Chapter 19 · Composite Databases, Multiple Databases, Federation, and Data-Domain Boundaries

Composite Database Concepts, Constituents, Querying Across Graphs, and Location Transparency

Understand a Neo4j composite database as an Enterprise execution and federation layer over local or remote constituent aliases—not a data store—and observe its metadata, graph-selection rules, privileges, and version boundaries.

Advanced230–310 minutesComposite concepts and metadata labNeo4j 2026.07.1 · Community multi-instance mandatory · Enterprise composite optionalCypher 25 · USE / CALL / SHOW DATABASES / SHOW ALIASESJava 21/25 · Python driver 6.3Last reviewed: September 2026

AtlasMart’s application-side federation works, but every service must know three Bolt addresses and orchestrate the same lookup sequence. Enterprise architects propose a composite database named atlasmart so callers can query logical constituents atlasmart.orders, atlasmart.customers, and atlasmart.catalog. The important question is not “how do I create it?” but “what semantics change, and what stays owned by the constituents?”

Mental model

A composite database is an execution/federation namespace over aliases. It has no independent graph store, does not own indexes/constraints, and is not a backup container for the constituent data.

Learning outcomes

01

Explain composite databases, constituents, local/remote aliases and location transparency without treating the composite as storage.

02

Create and inspect an optional Enterprise composite using current Cypher 25 administration syntax.

03

Use SHOW DATABASES and SHOW ALIASES evidence to distinguish composite metadata from constituent stores.

04

Query different constituents with USE/CALL while respecting graph-selection/root-scope rules.

05

Identify version, security, backup and Aura limitations before adopting a composite architecture.

Reproducible Chapter 19 lab baseline

Chapter 19 baseline · reviewed 9 September 2026

Current self-managed Neo4j is 2026.07.1; current 5.26 LTS is 5.26.30. The course remains on Java 21 or 25, explicit CYPHER 25 for version-sensitive examples, and Python driver 6.3. The mandatory chapter lab uses three disposable Neo4j Community 2026.07.1 instances because Community can host exactly one standard database per DBMS. No runtime output or latency value in these lessons is claimed to have been executed during generation; deterministic expected rows are fixture invariants and timings must be measured by the learner.

Edition and platform boundary

Self-managed Community Edition can have exactly one standard database. Self-managed Enterprise Edition can have multiple standard databases; CREATE DATABASE and composite-database administration are Enterprise features and are not available on Aura. Composite databases are Enterprise-only and explicitly unavailable on Aura. Therefore the free learning path uses separate Community DBMS instances and application-side federation; optional Enterprise commands are labeled and must not be mistaken for Community or Aura behavior.

Term Mechanism-first meaning
standard database A physical Neo4j database that contains one graph in Neo4j 2026.07; it is an execution context and transaction domain.
DBMS A Neo4j database-management process/deployment that hosts the system database plus the standard databases allowed by its edition.
system database Built-in metadata/security database used for database, alias, server and access administration; it does not contain AtlasMart domain graph data.
multiple databases Several standard databases managed by one Enterprise DBMS; separation is stronger than labels but still shares DBMS/server resources and operations.
composite database Enterprise logical execution/federation context containing aliases to constituent graphs; it stores no graph data independently.
constituent A local or remote standard database exposed inside a composite through a namespaced alias.
local alias Alias whose target standard database is in the same DBMS.
remote alias Alias whose target is another Neo4j DBMS over a driver connection and whose authentication/security is governed at that remote boundary.
federated query One Cypher query whose graph-specific subqueries read from more than one constituent.
location transparency The caller uses a logical constituent name while the alias determines whether its target is local or remote; latency/failure locality is not magically erased.
proxy node A deliberately duplicated identity-only node used to join facts across disjoint graphs because Neo4j relationships cannot span graphs.
transaction domain The set of graph updates that can commit atomically together. A standard database is one transaction domain; a composite permits multi-graph reads but updates only one constituent per transaction.
tenant boundary A technical/operational separation choice for tenant data. Database separation does not automatically provide CPU/memory/noisy-neighbor isolation, billing isolation, or legal compliance.
domain ownership The team/system accountable for a fact’s schema, invariants, writes, recovery and lifecycle—not merely the graph where a convenient copy exists.
Community instance Purpose HTTP Bolt Container Volume
catalog Product/catalog source of truth 7574 7767 atlasmart-ch19-catalog atlasmart-ch19-catalog-data
orders Order facts plus CustomerRef/ProductRef proxies 7575 7768 atlasmart-ch19-orders atlasmart-ch19-orders-data
customers Customer source of truth 7576 7769 atlasmart-ch19-customers atlasmart-ch19-customers-data
Assumption Pinned value / rule
deployment Three isolated local Community containers on one workstation; this simulates domain separation, not a composite database
database Each Community DBMS uses its single standard database named neo4j
auth Synthetic lab-only neo4j / atlasmart-course-2026 credential; never use it outside the disposable lab
TLS Loopback lab uses bolt:// for simplicity; remote production aliases/drivers require verified TLS and credential governance
plugins No APOC or GDS required
indexes Uniqueness constraints on domain IDs only; no cross-database constraint exists
graph size Tiny deterministic fixture: 3 products, 3 customers, 3 orders, 4 line items/proxy references
failure injection Stop one disposable instance or add an application-side artificial delay; no destructive network or disk fault is required
Enterprise option Commands are examples for a licensed self-managed Enterprise environment and are not executed by the free path
Aura Composite databases and self-managed CREATE DATABASE are not taught as Aura capabilities

