MySQL
Protect access to MySQL services through Pomerium TCP routes.
Overview
MySQL is a relational database system. Clients normally use the MySQL protocol over TCP port 3306 or a local Unix socket. A Pomerium tunnel supplies a local TCP listener for the private database endpoint.
MySQL can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to MySQL. MySQL remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.
Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.
Configure the MySQL client for the local Pomerium listener and the required TLS mode. Keep the real database hostname in certificate validation when the client supports that design.
Example
A database user starts a Pomerium tunnel and points the MySQL client to the loopback address and local port. Pomerium checks route access. MySQL still checks the database account and SQL permissions.
Considerations
- Force TCP when a local client would otherwise choose a Unix socket.
- Preserve MySQL TLS and account authentication. Use a distinct local port for every protected database route.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- MySQLOfficial website
- MySQL transport protocolsOfficial documentation
- MySQL encrypted connectionsPrimary source
- MySQL source repositoryOfficial repository
- Tunneled MySQL connectionsPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
