Repository: github.com/detoxd/detoxd | Images: images/mysql
MySQL is the world's most popular open-source relational database management system. Originally developed by MySQL AB and now owned by Oracle Corporation, MySQL powers some of the most heavily accessed applications on the internet including Facebook, Twitter, and YouTube.
MySQL databases are frequent attack targets:
[mysqld]
# Network
bind-address = 127.0.0.1
skip-networking = 0 # Enable for local-only access
port = 3306
# Disable dangerous features
local_infile = 0
symbolic-links = 0
skip-show-database
secure_file_priv = /var/lib/mysql-files
# SSL/TLS
require_secure_transport = ON
ssl-ca = /etc/mysql/ssl/ca.pem
ssl-cert = /etc/mysql/ssl/server-cert.pem
ssl-key = /etc/mysql/ssl/server-key.pem
tls_version = TLSv1.2,TLSv1.3
# Logging
log_error = /var/log/mysql/error.log
general_log = 0
slow_query_log = 1
slow_query_log_file = /var/log/mysql/slow.log
# Password Policies
validate_password.policy = STRONG
validate_password.length = 12
default_password_lifetime = 90
-- Remove anonymous users
DELETE FROM mysql.user WHERE User='';
-- Remove remote root access
DELETE FROM mysql.user WHERE User='root' AND Host NOT IN ('localhost', '127.0.0.1', '::1');
-- Remove test database
DROP DATABASE IF EXISTS test;
DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%';
-- Create application user with minimal privileges
CREATE USER 'app_user'@'localhost' IDENTIFIED BY 'STRONG_PASSWORD_HERE';
GRANT SELECT, INSERT, UPDATE, DELETE ON app_db.* TO 'app_user'@'localhost';
-- Flush privileges
FLUSH PRIVILEGES;
MYSQL_ROOT_PASSWORD=your_secure_root_password
MYSQL_DATABASE=your_database
MYSQL_USER=app_user
MYSQL_PASSWORD=app_user_password
# Disable root password for initialization only
# MYSQL_ALLOW_EMPTY_PASSWORD=no
# MYSQL_RANDOM_ROOT_PASSWORD=yes
Content type
Image
Digest
sha256:6525459f4…
Size
254 MB
Last updated
6 months ago
docker pull detoxd/mysql:9.6.0-oraclelinux9-detox.1