Chapter 15 · Security: Authentication, RBAC, Privileges, TLS, Secrets, and Least Privilege

Secrets Management, Rotation, Driver Credentials, Audit Evidence, and Incident Response

Treat AtlasMart credentials, tokens, TLS keys and admin secrets as rotating capabilities with controlled delivery, audit evidence and tested incident response.

Advanced190–250 minutesSecrets rotation and incident-response labNeo4j 2026.07.1 Community baseline · Cypher 25Enterprise/Aura RBAC clearly separatedPython driver 6.3.0Last reviewed: September 2026

Learning outcomes

AtlasMart rotates a database password and every application instance goes down because the password was copied into three repositories, a Dockerfile, a CI variable and an old runbook. Secret management is not “where do we put the password?”; it is a lifecycle with issuance, constrained delivery, use, rotation, revocation, evidence and recovery.

01

Keep Neo4j passwords/tokens/private keys out of source, images, logs and test snapshots.

02

Rotate native credentials and driver authentication without coupling secret values to code.

03

Use driver auth-management APIs appropriately for rotating token-based credentials.

04

Distinguish Community log evidence from Enterprise security/query logging and Aura-managed evidence.

05

Build an incident-response sequence for credential leakage, procedure abuse and backup/admin-path compromise.

Chapter 15 baseline · reviewed 9 September 2026

The continuity lab remains Neo4j Community 2026.07.1, database neo4j, explicit CYPHER 25 where language behavior matters, container atlasmart-neo4j, loopback Bolt bolt://127.0.0.1:7687, synthetic credential neo4j/atlasmart-course-2026, official Python driver neo4j 6.3.0, and no mandatory plugin. Neo4j 5.26.30 is the LTS comparison line. For TLS changes, this chapter deliberately uses a second disposable container atlasmart-neo4j-secure so earlier labs are not disrupted.

Edition boundary that changes the security design

Current Community Edition supports native users but has no roles; every Community user has implied administrator privileges. Fine-grained RBAC, built-in/custom roles, graph/database/procedure privileges, external auth-provider integration, security/query logs and related enterprise authorization controls are Enterprise/Aura-tier features. Mandatory Community exercises therefore prove authentication, parameterization, TLS, credential rotation and application-layer authorization, while RBAC denial examples are explicitly marked licensed/deterministic rather than presented as Community output.

Safety boundary

All credentials, certificates and attacks in this chapter are synthetic and disposable. Never paste production passwords/private keys into source control, do not disable certificate verification to make a production connection work, and do not broaden procedure/plugin privileges merely to get a demo running.

Reproducible AtlasMart setup

PowerShell · continuity environment
$env:NEO4J_URI='bolt://127.0.0.1:7687'$env:NEO4J_USER='neo4j'$env:NEO4J_PASSWORD='atlasmart-course-2026'$env:NEO4J_DATABASE='neo4j'py -3 -m venv .venv.\.venv\Scripts\Activate.ps1python -m pip install --upgrade pippython -m pip install neo4j==6.3.0
Cypher · stable security fixture
CYPHER 25CREATE CONSTRAINT customer_id IF NOT EXISTSFOR (c:Customer) REQUIRE c.customerId IS UNIQUE;CREATE CONSTRAINT product_id IF NOT EXISTSFOR (p:Product) REQUIRE p.productId IS UNIQUE;CREATE CONSTRAINT order_id IF NOT EXISTSFOR (o:Order) REQUIRE o.orderId IS UNIQUE;MERGE (c:Customer {customerId:'C-1001'})SET c.name='Mina Rahimi', c.tier='GOLD', c.tenantId='TENANT-A'MERGE (p:Product {productId:'P-1001'})SET p.name='Trail Camera', p.category='Cameras', p.price=129.90MERGE (o:Order {orderId:'O-5001'})SET o.status='PAID', o.tenantId='TENANT-A', o.orderedAt=datetime('2026-09-08T16:30:00Z')MERGE (c)-[:PLACED]->(o)MERGE (o)-[r:CONTAINS]->(p)SET r.quantity=1, r.unitPrice=129.90;

These are course-only credentials and synthetic records. The fixture deliberately includes tenantId because authorization mistakes often appear when a graph traversal crosses a tenant boundary even though authentication succeeded.

1. Inventory every secret-bearing surface

Surface Secret/risk Control
application runtime DB password/token platform secret store, least-readable process identity
CI/CD deployment credential scoped secret, protected environment, no echo
container image ENV baked at build time never bake production secret; inject at runtime
logs/traces URI/headers/query params redaction; parameterize; never log auth token
TLS directory server private key read-only mount/file ACL; separate from public cert
backup/admin tooling backup keys/admin password/cloud tokens separate operational identity and encrypted storage
developer laptops copied production env files avoid distribution; short-lived/SSO access where available

2. Rotate a native password safely

Cypher · administrative rotation with a parameter
ALTER USER atlasmart_serviceSET PASSWORD $newPasswordCHANGE NOT REQUIRED;
PowerShell · application receives secret through environment
$env:NEO4J_URI='neo4j+s://db.example.com:7687'$env:NEO4J_USER='atlasmart_service'$env:NEO4J_PASSWORD=(Get-Content -Raw .\run\secrets\neo4j_password).Trim()python .\app.py

In a real orchestrator, the file would be a managed secret mount, not a repository file. Rotation order depends on the authentication mechanism: avoid a window where all clients still use the retired secret, and verify new sessions before revoking old access when dual-token/provider mechanisms permit it.

