Chapter 15 · Security: Authentication, RBAC, Privileges, TLS, Secrets, and Least Privilege
Secrets Management, Rotation, Driver Credentials, Audit Evidence, and Incident Response
Treat AtlasMart credentials, tokens, TLS keys and admin secrets as rotating capabilities with controlled delivery, audit evidence and tested incident response.
Learning outcomes
AtlasMart rotates a database password and every application instance goes down because the password was copied into three repositories, a Dockerfile, a CI variable and an old runbook. Secret management is not “where do we put the password?”; it is a lifecycle with issuance, constrained delivery, use, rotation, revocation, evidence and recovery.
Keep Neo4j passwords/tokens/private keys out of source, images, logs and test snapshots.
Rotate native credentials and driver authentication without coupling secret values to code.
Use driver auth-management APIs appropriately for rotating token-based credentials.
Distinguish Community log evidence from Enterprise security/query logging and Aura-managed evidence.
Build an incident-response sequence for credential leakage, procedure abuse and backup/admin-path compromise.
The continuity lab remains Neo4j Community
2026.07.1, database neo4j, explicit
CYPHER 25 where language behavior matters,
container atlasmart-neo4j, loopback Bolt
bolt://127.0.0.1:7687, synthetic credential
neo4j/atlasmart-course-2026,
official Python driver neo4j 6.3.0, and no
mandatory plugin. Neo4j 5.26.30 is the LTS
comparison line. For TLS changes, this chapter deliberately
uses a second disposable container
atlasmart-neo4j-secure so earlier labs are not
disrupted.
Current Community Edition supports native users but has no roles; every Community user has implied administrator privileges. Fine-grained RBAC, built-in/custom roles, graph/database/procedure privileges, external auth-provider integration, security/query logs and related enterprise authorization controls are Enterprise/Aura-tier features. Mandatory Community exercises therefore prove authentication, parameterization, TLS, credential rotation and application-layer authorization, while RBAC denial examples are explicitly marked licensed/deterministic rather than presented as Community output.
All credentials, certificates and attacks in this chapter are synthetic and disposable. Never paste production passwords/private keys into source control, do not disable certificate verification to make a production connection work, and do not broaden procedure/plugin privileges merely to get a demo running.
Reproducible AtlasMart setup
$env:NEO4J_URI='bolt://127.0.0.1:7687'$env:NEO4J_USER='neo4j'$env:NEO4J_PASSWORD='atlasmart-course-2026'$env:NEO4J_DATABASE='neo4j'py -3 -m venv .venv.\.venv\Scripts\Activate.ps1python -m pip install --upgrade pippython -m pip install neo4j==6.3.0
CYPHER 25CREATE CONSTRAINT customer_id IF NOT EXISTSFOR (c:Customer) REQUIRE c.customerId IS UNIQUE;CREATE CONSTRAINT product_id IF NOT EXISTSFOR (p:Product) REQUIRE p.productId IS UNIQUE;CREATE CONSTRAINT order_id IF NOT EXISTSFOR (o:Order) REQUIRE o.orderId IS UNIQUE;MERGE (c:Customer {customerId:'C-1001'})SET c.name='Mina Rahimi', c.tier='GOLD', c.tenantId='TENANT-A'MERGE (p:Product {productId:'P-1001'})SET p.name='Trail Camera', p.category='Cameras', p.price=129.90MERGE (o:Order {orderId:'O-5001'})SET o.status='PAID', o.tenantId='TENANT-A', o.orderedAt=datetime('2026-09-08T16:30:00Z')MERGE (c)-[:PLACED]->(o)MERGE (o)-[r:CONTAINS]->(p)SET r.quantity=1, r.unitPrice=129.90;
These are course-only credentials and synthetic records. The
fixture deliberately includes tenantId because
authorization mistakes often appear when a graph traversal
crosses a tenant boundary even though authentication succeeded.
1. Inventory every secret-bearing surface
| Surface | Secret/risk | Control |
|---|---|---|
| application runtime | DB password/token | platform secret store, least-readable process identity |
| CI/CD | deployment credential | scoped secret, protected environment, no echo |
| container image | ENV baked at build time | never bake production secret; inject at runtime |
| logs/traces | URI/headers/query params | redaction; parameterize; never log auth token |
| TLS directory | server private key | read-only mount/file ACL; separate from public cert |
| backup/admin tooling | backup keys/admin password/cloud tokens | separate operational identity and encrypted storage |
| developer laptops | copied production env files | avoid distribution; short-lived/SSO access where available |
2. Rotate a native password safely
ALTER USER atlasmart_serviceSET PASSWORD $newPasswordCHANGE NOT REQUIRED;
$env:NEO4J_URI='neo4j+s://db.example.com:7687'$env:NEO4J_USER='atlasmart_service'$env:NEO4J_PASSWORD=(Get-Content -Raw .\run\secrets\neo4j_password).Trim()python .\app.py
In a real orchestrator, the file would be a managed secret mount, not a repository file. Rotation order depends on the authentication mechanism: avoid a window where all clients still use the retired secret, and verify new sessions before revoking old access when dual-token/provider mechanisms permit it.
3. Rotating token credentials in the Python driver
from neo4j import GraphDatabasefrom neo4j.auth_management import AuthManagers, ExpiringAuthimport timedef get_token(): token = fetch_token_from_identity_provider() return ExpiringAuth(token).expires_in(55)auth_manager = AuthManagers.bearer(get_token)driver = GraphDatabase.driver( "neo4j+s://db.example.com:7687", auth=auth_manager,)
The auth manager supports credentials expected to rotate, such as SSO bearer tokens. It does not magically make long external side effects idempotent or repair authorization. The provider callback itself is privileged code: protect its client credentials and failure behavior.
