> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# MariaDB

> How to connect to a MariaDB Resource using the Formal Connector

## Overview

MariaDB has its own technology, `mariadb`, in Formal. The Connector proxies it with the same engine and SQL dialect as [MySQL](/docs/guides/core-concepts/resources/mysql), so the MySQL guide applies to MariaDB too.

Choose `mariadb` rather than `mysql` for MariaDB servers. Policies and logs then report `mariadb` as the Resource technology, which lets you scope policies to MariaDB alone.

## Create a MariaDB Resource

<Tabs>
  <Tab title="Control Plane">
    Go to [Resources](https://app.formal.ai/resources) and click **Create Resource**. Set **Technology** to **MariaDB**, then enter the **Hostname**. The **Port** defaults to `3306`.
  </Tab>

  <Tab title="Terraform">
    ```hcl theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
    resource "formal_resource" "orders" {
      name       = "orders-mariadb"
      technology = "mariadb"
      hostname   = "orders.example.internal"
      port       = 3306
    }
    ```
  </Tab>
</Tabs>

## Requirements

### Networking

You may assign any listener port except 8080 (the Connector's health check port). Make sure your security groups allow the traffic.

### Database Health Check

Formal periodically connects and runs `SELECT 1`. If you don't configure a database for health checks, Formal uses `mysql`. See [Configure Health Check Database](/docs/guides/core-concepts/resources/introduction#configure-health-check-database).

### Native Users

MariaDB Resources require a [Native User](/docs/guides/core-concepts/resources/native-users). The Control Plane offers **Password**, **AWS IAM**, **AWS IAM Role**, and **GCP IAM** credentials. Grant the Native User the permissions end users need upstream. Granting `SELECT` on `information_schema` is recommended.

## Connect to MariaDB

Use the `mariadb` or `mysql` client:

```bash theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
mariadb -h CONNECTOR_HOSTNAME -P PORT -D DATABASE_NAME -u FORMAL_USERNAME --password=PASSWORD
```

Replace `CONNECTOR_HOSTNAME`, `PORT`, `DATABASE_NAME`, `FORMAL_USERNAME`, and `PASSWORD` with the right values.

<Warning>
  The `mariadb` and `mysql` clients don't accept passwords longer than 80
  characters with the interactive `-p` option. Formal access tokens are longer,
  so use [hashed tokens](/docs/guides/core-concepts/identities#using-hashed-access-tokens).
</Warning>

**Verify:**

```sql theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
SELECT CURRENT_USER();
```

The result is the Native User's database user.

### Smart Routing

Several MariaDB Resources can share one listener port. Add the Resource name after the database name:

```bash theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
mariadb -h CONNECTOR_HOSTNAME -P 3306 -D DATABASE_NAME@RESOURCE_NAME -u FORMAL_USERNAME
```

## Policy Evaluation

Formal evaluates policies at the **session**, **request**, and **response** stages, as for MySQL. To target MariaDB only:

```rego theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
package formal.v2

import future.keywords.if
import future.keywords.in

request := {
  "action": "block",
  "type": "block_with_custom_message",
  "message": "Schema changes on MariaDB require a change ticket"
} if {
  input.resource.technology == "mariadb"
  input.sql_query.statement_type in {"CREATE", "ALTER", "DROP"}
}
```

## Next Steps

<CardGroup cols={2}>
  <Card title="MySQL" icon="database" href="/docs/guides/core-concepts/resources/mysql">
    Read the full MySQL guide
  </Card>

  <Card title="Native Users" icon="key" href="/docs/guides/core-concepts/resources/native-users">
    Configure upstream credentials
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.