1. Composite anatomy

Object Stores graph data? Execution/transaction role Administration owner
standard database Yes normal graph execution + transaction domain its own schema, indexes, constraints, backup, topology/access
composite database No root execution context; reads may span constituents; writes limited to one constituent per transaction composite metadata/default language and constituent aliases
local constituent alias No routes graph scope to same-DBMS target alias metadata + target database
remote constituent alias No routes graph scope over network to another DBMS alias credentials/driver options + remote database administration

2. Optional licensed Enterprise setup

These commands are intentionally separated from the mandatory Community lab. They require self-managed Enterprise. Administration commands are routed to the system database over Bolt; the actual AtlasMart fixture would then be loaded into the three target standard databases just as it was into the three Community instances.

Cypher 25 · optional Enterprise local composite
// OPTIONAL: self-managed Neo4j Enterprise 2026.07.1; run administration against system.
CYPHER 25
CREATE DATABASE `atlasmart-catalog` IF NOT EXISTS;
CREATE DATABASE `atlasmart-orders` IF NOT EXISTS;
CREATE DATABASE `atlasmart-customers` IF NOT EXISTS;
CREATE COMPOSITE DATABASE atlasmart IF NOT EXISTS DEFAULT LANGUAGE CYPHER 25;
CREATE ALIAS atlasmart.catalog IF NOT EXISTS FOR DATABASE `atlasmart-catalog`;
CREATE ALIAS atlasmart.orders IF NOT EXISTS FOR DATABASE `atlasmart-orders`;
CREATE ALIAS atlasmart.customers IF NOT EXISTS FOR DATABASE `atlasmart-customers`;

SHOW DATABASE atlasmart YIELD name, type, currentStatus, constituents, defaultLanguage;
SHOW ALIASES FOR DATABASE
YIELD name, composite, database, location, url, credentials, user
WHERE composite = 'atlasmart'
RETURN * ORDER BY name;
What SHOW proves

A row with type=composite and a constituents list proves that the logical composite metadata exists. It does not prove the constituent datasets, indexes, backups or remote links are healthy; inspect those separately.

3. Location transparency is naming transparency, not latency transparency

A constituent alias can target a local standard database in the same DBMS or a remote standard database over a Neo4j driver connection. Callers can keep the logical alias stable while the target changes, but the physical location still determines network latency, TLS/authentication, remote capacity, failure modes and billing/egress.

Cypher 25 · optional remote constituent
// OPTIONAL remote constituent example. Use a secret-management process; do not commit passwords.
CYPHER 25
CREATE ALIAS atlasmart.catalogRemote
FOR DATABASE neo4j
AT 'neo4j+s://catalog.example.invalid:7687'
USER atlasmart_federation
PASSWORD 'example_secret';

SHOW ALIAS atlasmart.catalogRemote FOR DATABASE
YIELD name, composite, database, location, url, credentials, user;
Alias evidence Interpretation
location=local target is in the same DBMS; still a separate database/transaction/schema unit
location=remote target is another DBMS; network, remote auth, remote availability and version compatibility enter the request path
credentials=STORED NATIVE CREDENTIALS remote alias uses stored native credentials
credentials=OIDC CREDENTIAL FORWARDING supported current remote-alias mode where configured; identity/security provider requirements apply

4. Query graph scopes with USE and CALL

A composite query can keep the root scope non-graph-accessing while child CALL {} scopes select constituents with USE. Variables crossing a subquery boundary are scalar/map/list values—not magic edges between graphs. The example joins through customerId and productId.

