Skip to main content
To add a MySQL database, go to Instances, click Connect instance, and choose MySQL. Bytebase lists every database on the server except information_schema, mysql, performance_schema, and sys as a Bytebase database. See Database.

Supported versions

Bytebase supports MySQL 5.7 and later, including Amazon Aurora MySQL. It connects through a built-in driver, so there is nothing to install.

Create a user for Bytebase

Connect as an administrator and create a dedicated user for Bytebase. The examples name it bytebase. For MySQL 8.0 and 5.7:
MySQL 8.4 removed SET_USER_ID, and naming it there is a syntax error. For MySQL 8.4 and later, replace the /*!80000 , SET_USER_ID */ line with , SET_ANY_DEFINER, ALLOW_NONEXISTENT_DEFINER. On Amazon RDS for MySQL, run the statement as the master user. Before version 8.0.36, the master user doesn’t have SET_USER_ID, so leave that line out. For a read-only connection, create a separate user:

Connection details

Authentication

How Bytebase signs in:
  • Plain Password: the Username and Password below.
  • AWS RDS IAM: an IAM authentication token for Amazon RDS or Aurora. See AWS.
  • Google Cloud SQL IAM: an IAM service account for Cloud SQL. See GCP.

Hostname

The host name or IP address of the MySQL server, such as db.example.com. With Verify server certificate on, it must be one of the names in the server’s certificate.

Port

The server port. MySQL’s default is 3306.

Username

The MySQL account Bytebase connects as.

Password

The account’s password. You can also read it from a secret manager.

TLS

TLS mode decides whether Bytebase encrypts the connection:
  • Disabled: the connection is unencrypted, even when the server offers TLS.
  • TLS: Bytebase encrypts the connection.
  • Mutual TLS: the same as TLS, and Bytebase also presents a client certificate. Use it for accounts created with REQUIRE X509, REQUIRE SUBJECT, or REQUIRE ISSUER.
Under Server identity, turn on Verify server certificate so that Bytebase checks the server’s certificate and confirms that Hostname is one of the names in it. CA certificate source sets which certificate authority (CA) the check trusts:
  • System trust: the CAs that the machine running Bytebase already trusts.
  • Paste PEM: a CA certificate you paste in PEM format, for a private CA or a self-signed certificate.
  • File path: a CA certificate file on the Bytebase server. Not available in Bytebase Cloud.
The certificates that MySQL generates on its own at first start have no Subject Alternative Names, so verification always fails against them. To verify the server, install a certificate that names the server’s host, set through ssl_ca, ssl_cert, and ssl_key. With verification off, the connection is encrypted, but Bytebase doesn’t check which server it reached. Use that only for testing. For Mutual TLS, set Client identity source to Paste PEM or File path, and provide the client certificate and its private key.

SSH tunnel

Connects through a bastion host. See SSH Tunnel.

Extra Parameters

Options that Bytebase passes to the driver as key-value pairs, using the driver’s parameter names such as timeout and readTimeout. The driver sends any name it doesn’t recognize to MySQL as a session variable, so a server-wide setting such as connect_timeout fails. With TLS mode set to Disabled, the tls parameter controls encryption, so tls with the value skip-verify encrypts the connection without verifying the server. Bytebase refuses allowAllFiles, which would let the server read any file on the Bytebase server.

Troubleshooting

Test Connection shows the error from the server or the driver:

Read-only connection

A read-only connection has its own TLS settings and Extra Parameters. Set them the same way as for the admin connection.