MySQL (stack)
MySQL 8.4 LTS - the world's most popular open- source relational database, as a single self-hosted node. Configured entirely through the official image's environment variables, with data on a volume.
Image details
Configuration
TypeComposelinuxmysql:8.43306:3306/var/lib/mysql : mysqldataMYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD}MYSQL_DATABASE=${MYSQL_DATABASE:-app}MYSQL_USER=${MYSQL_USER:-app}MYSQL_PASSWORD=${MYSQL_PASSWORD}unless-stoppedTemplate by deployable-sh·Source
Report issueStandalone Install
Select an install method, to see config/commands for deploying MySQL (stack)
Install on Portainer
Import all app templates into your Portainer instance, for easy 1-click deploys
- Ensure both Docker and Portainer are installed, and up-to-date
- Log into your Portainer web UI
- Under Settings → App Templates, paste the below URL
- Head to Home → App Templates, and the list of apps will show up
- Select MySQL (stack), fill in any config options, and hit Deploy
Template Import URL
https://raw.githubusercontent.com/Lissy93/portainer-templates/main/templates.json
Show Me
Original stackfile
The compose file this template deploys, straight from its repo:
name: mysql
services:
mysql:
healthcheck:
test: ["CMD", "mysqladmin", "ping", "-h", "127.0.0.1"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
image: mysql:8.4
restart: unless-stopped
environment:
MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD}
MYSQL_DATABASE: ${MYSQL_DATABASE:-app}
MYSQL_USER: ${MYSQL_USER:-app}
MYSQL_PASSWORD: ${MYSQL_PASSWORD}
ports:
- "3306:3306"
volumes:
- mysqldata:/var/lib/mysql
volumes:
mysqldata:
Or deploy it directly from the source:
git clone https://github.com/deployable-sh/stacks
cd stacks
docker compose -f mysql/compose.yaml up -dMore install options in our documentation.
Quick reference
- Maintained by:
[the Docker Community and the MySQL Team](https://github.com/docker-library/mysql)- Where to get help:
[the Docker Community Slack](https://dockr.ly/comm-slack), [Server Fault](https://serverfault.com/help/on-topic), [Unix & Linux](https://unix.stackexchange.com/help/on-topic), or [Stack Overflow](https://stackoverflow.com/help/on-topic)Supported tags and respective Dockerfile links
Quick reference (cont.)
- Where to file issues:
[https://github.com/docker-library/mysql/issues](https://github.com/docker-library/mysql/issues?q=is:issue+is:pr)- Supported architectures: (more info)
[`amd64`](https://hub.docker.com/r/amd64/mysql/), [`arm64v8`](https://hub.docker.com/r/arm64v8/mysql/)- Published image artifact details:
[repo-info repo's `repos/mysql/` directory](https://github.com/docker-library/repo-info/blob/master/repos/mysql) ([history](https://github.com/docker-library/repo-info/commits/master/repos/mysql))
(image metadata, transfer size, etc)- Image updates:
[official-images repo's `library/mysql` label](https://github.com/docker-library/official-images/issues?q=label%3Alibrary%2Fmysql)
[official-images repo's `library/mysql` file](https://github.com/docker-library/official-images/blob/master/library/mysql) ([history](https://github.com/docker-library/official-images/commits/master/library/mysql))- Source of this description:
[docs repo's `mysql/` directory](https://github.com/docker-library/docs/tree/master/mysql) ([history](https://github.com/docker-library/docs/commits/master/mysql))What is MySQL?
MySQL is the world's most popular open source database. With its proven performance, reliability and ease-of-use, MySQL has become the leading database choice for web-based applications, covering the entire range from personal projects and websites, via e-commerce and information services, all the way to high profile web properties including Facebook, Twitter, YouTube, Yahoo! and many more.For more information and related downloads for MySQL Server and other MySQL products, please visit www.mysql.com.