Cypher 25 · optional Enterprise composite federation
CYPHER 25
CALL {
  USE atlasmart.orders
  MATCH (o:Order {orderId:$orderId})-[:PLACED_BY]->(cr:CustomerRef)
  MATCH (o)-[li:CONTAINS]->(pr:ProductRef)
  RETURN o.orderId AS orderId, o.status AS status,
         cr.customerId AS customerId, pr.productId AS productId,
         li.quantity AS quantity, li.unitPrice AS unitPrice
}
CALL {
  USE atlasmart.customers
  WITH customerId
  MATCH (c:Customer {customerId:customerId})
  RETURN c.name AS customerName, c.tier AS tier
}
CALL {
  USE atlasmart.catalog
  WITH productId
  MATCH (p:Product {productId:productId})
  RETURN p.name AS productName, p.price AS currentPrice
}
RETURN orderId, status, customerId, customerName, tier,
       productId, productName, quantity, unitPrice, currentPrice
ORDER BY productId;
Expected deterministic rows

For O-1901 the query yields two rows: Ada Lovelace with Trail Camera and Weather Case. Current/catalog price and historical unitPrice are returned separately.

5. Graph-selection limitations matter

Rule Why it exists / effect
root scopes without USE must not perform graph-accessing operations the root is coordinating data from potentially several graphs and is not itself one target graph
nested USE must not switch away from the graph chosen by its parent scope graph context is explicit and predictable inside nested scopes
relationships cannot span graphs graph relationship identity/storage is local; use proxy IDs and federated joins
write at most one constituent per transaction composite provides a limited transaction domain, not distributed two-phase commit across graph stores
indexes/constraints/privileges are managed on constituent targets composite does not own the target graph schema or graph privileges

6. Cypher/version compatibility is an intersection

The current composite can have a default language such as Cypher 25. However, a remote constituent may run another compatible Neo4j release. Neo4j does not guarantee arbitrary mixed-version composite compatibility: newly added behavior can only be used when supported by the composite DBMS and the constituents involved. Treat a version matrix as deployment evidence, not an assumption.

Preflight Evidence to record
composite DBMS Neo4j version, defaultLanguage, Enterprise license state
each constituent Neo4j version, graph schema/indexes, expected Cypher feature set
remote aliases URL/TLS mode, credential mode, driver options, remote availability
application official driver version and query features used

7. Security and backup stay constituent-aware

Cypher 25 · optional Enterprise read role
// OPTIONAL Enterprise example; exact role naming is an AtlasMart design choice.
CYPHER 25
CREATE ROLE atlasmart_reader IF NOT EXISTS;
GRANT ACCESS ON DATABASE atlasmart TO atlasmart_reader;
GRANT ACCESS ON DATABASE `atlasmart-catalog` TO atlasmart_reader;
GRANT ACCESS ON DATABASE `atlasmart-orders` TO atlasmart_reader;
GRANT ACCESS ON DATABASE `atlasmart-customers` TO atlasmart_reader;
GRANT MATCH {*} ON GRAPH `atlasmart-catalog` TO atlasmart_reader;
GRANT MATCH {*} ON GRAPH `atlasmart-orders` TO atlasmart_reader;
GRANT MATCH {*} ON GRAPH `atlasmart-customers` TO atlasmart_reader;
SHOW ROLE atlasmart_reader PRIVILEGES;
Access boundary

Composite RBAC requires access to the composite and to every constituent needed by the query. Remote aliases apply the remote user’s RBAC on the remote DBMS. A composite-level grant does not erase constituent authorization.

Backup boundary

Back up and validate the data-bearing standard databases/remote targets. The composite’s alias metadata alone cannot reconstruct Product, Customer or Order stores.

8. Wrong model: “the composite contains the data”

If AtlasMart only exports or backs up the composite namespace and ignores target databases, recovery will have metadata pointing at missing/unrecovered data. Repair the mental model by producing a constituent inventory: owner, target, location, version, backup policy, RPO/RTO, security owner, and dependency SLO for every alias.