4. Wrong patterns and concrete failure
| Wrong pattern | Concrete failure | Repair |
|---|---|---|
| password in Git | history/forks/cache preserve leak | revoke/rotate, scrub exposure where appropriate, secret manager |
| password in Dockerfile ENV | recoverable from image/layers/metadata | runtime secret injection |
| log complete driver URI/auth object | credential exfiltration through logs | structured redaction and safe fields only |
| same admin secret for app + backup + humans | one leak crosses every boundary | separate scoped identities and duties |
| rotate only in secret store | long-running process keeps old credential indefinitely | document reload/restart/auth-manager behavior and verify |
| assume timeout means password change failed | ambiguous operation may have completed | read back state/login test; do not blindly repeat destructive admin operations |
5. Evidence: what can you actually audit?
| Evidence | Community | Enterprise/Aura note |
|---|---|---|
SHOW USERS/SHOW CURRENT USER
|
available user-state evidence | Enterprise adds roles/metadata/provider features |
| general/debug/service logs | available depending packaging/config | not a complete security audit trail |
security.log |
not an Enterprise-style security log in Community | Enterprise security-event log |
query.log |
Enterprise feature | threshold/verbose query evidence; protect sensitive parameters/log access |
| Aura audit/console evidence | managed-service specific | use tier/console audit capabilities, not self-managed file assumptions |
| application auth/authorization audit | application responsibility | correlate subject, action, resource, decision, request id without logging secret |
Audit data is itself sensitive. Protect log access, retention and export paths; avoid DEBUG token/JWT claim logging in production unless a short troubleshooting window explicitly requires it.
6. Incident-response mini playbook
| Phase | Action | Verification |
|---|---|---|
| Detect | identify leaked credential/key/procedure path and affected identities | scope evidence, timestamps, hosts/clients |
| Contain | revoke/rotate credential; restrict network/procedure access | old credential fails, approved client still works |
| Eradicate | remove secret from source/image/log pipeline and fix root cause | secret scanners/builds/config review clean |
| Recover | redeploy/reload clients, restore required service | read/write invariants and TLS/auth positive tests |
| Review | analyze security/query/app logs available to tier | unexpected reads/writes/admin actions investigated |
| Improve | reduce privilege, shorten lifetime, improve detection/runbook | repeat tabletop and negative tests |
7. Backup and admin paths are part of secrets architecture
A graph may be perfectly protected over Bolt while a world-readable backup, mounted data directory or orchestration secret leaks the entire database. Restrict backup directories, private keys, configuration, plugin directories and admin scripts at the OS/container/cloud layer. Neo4j’s security checklist specifically treats filesystem and backup access as security controls, not housekeeping.
Production judgment
| Review area | Decision evidence |
|---|---|
| Identity/authentication | native or external identity source, MFA/SSO upstream where available, password/token lifecycle, lockout and break-glass process |
| Authorization | least-privilege database/graph/procedure grants; explicit DENY review; Community control gap documented |
| Transport | encrypted remote Bolt/HTTPS, trusted CA and hostname validation; self-signed only for isolated testing |
| Secrets | out of source/logs/images; rotated without code changes; incident revocation path tested |
| Application layer | parameterized Cypher, tenant/subject authorization before graph expansion, bounded result/data-export paths |
| Extensions/admin | procedure allowlist/unrestricted/boosted review, plugin provenance, backup/admin filesystem and host access |
| Evidence | auth/TLS denial tests, security/query logs where licensed, driver/server correlation and configuration review |
| Recovery | credential compromise playbook, backup encryption/access, break-glass scope, rollback/reconciliation and post-incident validation |
Check your understanding
- Is an environment variable a complete secrets-management strategy?
- What should happen immediately after a credential leak?
- Why can token auth managers help?
- Does Community security.log provide the same audit evidence as Enterprise?
- Why separate backup and app credentials?
Review the answers
1. No. It is one delivery mechanism; process, CI, diagnostics, host and rotation controls still matter.
2. Contain by revoking/rotating the credential, then fix the exposure path and verify approved/denied access.
3. They let the driver obtain rotating/expiring tokens without embedding static values in query code.
4. No. Enterprise provides dedicated security/query logging capabilities; Community evidence is more limited.
5. Compromise of one path should not automatically grant the privileges of another operational domain.
Summary and next step
Secrets are revocable capabilities with owners and evidence, not strings hidden from Git. Lesson 5 combines identity, RBAC, TLS, secrets, extension and admin paths into one threat model and verifies concrete defenses against realistic graph-application abuse.
Authoritative references
- Current Neo4j versions — Current server and 5.26 LTS release snapshot.
- Security checklist — Official baseline for deployment, transport, extensions, backup and filesystem security.
- Manage users — Native users, password handling, Community/Enterprise user-model distinctions.
- Role-based access control — Enterprise RBAC model and GRANT/DENY/REVOKE semantics.
- Read privileges — TRAVERSE, READ and MATCH graph privilege semantics.
- Write privileges — CREATE, DELETE, SET, MERGE and WRITE privilege semantics.
- SSL framework — Bolt/HTTPS TLS policies, certificate files, TLS levels and URI schemes.
- Procedure/function privileges — Execute and boosted-execution privilege boundaries.
- Python driver advanced connections — TLS/trust and rotating authentication token support in the maintained Python driver.
- Logging — Community/Enterprise log availability, including query/security log boundaries.
- Aura user management — Managed-service roles and distinction between Aura console roles and DB-level RBAC.
- Recover admin user/password — Break-glass recovery and network-isolation precautions.