3. Rotating token credentials in the Python driver

Python · auth manager pattern
from neo4j import GraphDatabasefrom neo4j.auth_management import AuthManagers, ExpiringAuthimport timedef get_token():    token = fetch_token_from_identity_provider()    return ExpiringAuth(token).expires_in(55)auth_manager = AuthManagers.bearer(get_token)driver = GraphDatabase.driver(    "neo4j+s://db.example.com:7687",    auth=auth_manager,)

The auth manager supports credentials expected to rotate, such as SSO bearer tokens. It does not magically make long external side effects idempotent or repair authorization. The provider callback itself is privileged code: protect its client credentials and failure behavior.

4. Wrong patterns and concrete failure

Wrong pattern Concrete failure Repair
password in Git history/forks/cache preserve leak revoke/rotate, scrub exposure where appropriate, secret manager
password in Dockerfile ENV recoverable from image/layers/metadata runtime secret injection
log complete driver URI/auth object credential exfiltration through logs structured redaction and safe fields only
same admin secret for app + backup + humans one leak crosses every boundary separate scoped identities and duties
rotate only in secret store long-running process keeps old credential indefinitely document reload/restart/auth-manager behavior and verify
assume timeout means password change failed ambiguous operation may have completed read back state/login test; do not blindly repeat destructive admin operations

5. Evidence: what can you actually audit?

Evidence Community Enterprise/Aura note
SHOW USERS/SHOW CURRENT USER available user-state evidence Enterprise adds roles/metadata/provider features
general/debug/service logs available depending packaging/config not a complete security audit trail
security.log not an Enterprise-style security log in Community Enterprise security-event log
query.log Enterprise feature threshold/verbose query evidence; protect sensitive parameters/log access
Aura audit/console evidence managed-service specific use tier/console audit capabilities, not self-managed file assumptions
application auth/authorization audit application responsibility correlate subject, action, resource, decision, request id without logging secret

Audit data is itself sensitive. Protect log access, retention and export paths; avoid DEBUG token/JWT claim logging in production unless a short troubleshooting window explicitly requires it.

6. Incident-response mini playbook

Phase Action Verification
Detect identify leaked credential/key/procedure path and affected identities scope evidence, timestamps, hosts/clients
Contain revoke/rotate credential; restrict network/procedure access old credential fails, approved client still works
Eradicate remove secret from source/image/log pipeline and fix root cause secret scanners/builds/config review clean
Recover redeploy/reload clients, restore required service read/write invariants and TLS/auth positive tests
Review analyze security/query/app logs available to tier unexpected reads/writes/admin actions investigated
Improve reduce privilege, shorten lifetime, improve detection/runbook repeat tabletop and negative tests

7. Backup and admin paths are part of secrets architecture

A graph may be perfectly protected over Bolt while a world-readable backup, mounted data directory or orchestration secret leaks the entire database. Restrict backup directories, private keys, configuration, plugin directories and admin scripts at the OS/container/cloud layer. Neo4j’s security checklist specifically treats filesystem and backup access as security controls, not housekeeping.

Production judgment

Review area Decision evidence
Identity/authentication native or external identity source, MFA/SSO upstream where available, password/token lifecycle, lockout and break-glass process
Authorization least-privilege database/graph/procedure grants; explicit DENY review; Community control gap documented
Transport encrypted remote Bolt/HTTPS, trusted CA and hostname validation; self-signed only for isolated testing
Secrets out of source/logs/images; rotated without code changes; incident revocation path tested
Application layer parameterized Cypher, tenant/subject authorization before graph expansion, bounded result/data-export paths
Extensions/admin procedure allowlist/unrestricted/boosted review, plugin provenance, backup/admin filesystem and host access
Evidence auth/TLS denial tests, security/query logs where licensed, driver/server correlation and configuration review
Recovery credential compromise playbook, backup encryption/access, break-glass scope, rollback/reconciliation and post-incident validation

Check your understanding

  1. Is an environment variable a complete secrets-management strategy?
  2. What should happen immediately after a credential leak?
  3. Why can token auth managers help?
  4. Does Community security.log provide the same audit evidence as Enterprise?
  5. Why separate backup and app credentials?
Review the answers

1. No. It is one delivery mechanism; process, CI, diagnostics, host and rotation controls still matter.

2. Contain by revoking/rotating the credential, then fix the exposure path and verify approved/denied access.

3. They let the driver obtain rotating/expiring tokens without embedding static values in query code.

4. No. Enterprise provides dedicated security/query logging capabilities; Community evidence is more limited.

5. Compromise of one path should not automatically grant the privileges of another operational domain.

Summary and next step

Secrets are revocable capabilities with owners and evidence, not strings hidden from Git. Lesson 5 combines identity, RBAC, TLS, secrets, extension and admin paths into one threat model and verifies concrete defenses against realistic graph-application abuse.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.