Check your understanding

  1. Does a composite database have an independent property graph store?
  2. What does location transparency hide and what does it not hide?
  3. Where are indexes and constraints defined?
  4. Can a composite transaction update Orders and Catalog together?
  5. Is a composite database available on Aura today?
Review the answers

1. No. It contains aliases to local/remote constituent databases and provides an execution/federation context.

2. It hides target naming behind an alias; it does not remove network latency, failures, security, egress or version constraints.

3. On each data-bearing constituent target database, not on the composite.

4. No. It may read multiple graphs but can update only one constituent graph per transaction.

5. No; current documentation marks composites as Enterprise Edition and not available on Aura.

Production judgment

Decision surface Production questions
graph/workload fit Does domain separation reduce ownership/capacity coupling, or does it turn the dominant traversal into repeated remote joins?
correctness Which invariants remain atomic inside one graph, and which become asynchronous/application-coordinated across domains?
model/cardinality/degree Which high-degree relationships must remain local for traversal cost and invariant enforcement? Which references are safe as proxy keys?
latency How much p95/p99 is local graph work versus remote constituent/network/application join time? What happens during remote tail spikes?
transactions/concurrency Which writes must commit together? Composite transactions may read many graphs but update only one constituent; plan compensating/outbox workflows elsewhere.
memory/resources Do multiple databases share a DBMS resource envelope? Do separate instances need independent memory/page-cache/process budgets and capacity headroom?
CPU/disk/network Does federation move filtering to constituents or ship excessive rows across network boundaries? Are region/zone egress and serialization material?
indexes/constraints Are stable IDs constrained and indexed independently on each owning/proxy graph? No cross-graph relationship or uniqueness constraint exists.
driver Are database/alias names explicit, drivers long-lived, timeouts/retries bounded, and per-domain timings correlated?
security/tenant risk Are ACCESS/MATCH/procedure rights granted on every required constituent? How are remote credentials/OIDC forwarding, TLS and tenant boundaries governed?
backup/recovery Can every constituent be restored and reconciled independently? A composite alias layer is not a backup of its target stores.
observability Can operators attribute latency/errors to the root composite scope and each local/remote constituent without hiding network waits?
testing/failure injection Have one-domain-down, stale proxy, version mismatch, denied constituent, slow remote graph and ambiguous cross-service write cases been tested safely?
version/edition/Aura Is the design pinned to self-managed Enterprise composite support? What is the fallback for Community/Aura or mixed-version constituents?
licensing/cost/migration Does federation justify Enterprise/ops/network cost, and can the split be rolled back or re-partitioned without breaking identity contracts?

Summary and next step

A composite makes graph location selectable inside one Cypher request, but domain data, security, schema, version and recovery remain constituent responsibilities. Lesson 3 examines the performance and query-shape consequences once federated reads cross those boundaries.

Authoritative references

  • Current Neo4j versions — Current self-managed release 2026.07.1 and 5.26.30 LTS snapshot.
  • Database administration — Current database/transaction-domain model and the one-standard-database Community versus multi-database Enterprise boundary.
  • Create standard databases — Enterprise-only self-managed CREATE DATABASE semantics and system-database administration.
  • Show databases — SHOW DATABASES fields including type, role, writer, status, aliases and constituents.
  • Composite database concepts — Enterprise-only, unavailable-on-Aura composite semantics, local/remote constituents, compatibility, transactions and proxy-node federation.
  • Create composite databases — CREATE COMPOSITE DATABASE and current default Cypher language behavior.
  • Query composite databases — USE/CALL graph selection, graph functions, update restrictions, root-scope limits and runtime behavior.
  • Composite aliases — Local and remote constituent aliases, SHOW ALIASES evidence, namespace rules and alias limitations.
  • Standard aliases — Local/remote alias behavior, credentials, access visibility and current OIDC-forwarding option for remote aliases.
  • Composite RBAC — Access must be granted to the composite and constituents; remote constituents enforce remote-user RBAC.
  • Composite tutorial — Official federation/sharding example and proxy-node model.
  • Database alias command syntax — Current SHOW/CREATE/ALTER alias command forms.
  • Cypher USE clause — Current graph-selection clause semantics for composite/federated queries.
  • Python driver manual — Official driver lifecycle, sessions, parameters, database selection and application-side orchestration.
  • Backup and restore — Operational reminder that constituent data stores—not a composite alias layer—are the recovery units.

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.