Skip to main content
See All Integrations

MySQL

Protect access to MySQL services through Pomerium TCP routes.

First-party Pomerium access capability

Categories
Databases, Non-HTTP Services

Overview

MySQL is a relational database system. Clients normally use the MySQL protocol over TCP port 3306 or a local Unix socket. A Pomerium tunnel supplies a local TCP listener for the private database endpoint.

MySQL can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to MySQL. MySQL remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.

Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.

Configure the MySQL client for the local Pomerium listener and the required TLS mode. Keep the real database hostname in certificate validation when the client supports that design.

Example

A database user starts a Pomerium tunnel and points the MySQL client to the loopback address and local port. Pomerium checks route access. MySQL still checks the database account and SQL permissions.

Considerations

  • Force TCP when a local client would otherwise choose a Unix socket.
  • Preserve MySQL TLS and account authentication. Use a distinct local port for every protected database route.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to PostgreSQL services through Pomerium TCP routes.

  • Protect access to MongoDB services through Pomerium TCP routes.

  • Connect DBeaver to protected database services through Pomerium TCP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo