availability and edition before choosing an evidence command
Treat replication as backup A logical/operator error or correlated failure can affect replicas Design independent backup/snapshot/export plus restore drills and RPO/RTO
Treat Infinigraph as “Community plus more containers” The lab teaches a false sharding/routing mechanism Label it as a distinct licensed architecture and use official evidence/simulation unless available

Production selection checklist

AtlasMart should decide from requirements outward. Start with tolerated downtime, RPO/RTO, expected graph size and growth, query concurrency, write rate, graph algorithms, security/SSO/RBAC needs, geographic placement, compliance, observability, backup/restore, team operations skill, upgrade cadence, and cost. Then map those requirements to a deployment. Include an exit path: how data can be exported, how applications isolate driver/config differences, which features create lock-in, and how rollback works during migration.

Check your understanding

  1. Why is Community the mandatory Chapter 01 lab even if production may need Enterprise?
  2. What is the main operational difference between self-managed Enterprise and Aura?
  3. Why does adding a second user in Community not demonstrate least privilege?
  4. What makes Infinigraph more than an edition-name change?
  5. Why must licensing/terms be re-checked rather than copied permanently into a technical course?
Review the answers

1. It exposes core Neo4j/Cypher semantics using free local tooling and avoids making a paid license/service a prerequisite. Enterprise-only concepts can be added explicitly later.

2. Enterprise adds self-managed capabilities but AtlasMart still runs the infrastructure. Aura is a managed service with service-specific operational surfaces and restrictions.

3. Community supports users but not Enterprise RBAC; users have implied full administrative access, so account separation is not fine-grained privilege separation.

4. It introduces a specialized sharded property-database architecture, requires a separate subscription, is not available on Aura, and has Cypher/version requirements.

5. Agreements, product packaging, and service tiers can change independently of code. The applicable agreement depends on the actual product/use and is a legal/procurement decision, not a frozen programming fact.

Summary and next step

Community, Enterprise, Aura, Desktop, and Infinigraph share important Neo4j concepts but differ in feature surface, license/terms, topology, and who operates what. The safe course baseline remains pinned Community; paid/managed capabilities are taught with explicit boundaries rather than silently assumed.

Next, install or start the DBMS deliberately and verify Browser, Cypher Shell, authentication, runtime versions, and driver connectivity end to end.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.