Sign inSign up

silvarcode/sc-mysql-c-router

By silvarcode

•Updated 4 months ago

Oracle Linux 9-based image with MySQL Router 8.0 and MySQL Client for secure database routing.

Image
Security
Developer tools
Databases & storage
0

457

silvarcode/sc-mysql-c-router repository overview

⁠silvarcode/sc-mysql-c-router

A lightweight Docker image based on Oracle Linux 9 (slim), featuring MySQL Router 8.0.40 and the MySQL Community Client. This image is designed for secure and efficient routing in MySQL environments, with support for dynamic signaling to control operations.


⁠Features

  • Base Image: Oracle Linux 9 (slim)
  • MySQL Router Version: 8.0.40
  • Included Tools:
    • MySQL Community Client
    • Custom signal-handling scripts for operational control
  • Security:
    • Runs as a non-root user (mysqlrouter)
    • GPG keys securely imported from MySQL official repositories
  • Healthcheck:
    • Monitors connectivity on port 6446

⁠Environment Variables

This image supports configurable shared volume paths for signal handling:

  • MYSQL_SV_DIR: Base directory for shared volumes (default: /shared-volume)
  • MYSQL_SV_SIGNAL_ROUTER_DIR: Directory for router signals (default: ${MYSQL_SV_DIR}/mysql-router)
  • MYSQL_SV_SIGNAL_ROUTER_START_FILE: File to signal router start (default: ${MYSQL_SV_SIGNAL_ROUTER_DIR}/start)
  • MYSQL_SV_SIGNAL_ROUTER_RESTART_FILE: File to signal router restart (default: ${MYSQL_SV_SIGNAL_ROUTER_DIR}/restart)

⁠Exposed Ports

  • 6446–6450: MySQL Router ports
  • 8443: SSL connection port

⁠Secrets Importer Description

This image includes a Secrets Importer feature, which enhances security and flexibility when managing sensitive data such as passwords and configuration details. Instead of directly defining sensitive environment variables, you can use secrets stored in files (e.g., Docker secrets) and reference them securely.

⁠How the Secrets Importer Works

⁠Environment Variable Suffix
  • Any environment variable suffixed with __FILE is automatically processed by the Secrets Importer.
  • The importer reads the value from the file specified by the __FILE environment variable and assigns it to the corresponding variable without the suffix.
⁠Examples:
  • MYSQL_USER__FILE=/run/secrets/db_user_router
    → The content of /run/secrets/db_user_router will be assigned to MYSQL_USER.

  • MYSQL_PASSWORD__FILE=/run/secrets/db_user_router_pass
    → The content of /run/secrets/db_user_router_pass will be assigned to MYSQL_PASSWORD.

⁠Variable Overwriting
  • The importer ensures that any variable defined using the __FILE mechanism overrides the existing value of the corresponding environment variable.
  • This makes it easy to transition between using secrets and hardcoded environment variables.

⁠Security Benefits

  • Secrets are stored securely as files and are not directly exposed in environment variables.
  • This approach minimizes the risk of accidental exposure in logs or error messages.

⁠Configuration Options

  • The Secrets Importer includes a SECRETS_IMPORTER_QUIET flag.
    When set to true, it suppresses logs related to secret import operations, making it ideal for production environments.

⁠Usage

⁠Pull the Image
docker pull silvarcode/sc-mysql-c-router:8.0.40

Tag summary

Content type

Image

Digest

sha256:531f4024a…

Size

91.2 MB

Last updated

11 months ago

docker pull silvarcode/sc-mysql-c-router:8.0.40