How to Install MariaDB on Rocky Linux

In Rocky Linux, you can start the MariaDB server by installing the mariadb-server package and enabling the mariadb service. After installation, clean up unnecessary default accounts using mariadb-secure-installation, and create and use an account with minimal privileges for applications instead of root.

Check provided versions and packages

cat /etc/rocky-release
dnf info mariadb-server
dnf module list mariadb

Support for module commands and provided versions vary depending on the Rocky Linux version and DNF implementation. If an application requires a specific major MariaDB version, choose either the default repository or the official MariaDB repository, and do not mix server packages from different repositories.

Install and start MariaDB

Install server package

sudo dnf install mariadb-server

Check the installation results.

rpm -q mariadb-server
mariadb --version

Enable the service

sudo systemctl enable --now mariadb
systemctl status mariadb

If startup fails, check the following logs for the cause.

journalctl -u mariadb -b --no-pager

Verify Local Administrator Access

sudo mariadb

Recently, it is common for MariaDB to be configured to use Unix socket authentication for the root database account. In this case, you can access it locally with Linux administrative privileges, and you may not need to create a separate database root password.

Set Initial Security

sudo mariadb-secure-installation

This tool interactively sets the removal of anonymous users, restriction of remote root access, removal of test databases, and more. Since MariaDB 10.4, the old guidance and question flow may differ due to Unix socket authentication. For more details, check the official MariaDB secure installation document.

The mysql_secure_installation name may remain as a compatibility link, but in the new document, it is clearer to use mariadb-secure-installation.

Create Application Database and Account

Create Database

CREATE DATABASE appdb CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;

Collation rules affect search and sort results as well as index behavior. Check your application requirements and the support list of the MariaDB version you are using.

Create Local-Only User

CREATE USER 'appuser'@'localhost' IDENTIFIED BY 'replace-with-a-strong-secret';
GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'appuser'@'localhost';

Do not use the example password as is. Grant only the permissions required by the application and avoid GRANT ALL ON *.* and remote root access.

Check Permissions

SHOW GRANTS FOR 'appuser'@'localhost';

In recent versions of MariaDB, account and permission changes take effect immediately, so it is not necessary to always execute FLUSH PRIVILEGES after the usual CREATE USER and GRANT. Do not modify the privilege tables directly.

Allow Remote Access Selectively

Check Current Receiving Settings

sudo mariadbd --print-defaults
ss -lntp | grep 3306

The location of configuration files and the order of application may vary depending on the package. Check the include relationship of /etc/my.cnf and /etc/my.cnf.d/ and back up existing files.

Accept Connections Only from Specific Server Addresses

Review the configuration that specifies an actual private IP in the [mysqld] section.

[mysqld]
bind-address = 192.0.2.20

0.0.0.0 listens on all IPv4 interfaces, so limit it to a specific address unless absolutely necessary. For remote connection settings, you can refer to the official MariaDB remote connection guide.

Remote-only users and firewall restrictions

CREATE USER 'appuser'@'192.0.2.10' IDENTIFIED BY 'replace-with-a-strong-secret';
GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'appuser'@'192.0.2.10';
sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.0.2.10/32" port port="3306" protocol="tcp" accept'
sudo firewall-cmd --runtime-to-permanent

Replace the documentation address with the actual application server address. Avoid combinations where the user host is % and the port is open to the entire internet.

Apply settings and test the connection

sudo systemctl restart mariadb
sudo systemctl status mariadb
ss -lntp | grep 3306

Connect from the client.

mariadb --host=192.0.2.20 --user=appuser --password appdb

If you do not attach a value directly after --password, you can enter it interactively. Specifying the password on the command line may expose it in shell history and process lists.

If passing through an untrusted network, configure TLS certificates and make the client verify the server certificate.

Checks Before Updates and Backups

  • Regularly back up data and configuration files and test recovery on another system.
  • Before changing the major version, check the release notes, removed features, and character set and collation compatibility.
  • After a package update, check the installed version documentation to see whether to run mariadb-upgrade if necessary.
  • Monitor disk usage, connections, slow queries, replication status, and error logs.
  • Protect application credentials with configuration file permissions or a secret management system.

Frequently Asked Questions

sudo mariadb works, but mariadb -u root -p fails.

This may be because the root account uses Unix socket authentication. Check the current authentication plugin and, unless there is a specific reason, keep the local administrator access method.

External access is not working

Check bind-address, the Host value of the remote user account, the reception status of port 3306, firewalld, and cloud security groups in order.

Is it okay to open port 3306 to the entire internet?

It is not recommended. Limit it to the fixed address of the application server or the private network, and use VPN, TLS, and least privilege accounts together.

Can I use mysql_secure_installation?

It may be provided as a compatibility name, but the current name in the MariaDB documentation is mariadb-secure-installation. Check the installed executable and version documentation.

Summary

Install mariadb-server, activate the service, and then run the initial security tool. Use a separate database and least privilege account for the application.

If remote access is necessary, only listen from specific private addresses, restrict the account Host and firewall source addresses, and prepare TLS and backup/recovery procedures.

More in This Category
How to Configure a Static IP Address on Rocky Linux

How to Configure a Static IP Address on Rocky Linux

Configure and verify a static IPv4 address on Rocky Linux with NetworkManager, including the gateway, DNS servers, connection profile, and safe remote-change checks.

How to Change the Hostname on Rocky Linux

How to Change the Hostname on Rocky Linux

Learn how to change a Rocky Linux hostname with hostnamectl, verify the persistent setting, and check name resolution and services afterward.

How to Configure SELinux Modes on Rocky Linux

How to Configure SELinux Modes on Rocky Linux

Check and change SELinux enforcing, permissive, and disabled modes on Rocky Linux, understand temporary and persistent changes, and troubleshoot denials safely.

How to Change the System Language and Locale on Rocky Linux

How to Change the System Language and Locale on Rocky Linux

Learn how to check and change the system-wide language and locale on Rocky Linux with localectl and glibc language packs. This guide also explains session-only changes, LANG and LC_* precedence, and troubleshooting for broken Korean characters.

How to Install MariaDB on Rocky Linux

How to Install MariaDB on Rocky Linux

Install MariaDB on Rocky Linux, enable the database service, complete the initial security setup, create a database and account, and verify access.

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

Learn how to manage firewalld on Rocky Linux with firewall-cmd, including active zones, services, custom ports, runtime and permanent rules, rich rules, and NetworkManager integration. The guide emphasizes a safe workflow for remote SSH servers.

How to Install PostgreSQL on Rocky Linux

How to Install PostgreSQL on Rocky Linux

Install PostgreSQL on Rocky Linux, initialize the database cluster, enable the service, create a database and user, and review network and authentication settings.

How to Configure Root SSH Login on Rocky Linux Safely

How to Configure Root SSH Login on Rocky Linux Safely

Review how root SSH login is controlled on Rocky Linux, why direct root access is risky, and how to change and verify sshd settings without losing remote access.

How to Install a GUI and Remote Desktop on Rocky Linux

How to Install a GUI and Remote Desktop on Rocky Linux

Install a graphical desktop on Rocky Linux, select the graphical boot target, configure remote access, and review firewall and security considerations.

How to List Installed Packages on Rocky Linux

How to List Installed Packages on Rocky Linux

Use DNF and RPM to list, search, count, and inspect installed packages on Rocky Linux and identify which package owns a file.