MariaDB wrapped with the Knot entrypoint for agent integration, syslog logging and startup hooks.
7.8K
A MariaDB image for knot spaces. It wraps the official mariadb image with the knot entrypoint, so a MariaDB instance running inside a space gets the same agent integration, rsyslog logging and startup hooks as every other knot base image. It is otherwise a standard MariaDB container and accepts the usual MariaDB environment variables.
All tags are multi-arch (linux/amd64, linux/arm64); see Docker Hub for the current list.
Each release is also tagged <version>-<BUILD_DATE>.
docker run -d \
-p 3306:3306 \
-e MARIADB_ROOT_PASSWORD=changeme \
-e KNOT_SERVER=https://knot.example.com \
-v mariadb_data:/var/lib/mysql \
paularlott/knot-mariadb:12.3
In a knot space, the root password is typically set from the user's Service Password:
environment:
- KNOT_SERVER=${{.server.url}}
- KNOT_USER=mysql
- MARIADB_ROOT_PASSWORD=${{.user.service_password}}
Connect to the running server (from the host or another space) via knot port forwarding:
knot forward port 127.0.0.1:3306 <space> 3306
The image layers the knot entrypoint on top of the official MariaDB image. On startup the entrypoint:
KNOT_USER to mysql.KNOT_SERVER is set, downloads and starts the knot agent (as mysql).rsyslog and forwards logs to the agent's syslog port./etc/knot-startup.d/ and ~/.knot-startup.d/.execs MariaDB's original docker-entrypoint.sh with mariadbd./etc/mysql/mariadb.conf.d/99-logging.cnf routes the server error log to syslog so it is captured by the knot agent./docker-entrypoint-initdb.d/localaccess.sql clears the root@localhost password on first initialisation so that mysqladmin ping works for health checks.Set MARIADB_ENCRYPTION_KEY to a non-empty passphrase to transparently encrypt the database at rest using MariaDB's file_key_management plugin. When the variable is set, the entrypoint:
1) on first start and stores it in /var/lib/mysql/.mariadb-keyfile.enc, encrypted with the passphrase via openssl (AES-256-CBC, SHA-1 digest — the format MariaDB expects)./etc/mysql/mariadb.conf.d/zz-knot-encryption.cnf (loaded automatically) that loads file_key_management and forces encryption of InnoDB tables, the InnoDB redo log, Aria tables, the binary log and temporary files./run/...) for the lifetime of the container — the persistent volume never holds the plaintext key.The encrypted key file lives in the data directory (persisted across restarts), while the passphrase is injected at runtime via the environment. A stolen volume alone is therefore useless without the passphrase.
environment:
- MARIADB_ROOT_PASSWORD=${{.user.service_password}}
- MARIADB_ENCRYPTION_KEY=${{.user.service_password}}
Caveats:
MARIADB_ENCRYPTION_KEY afterwards — MariaDB will be unable to decrypt the existing data and refuse to start. Treat the passphrase like any other secret: store it in a password manager / secret provider and keep it stable.innodb_encrypt_threads capacity in mind.| Variable | Default | Description |
|---|---|---|
KNOT_USER | mysql | Runtime user (forced) |
KNOT_SERVER | (unset) | knot server URL; if set, the agent is started |
KNOT_AGENT_ENDPOINT | (unset) | Agent endpoint reported to the server |
KNOT_SPACEID | (unset) | Space identifier |
KNOT_SYSLOG_PORT | 1514 | Syslog forward target (0 disables forwarding) |
TZ | Etc/UTC | Timezone |
MARIADB_ENCRYPTION_KEY | (unset) | Set to a non-empty passphrase to enable data-at-rest encryption (see below) |
Plus all standard MariaDB variables (MARIADB_ROOT_PASSWORD, MARIADB_DATABASE, MARIADB_USER, MARIADB_PASSWORD, …) and MariaDB config files mounted under /etc/mysql/.
| Port | Protocol | Purpose |
|---|---|---|
3306 | TCP | MariaDB |
/var/lib/mysql — the MariaDB data directory; persist this across restarts.MariaDB is GPLv2. This image's packaging — the Dockerfile, knot-entrypoint and supporting scripts/configs — is Apache License 2.0.
Source: paularlott/knot-base-images.
Content type
Image
Digest
sha256:5f4e9b072…
Size
177.8 MB
Last updated
7 days ago
docker pull paularlott/knot-mariadb:12.3-20260929