How to use this image
Start a mysql server instance
Starting a MySQL instance is simple:$ docker run --name some-mysql -e MYSQL_ROOT_PASSWORD=my-secret-pw -d mysql:tag... where
some-mysql is the name you want to assign to your container, my-secret-pw is the password to be set for the MySQL root user and tag is the tag specifying the MySQL version you want. See the list above for relevant tags.Connect to MySQL from the MySQL command line client
The following command starts anothermysql container instance and runs the mysql command line client against your original mysql container, allowing you to execute SQL statements against your database instance:$ docker run -it --network some-network --rm mysql mysql -hsome-mysql -uexample-user -p... where
some-mysql is the name of your original mysql container (connected to the some-network Docker network).This image can also be used as a client for non-Docker or remote instances:
$ docker run -it --rm mysql mysql -hsome.mysql.host -usome-mysql-user -pMore information about the MySQL command line client can be found in the MySQL documentation
... via docker compose
Example compose.yaml for mysql:# Use root/example as user/password credentials
services:
db:
image: mysql
restart: always
environment:
MYSQL_ROOT_PASSWORD: example
# (this is just an example, not intended to be a production configuration)Run
docker compose up, wait for it to initialize completely, and visit http://localhost:8080 or http://host-ip:8080 (as appropriate).Container shell access and viewing MySQL logs
Thedocker exec command allows you to run commands inside a Docker container. The following command line will give you a bash shell inside your mysql container:$ docker exec -it some-mysql bashThe log is available through Docker's container log:
$ docker logs some-mysqlUsing a custom MySQL configuration file
The default configuration for MySQL varies depending on the base image:Oracle-based images (default): The default configuration is located at
/etc/my.cnf, which may !includedir additional directories such as /etc/mysql/conf.d.Debian-based MySQL 8 images: The default configuration can be found in
/etc/mysql/my.cnf, which may !includedir additional directories such as /etc/mysql/conf.d.Please inspect the relevant files and directories within the
mysql image itself for more details.If
/my/custom/config-file.cnf is the path and name of your custom configuration file, you can start your mysql container like this (note that only the directory path of the custom config file is used in this command):$ docker run --name some-mysql -v /my/custom:/etc/mysql/conf.d -e MYSQL_ROOT_PASSWORD=my-secret-pw -d mysql:tagThis will start a new container
some-mysql where the MySQL instance uses the combined startup settings from the default configuration file and /etc/mysql/conf.d/config-file.cnf, with settings from the latter taking precedence.Configuration without a cnf file
Many configuration options can be passed as flags to mysqld. This will give you the flexibility to customize the container without needing a cnf file. For example, if you want to change the default encoding and collation for all tables to use UTF-8 (utf8mb4) just run the following:$ docker run --name some-mysql -e MYSQL_ROOT_PASSWORD=my-secret-pw -d mysql:tag --character-set-server=utf8mb4 --collation-server=utf8mb4_unicode_ciIf you would like to see a complete list of available options, just run:
$ docker run -it --rm mysql:tag --verbose --helpEnvironment Variables
When you start themysql image, you can adjust the configuration of the MySQL instance by passing one or more environment variables on the docker run command line. Do note that none of the variables below will have any effect if you start the container with a data directory that already contains a database: any pre-existing database will always be left untouched on container startup.See also https://dev.mysql.com/doc/refman/5.7/en/environment-variables.html for documentation of environment variables which MySQL itself respects (especially variables like
MYSQL_HOST, which is known to cause issues when used with this image).MYSQL_ROOT_PASSWORD
This variable is mandatory and specifies the password that will be set for the MySQL root superuser account. In the above example, it was set to my-secret-pw.MYSQL_DATABASE
This variable is optional and allows you to specify the name of a database to be created on image startup. If a user/password was supplied (see below) then that user will be granted superuser access (corresponding to GRANT ALL) to this database.MYSQL_USER, MYSQL_PASSWORD
These variables are optional, used in conjunction to create a new user and to set that user's password. This user will be granted superuser permissions (see above) for the database specified by the MYSQL_DATABASE variable. Both variables are required for a user to be created.Do note that there is no need to use this mechanism to create the root superuser, that user gets created by default with the password specified by the
