Skip to content

Connect to MySQL

Tested with: MySQL 8.4.6 on Databasezy (Percona Operator) · drivers listed per tab · zb CLI 0.1

  1. Copy the host and port from the instance’s Connect tab. Credentials were shown once at creation.
  2. Download the CA bundle (zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pem). The MySQL protocol sends the server greeting before TLS, so the gateway cannot fall back to a public certificate for clients that skip verification: always pass the CA and ask for identity verification.
  3. Add your egress IPs under Network → Allow-list.
  4. Use a snippet below. Each one sets VERIFY_IDENTITY (chain and hostname) or the driver’s equivalent.

MySQL listens on port 3306 (MySQL wire protocol). Versions: 8.4, 8.0. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.

Connection URI
mysql://app:<password>@mysql-7f3k.us-east.databasezy.com:3306/app?ssl-mode=VERIFY_IDENTITY&ssl-ca=databasezy-ca.pem
db.js
import { readFileSync } from "node:fs";
import mysql from "mysql2/promise";
export const pool = mysql.createPool({
host: "mysql-7f3k.us-east.databasezy.com",
port: 3306,
user: "app",
password: process.env.ZB_PASSWORD,
database: "app",
ssl: {
ca: readFileSync("databasezy-ca.pem", "utf8"),
rejectUnauthorized: true, // verify chain and hostname
},
connectionLimit: 10,
});
const [rows] = await pool.query("select version() as v");
console.log(rows[0].v);

Tested with: MySQL 8.4 · mysql2 3.11

  • Clients must use --ssl-mode=REQUIRED or stricter; VERIFY_IDENTITY is what the snippets use.
  • MySQL 8.4 defaults to caching_sha2_password, which needs TLS or the server public key; on Databasezy TLS is always on so no extra flag is needed.
  • Java needs the CA in a PKCS12 truststore; the one-line keytool import is in the Java tab.
  • max_connections comes from the size; leave headroom for replication and the backup agent (about 10 connections).
  • MySQL has no transaction-mode pooler on Databasezy yet; use your driver’s pool (connectionLimit, HikariCP, SetMaxOpenConns) and keep connections alive with a validation query.
  • Set wait_timeout awareness in your pool: the server closes idle sessions after 8 hours; pools should validate on borrow.

Enforced at the gateway on every plan. Replication users and the migration agent connect from inside the cell and are not subject to the list.