MySQL · 8.0

Managed MySQL 8.0

The database comes up with host, a port unique to that database, user and certificates ready. Authentication is X509: every connection presents a client certificate, and the platform is what issues the files for you to download.

How it started

MySQL was built to be fast and practical

Michael “Monty” Widenius and his collaborators created a database that was light, portable, and easy to integrate — a beginning that still shows in its focus on simplicity.

Michael “Monty” Widenius

Dan Strömberg · CC BY-SA 4.0

A concrete need

The team first tried to use mSQL, but needed more speed and flexibility for their tables.

A familiar API

Instead of abandoning the existing ecosystem, they built a new SQL interface while keeping nearly the same mSQL API, making migration easier.

A family name

MySQL was named after Monty’s daughter, My — a personal detail from a project that became global infrastructure.

What a MySQL here ships with

The tedious part of a fresh MySQL — certificates, user, TLS — is already done by the time the instance shows up in the dashboard.

Version 8.0, already configured

The platform starts the container and hands you the host as id-without-hyphens.db.usa1.vertraweb.app with a port unique to that database. There is no my.cnf to edit and no server to install on your machine.

X509 required

A password alone will not connect: the server demands a client certificate. The CA, the server certificate and the client certificate are generated automatically and are available for download in the dashboard or through the API.

Tables and a SQL console in the dashboard

The Data tab opens schemas, tables, columns, indexes and rows — 200 per page — plus a SQL console with a 10 s timeout enforced by the engine itself. It is the everyday phpMyAdmin, with nothing to install. From the Intermediary plan up.

Snapshots, restores and resets

Start, stop, restart, reset the password, reset the certificates, take a snapshot with a ZIP download and restore an earlier one — all from the dashboard, with 30 seconds between restores.

Where MySQL usually fits

It is the relational database most web applications already expect to find — drivers, ORMs and migration tools exist for every language on the platform.

PHP web applications

PDO and mysqli talk to this instance like to any MySQL 8.0 — the difference is that you have to point the driver's SSL options at the CA and the client certificate, because the server requires X509.

Projects that already assume MySQL

Laravel, Prisma, Sequelize, Hibernate and Django all ship a MySQL dialect. Moving from a local MySQL to here means changing the host, the port and the TLS options in the connection string.

Catalogs, orders and sign-ups

Products, customers and orders are stable-shaped data, and InnoDB handles transactions and foreign keys without application code. To check a query before shipping it, use the SQL console in the Data tab.

The database for the app already running here

Application and database live in the same dashboard and the same plan: one deploy, one account, and the connection goes out over the database host with TLS instead of crossing the open internet to another provider.

Connection details

These values show up on the database page as soon as it finishes starting. The id is the database identifier with the hyphens removed.

Version8.0
Port<port>
TLSRequired
AuthenticationX509 required
Host<id>.db.usa1.vertraweb.app

Connecting with the mysql client

That is three files, not one: certificate.pem to validate the server, certificate.crt and certificate.key so the server can validate you. Without the last two, X509 refuses the connection even with the right password.

bash
mysql -h <id>.db.usa1.vertraweb.app -P <port> -u root -p default   --ssl-mode=VERIFY_IDENTITY --ssl-ca=certificate.pem --ssl-cert=certificate.crt --ssl-key=certificate.key

A plan for every stage of the project

Memory and storage change with the plan; the engine does not. Compare the plans and pick the one that fits today.

Compare plans

Other managed databases

Same dashboard, same certificates, a different engine.

Frequently asked questions about managed MySQL

The questions support gets most often about MySQL databases.

How do I connect over TLS?

TLS is mandatory and authentication is X509, so the client needs all three files: --ssl-ca=certificate.pem, --ssl-cert=certificate.crt and --ssl-key=certificate.key. In drivers it is the same trio under the SSL options (ssl.ca, ssl.cert, ssl.key).

Where do I download the certificates?

On the database page in the dashboard, or through the API. The CA, the server certificate and the client certificate are generated automatically when the database is created and can be downloaded whenever you need them.

What does the destructive reset erase?

The contents of the database: reset returns the instance to its initial state and there is no undo. Resetting the password and resetting the certificates are two other operations — they swap credentials and preserve the data. Take a snapshot first.

How do I restore a snapshot?

From the database's snapshot list: pick the point and confirm the restore. There is a 30 second cooldown between one restore and the next, and the snapshot contents can also be downloaded as a ZIP.

How many databases can I have, and what changes per plan?

On paid plans, there is no fixed number of databases: each instance is created with the RAM you choose and must fit in the plan's available memory. This MySQL instance requires at least 1,024 MB. Free ("suspended") allows 1 app + 1 database, but the Free plan's RAM is still pending definition. Manual snapshots start on Scale; the Data tab, on Intermediary.

Create your MySQL now

Choose the memory, wait for the database to start and download the certificates in the dashboard for the first connection.

Create account