How to Install MariaDB on Rocky Linux
In Rocky Linux, you can start the MariaDB server by installing the mariadb-server package and enabling the mariadb service. After installation, clean up unnecessary default accounts using mariadb-secure-installation, and create and use an account with minimal privileges for applications instead of root.
Check provided versions and packages
cat /etc/rocky-release dnf info mariadb-server dnf module list mariadb
Support for module commands and provided versions vary depending on the Rocky Linux version and DNF implementation. If an application requires a specific major MariaDB version, choose either the default repository or the official MariaDB repository, and do not mix server packages from different repositories.
Install and start MariaDB
Install server package
sudo dnf install mariadb-server
Check the installation results.
rpm -q mariadb-server mariadb --version
Enable the service
sudo systemctl enable --now mariadb systemctl status mariadb
If startup fails, check the following logs for the cause.
journalctl -u mariadb -b --no-pager
Verify Local Administrator Access
sudo mariadb
Recently, it is common for MariaDB to be configured to use Unix socket authentication for the root database account. In this case, you can access it locally with Linux administrative privileges, and you may not need to create a separate database root password.
Set Initial Security
sudo mariadb-secure-installation
This tool interactively sets the removal of anonymous users, restriction of remote root access, removal of test databases, and more. Since MariaDB 10.4, the old guidance and question flow may differ due to Unix socket authentication. For more details, check the official MariaDB secure installation document.
The mysql_secure_installation name may remain as a compatibility link, but in the new document, it is clearer to use mariadb-secure-installation.
Create Application Database and Account
Create Database
CREATE DATABASE appdb CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
Collation rules affect search and sort results as well as index behavior. Check your application requirements and the support list of the MariaDB version you are using.
Create Local-Only User
CREATE USER 'appuser'@'localhost' IDENTIFIED BY 'replace-with-a-strong-secret'; GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'appuser'@'localhost';
Do not use the example password as is. Grant only the permissions required by the application and avoid GRANT ALL ON *.* and remote root access.
Check Permissions
SHOW GRANTS FOR 'appuser'@'localhost';
In recent versions of MariaDB, account and permission changes take effect immediately, so it is not necessary to always execute FLUSH PRIVILEGES after the usual CREATE USER and GRANT. Do not modify the privilege tables directly.
Allow Remote Access Selectively
Check Current Receiving Settings
sudo mariadbd --print-defaults ss -lntp | grep 3306
The location of configuration files and the order of application may vary depending on the package. Check the include relationship of /etc/my.cnf and /etc/my.cnf.d/ and back up existing files.
Accept Connections Only from Specific Server Addresses
Review the configuration that specifies an actual private IP in the [mysqld] section.
[mysqld] bind-address = 192.0.2.20
0.0.0.0 listens on all IPv4 interfaces, so limit it to a specific address unless absolutely necessary. For remote connection settings, you can refer to the official MariaDB remote connection guide.
Remote-only users and firewall restrictions
CREATE USER 'appuser'@'192.0.2.10' IDENTIFIED BY 'replace-with-a-strong-secret'; GRANT SELECT, INSERT, UPDATE, DELETE ON appdb.* TO 'appuser'@'192.0.2.10';
sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.0.2.10/32" port port="3306" protocol="tcp" accept' sudo firewall-cmd --runtime-to-permanent
Replace the documentation address with the actual application server address. Avoid combinations where the user host is % and the port is open to the entire internet.
Apply settings and test the connection
sudo systemctl restart mariadb sudo systemctl status mariadb ss -lntp | grep 3306
Connect from the client.
mariadb --host=192.0.2.20 --user=appuser --password appdb
If you do not attach a value directly after --password, you can enter it interactively. Specifying the password on the command line may expose it in shell history and process lists.
If passing through an untrusted network, configure TLS certificates and make the client verify the server certificate.
Checks Before Updates and Backups
- Regularly back up data and configuration files and test recovery on another system.
- Before changing the major version, check the release notes, removed features, and character set and collation compatibility.
- After a package update, check the installed version documentation to see whether to run
mariadb-upgradeif necessary. - Monitor disk usage, connections, slow queries, replication status, and error logs.
- Protect application credentials with configuration file permissions or a secret management system.
Frequently Asked Questions
sudo mariadb works, but mariadb -u root -p fails.
This may be because the root account uses Unix socket authentication. Check the current authentication plugin and, unless there is a specific reason, keep the local administrator access method.
External access is not working
Check bind-address, the Host value of the remote user account, the reception status of port 3306, firewalld, and cloud security groups in order.
Is it okay to open port 3306 to the entire internet?
It is not recommended. Limit it to the fixed address of the application server or the private network, and use VPN, TLS, and least privilege accounts together.
Can I use mysql_secure_installation?
It may be provided as a compatibility name, but the current name in the MariaDB documentation is mariadb-secure-installation. Check the installed executable and version documentation.
Summary
Install mariadb-server, activate the service, and then run the initial security tool. Use a separate database and least privilege account for the application.
If remote access is necessary, only listen from specific private addresses, restrict the account Host and firewall source addresses, and prepare TLS and backup/recovery procedures.









