Skip to main content

Overview

MariaDB has its own technology, mariadb, in Formal. The Connector proxies it with the same engine and SQL dialect as MySQL, so the MySQL guide applies to MariaDB too. Choose mariadb rather than mysql for MariaDB servers. Policies and logs then report mariadb as the Resource technology, which lets you scope policies to MariaDB alone.

Create a MariaDB Resource

Go to Resources and click Create Resource. Set Technology to MariaDB, then enter the Hostname. The Port defaults to 3306.

Requirements

Networking

You may assign any listener port except 8080 (the Connector’s health check port). Make sure your security groups allow the traffic.

Database Health Check

Formal periodically connects and runs SELECT 1. If you don’t configure a database for health checks, Formal uses mysql. See Configure Health Check Database.

Native Users

MariaDB Resources require a Native User. The Control Plane offers Password, AWS IAM, AWS IAM Role, and GCP IAM credentials. Grant the Native User the permissions end users need upstream. Granting SELECT on information_schema is recommended.

Connect to MariaDB

Use the mariadb or mysql client:
Replace CONNECTOR_HOSTNAME, PORT, DATABASE_NAME, FORMAL_USERNAME, and PASSWORD with the right values.
The mariadb and mysql clients don’t accept passwords longer than 80 characters with the interactive -p option. Formal access tokens are longer, so use hashed tokens.
Verify:
The result is the Native User’s database user.

Smart Routing

Several MariaDB Resources can share one listener port. Add the Resource name after the database name:

Policy Evaluation

Formal evaluates policies at the session, request, and response stages, as for MySQL. To target MariaDB only:

Next Steps

MySQL

Read the full MySQL guide

Native Users

Configure upstream credentials