MYSQL_ROOT_PASSWORD variable.MYSQL_ALLOW_EMPTY_PASSWORD
This is an optional variable. Set to a non-empty value, like yes, to allow the container to be started with a blank password for the root user. NOTE: Setting this variable to yes is not recommended unless you really know what you are doing, since this will leave your MySQL instance completely unprotected, allowing anyone to gain complete superuser access.MYSQL_RANDOM_ROOT_PASSWORD
This is an optional variable. Set to a non-empty value, like yes, to generate a random initial password for the root user (using openssl). The generated root password will be printed to stdout (GENERATED ROOT PASSWORD: .....).MYSQL_ONETIME_PASSWORD
Sets root (not the user specified in MYSQL_USER!) user as expired once init is complete, forcing a password change on first login. Any non-empty value will activate this setting. NOTE: This feature is supported on MySQL 5.6+ only. Using this option on MySQL 5.5 will throw an appropriate error during initialization.MYSQL_INITDB_SKIP_TZINFO
By default, the entrypoint script automatically loads the timezone data needed for the CONVERT_TZ() function. If it is not needed, any non-empty value disables timezone loading.Docker Secrets
As an alternative to passing sensitive information via environment variables,_FILE may be appended to the previously listed environment variables, causing the initialization script to load the values for those variables from files present in the container. In particular, this can be used to load passwords from Docker secrets stored in /run/secrets/<secret_name> files. For example:$ docker run --name some-mysql -e MYSQL_ROOT_PASSWORD_FILE=/run/secrets/mysql-root -d mysql:tagCurrently, this is only supported for
MYSQL_ROOT_PASSWORD, MYSQL_ROOT_HOST, MYSQL_DATABASE, MYSQL_USER, and MYSQL_PASSWORD.Initializing a fresh instance
When a container is started for the first time, a new database with the specified name will be created and initialized with the provided configuration variables. Furthermore, it will execute files with extensions.sh, .sql, .sql.gz, .sql.bz2, .sql.xz, and .sql.zst that are found in /docker-entrypoint-initdb.d. Files will be executed in alphabetical order. When parsing .sh files without the execute bit set, they are sourced rather than executed.You can easily populate your
mysql services by mounting a SQL dump into that directory and provide custom images with contributed data. SQL files will be imported by default to the database specified by the MYSQL_DATABASE variable.Caveats
Where to Store Data
Important note: There are several ways to store data used by applications that run in Docker containers. We encourage users of themysql images to familiarize themselves with the options available, including:- Let Docker manage the storage of your database data by writing the database files to disk on the host system using its own internal volume management. This is the default and is easy and fairly transparent to the user. The downside is that the files may be hard to locate for tools and applications that run directly on the host system, i.e. outside containers.
- Create a data directory on the host system (outside the container) and mount this to a directory visible from inside the container. This places the database files in a known location on the host system, and makes it easy for tools and applications on the host system to access the files. The downside is that the user needs to make sure that the directory exists, and that e.g. directory permissions and other security mechanisms on the host system are set up correctly.
The Docker documentation is a good starting point for understanding the different storage options and variations, and there are multiple blogs and forum postings that discuss and give advice in this area. We will simply show the basic procedure here for the latter option above:
- Create a data directory on a suitable volume on your host system, e.g.
/my/own/datadir. - Start your
mysqlcontainer like this:
```console
$ docker run --name some-mysql -v /my/own/datadir:/var/lib/mysql -e MYSQL_ROOT_PASSWORD=my-secret-pw -d mysql:tag
```The -v /my/own/datadir:/var/lib/mysql part of the command mounts the /my/own/datadir directory from the underlying host system as /var/lib/mysql inside the container, where MySQL by default will write its data files.No connections until MySQL init completes
If there is no database initialized when the container starts, then a default database will be created. While this is the expected behavior, this means that it will not accept incoming connections until such initialization completes. This may cause issues when using automation tools, such as Docker Compose, which start several containers simultaneously.If the application you're trying to connect to MySQL does not handle MySQL downtime or waiting for MySQL to start gracefully, then putting a connect-retry loop before the service starts might be necessary. For an example of such an implementation in the official images, see WordPress or Bonita.
