Sign inSign up

detoxd/mysql

By detoxd

•Updated 6 months ago

Image
0

2.6K

detoxd/mysql repository overview

⁠MySQL - Detoxd Hardened Image

⁠Overview

MySQL is the world's most popular open-source relational database management system. Originally developed by MySQL AB and now owned by Oracle Corporation, MySQL powers some of the most heavily accessed applications on the internet including Facebook, Twitter, and YouTube.

⁠Common Use Cases

  • Web Applications - LAMP/LEMP stack backend
  • E-commerce - Transaction processing and inventory
  • Content Management - WordPress, Drupal, Joomla
  • Data Warehousing - Reporting and analytics
  • SaaS Applications - Multi-tenant databases
  • Mobile Backends - API data storage

⁠Security Concerns

MySQL databases are frequent attack targets:

  • SQL Injection - The most common web vulnerability
  • Weak Authentication - Default/empty root passwords
  • Privilege Escalation - Excessive user permissions
  • Data Exposure - Unencrypted data in transit
  • Remote Root Access - Network-accessible root user

⁠What Detoxd Does

⁠System Hardening
  • Updates all Oracle Linux packages to latest versions
  • Removes unnecessary development tools and packages
  • Cleans package caches
  • Sets secure file permissions
⁠Security Improvements
  • Removes setuid/setgid bits from binaries
  • Removes unnecessary system users
  • Prepares for secure initialization
⁠Network Security
  • Exposes only MySQL port (3306)
  • Ready for SSL/TLS configuration
⁠my.cnf Security Settings
[mysqld]
# Network
bind-address = 127.0.0.1
skip-networking = 0  # Enable for local-only access
port = 3306

# Disable dangerous features
local_infile = 0
symbolic-links = 0
skip-show-database
secure_file_priv = /var/lib/mysql-files

# SSL/TLS
require_secure_transport = ON
ssl-ca = /etc/mysql/ssl/ca.pem
ssl-cert = /etc/mysql/ssl/server-cert.pem
ssl-key = /etc/mysql/ssl/server-key.pem
tls_version = TLSv1.2,TLSv1.3

# Logging
log_error = /var/log/mysql/error.log
general_log = 0
slow_query_log = 1
slow_query_log_file = /var/log/mysql/slow.log

# Password Policies
validate_password.policy = STRONG
validate_password.length = 12
default_password_lifetime = 90
⁠Secure Initialization Script
-- Remove anonymous users
DELETE FROM mysql.user WHERE User='';

-- Remove remote root access
DELETE FROM mysql.user WHERE User='root' AND Host NOT IN ('localhost', '127.0.0.1', '::1');

-- Remove test database
DROP DATABASE IF EXISTS test;
DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%';

-- Create application user with minimal privileges
CREATE USER 'app_user'@'localhost' IDENTIFIED BY 'STRONG_PASSWORD_HERE';
GRANT SELECT, INSERT, UPDATE, DELETE ON app_db.* TO 'app_user'@'localhost';

-- Flush privileges
FLUSH PRIVILEGES;

⁠Environment Variables

MYSQL_ROOT_PASSWORD=your_secure_root_password
MYSQL_DATABASE=your_database
MYSQL_USER=app_user
MYSQL_PASSWORD=app_user_password

# Disable root password for initialization only
# MYSQL_ALLOW_EMPTY_PASSWORD=no
# MYSQL_RANDOM_ROOT_PASSWORD=yes

⁠References

Tag summary

Content type

Image

Digest

sha256:6525459f4…

Size

254 MB

Last updated

6 months ago

docker pull detoxd/mysql:9.6.0-oraclelinux9-detox.1