> ## Documentation Index
> Fetch the complete documentation index at: https://docs.myrmex.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# MySQL / MariaDB

> Connect a MySQL or MariaDB database to Myrmex — create a read-only audit user and add the integration.

import { Note, Steps, Step, CardGroup, Card, Tip } from '@mintlify/components';

Connect your **MySQL** or **MariaDB** database so Myrmex can audit its hardening and compliance, check its operational health, explore its schema, and — with approval — run SQL for you. Myrmex reaches the database over the native protocol through a [Collector](/documentation/agent-endpoint-security/collector-mode) on your network. Operations run live and on demand through the [Integration Specialist](/documentation/multi-agent-system/integration-specialist-agent) agent — Myrmex reads only what you ask for and keeps none of your data on the Myrmex side.

## What Myrmex Can Do

<CardGroup cols={2}>
  <Card title="Compliance audit" icon="shield-halved">
    Run a [Security Posture](/documentation/security-posture/overview) audit and map findings to CIS, ISO 27001, NIST CSF, and BACEN [frameworks](/documentation/security-posture/frameworks).
  </Card>

  <Card title="Health checks" icon="heart-pulse">
    Review connections, buffer pool usage, replication status, and slow queries.
  </Card>

  <Card title="Explore tables" icon="table">
    List schemas and tables so you can see what the database holds.
  </Card>

  <Card title="Describe structure" icon="sitemap">
    Inspect columns, types, indexes, and constraints for any table.
  </Card>

  <Card title="Sensitive-data scan" icon="user-secret">
    Scan tables and columns for personal or sensitive data that needs protection.
  </Card>

  <Card title="Run SQL" icon="terminal">
    Execute read queries any time; write statements (DDL/DML) require your confirmation.
  </Card>
</CardGroup>

## Before You Start

* A **Collector** on a network that can reach the MySQL/MariaDB host on its TCP port (default `3306`). See [Collector mode](/documentation/agent-endpoint-security/collector-mode).
* A **dedicated database user** for Myrmex (create it in Step 1).
* **TLS** is recommended. Set SSL Mode to `require` to encrypt the connection; servers without TLS use `disable` (the audit flags the missing encryption).

## Step 1 — Create the Credential in MySQL / MariaDB

Create a dedicated, least-privilege user for auditing. `PROCESS` plus read access to `performance_schema` and `mysql.user` cover the checks the audit runs (`information_schema` is readable by default).

```sql theme={null}
-- Restrict the host to your Collector's IP where possible
CREATE USER 'myrmex_audit'@'%' IDENTIFIED BY 'a-strong-password';
GRANT PROCESS ON *.* TO 'myrmex_audit'@'%';
GRANT SELECT ON performance_schema.* TO 'myrmex_audit'@'%';
GRANT SELECT ON mysql.user TO 'myrmex_audit'@'%';
FLUSH PRIVILEGES;
```

<Tip>
  Keep the account read-only for auditing. Grant a write-capable user only if you want the agents to run write statements (DDL/DML) through **Run SQL**.
</Tip>

## Step 2 — Add the Integration in Myrmex

From the **Directory**, choose **Add Integration → MySQL / MariaDB**, then fill in:

| Field           | Description                                                                                                               |
| --------------- | ------------------------------------------------------------------------------------------------------------------------- |
| **Name**        | A unique name for this database.                                                                                          |
| **Description** | Optional note to identify the instance.                                                                                   |
| **Host**        | MySQL/MariaDB host or IP.                                                                                                 |
| **Port**        | TCP port (default `3306`).                                                                                                |
| **Database**    | Optional target database/schema (audit uses `information_schema` by default).                                             |
| **Username**    | Audit user (read-only) or a write-capable user for operations.                                                            |
| **Password**    | Password (stored encrypted).                                                                                              |
| **SSL Mode**    | TLS posture: `require` encrypts, `verify-full` / `verify-ca` validate the certificate, `disable` for servers without TLS. |
| **Collectors**  | The [Collector(s)](/documentation/agent-endpoint-security/collector-mode) that can reach this database.                   |

## Connect

Click **Connect** to validate the login and TLS settings. The database then appears under **Environment → Integrations** alongside your other [integrations](/documentation/integrations/overview), and you can start asking the AI about it in the Workspace.

## Notes

* **Read-only by default.** Auditing, health, schema exploration, and sensitive-data scans only need the read-only user. Provide a write-capable user only if you want confirmation-gated **Run SQL** writes.
* **Nothing is stored.** Every operation runs in real time through the Collector; results return to your Workspace and no database data is retained on the Myrmex side.
* **MariaDB.** The same grants and connection settings apply to MariaDB servers.