Usage against an existing database
If you start yourmysql container instance with a data directory that already contains a database (specifically, a mysql subdirectory), the $MYSQL_ROOT_PASSWORD variable should be omitted from the run command line; it will in any case be ignored, and the pre-existing database will not be changed in any way.Running as an arbitrary user
If you know the permissions of your directory are already set appropriately (such as running against an existing database, as described above) or you have need of runningmysqld with a specific UID/GID, it is possible to invoke this image with --user set to any value (other than root/0) in order to achieve the desired access/configuration:$ mkdir data
$ ls -lnd data
drwxr-xr-x 2 1000 1000 4096 Aug 27 15:54 data
$ docker run -v "$PWD/data":/var/lib/mysql --user 1000:1000 --name some-mysql -e MYSQL_ROOT_PASSWORD=my-secret-pw -d mysql:tagCreating database dumps
Most of the normal tools will work, although their usage might be a little convoluted in some cases to ensure they have access to themysqld server. A simple way to ensure this is to use docker exec and run the tool from the same container, similar to the following:$ docker exec some-mysql sh -c 'exec mysqldump --all-databases -uroot -p"$MYSQL_ROOT_PASSWORD"' > /some/path/on/your/host/all-databases.sqlRestoring data from dump files
For restoring data. You can usedocker exec command with -i flag, similar to the following:$ docker exec -i some-mysql sh -c 'exec mysql -uroot -p"$MYSQL_ROOT_PASSWORD"' < /some/path/on/your/host/all-databases.sqlLicense
View license information for the software contained in this image.As with all Docker images, these likely also contain other software which may be under other licenses (such as Bash, etc from the base distribution, along with any direct or indirect dependencies of the primary software being contained).
Some additional license information which was able to be auto-detected might be found in the
repo-info repository's mysql/ directory.As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.
Serve MySQL (stack) on your own domain behind Caddy, Nginx or Traefik. Fill in your domain and copy the result. It's a starting point, some apps need their own base URL or extra headers set too.
Proxying mysql-stack.example.com to http://mysql:3306
Add this to your Caddyfile
mysql-stack.example.com {
reverse_proxy http://mysql:3306
}Check the logs first
Nine times out of ten the logs tell you exactly what went wrong.
- In Portainer, go to Containers, click the container, then Logs. Or run
docker logs <container> - Exit codes help too:
137means killed, usually out of memory.126or127means the command inside the image is broken.
Port already in use
If deployment fails with "Bind for 0.0.0.0:3306 failed: port is already allocated", something else on your server is using that port.
- Find what's using it:
sudo ss -tlnp | grep :3306 - Stop the other service, or pick a different host port. In
3306:3306only the left number is yours to change, the right one belongs to the app.
Running but the page won't load
The container is up but nothing appears in your browser.
- Use your server's real IP:
http://your-server-ip:3306. The 0.0.0.0 link Portainer shows isn't a real address. - Give it a minute after first deploy, mysql can take a while to initialise.
- Make sure your firewall allows the port, e.g.
sudo ufw allow 3306
Image won't pull
Test the pull directly on the host: docker pull mysql:8.4
- "manifest unknown" means the tag no longer exists.
- "toomanyrequests" is the Docker Hub rate limit. Log in with
docker loginto raise it. - "no space left on device" means a full disk. Reclaim space with
docker system prune
"exec format error"
This means the image was built for a different CPU architecture than your server.
- This image supports:
amd64, arm64/v8 - Check yours with
uname -m: x86_64 is amd64, aarch64 is arm64. Raspberry Pi and other ARM boards are the usual culprits.
Container keeps restarting
The unless-stopped restart policy relaunches the app after every crash, so the real error can scroll past.
- Check the logs right after a restart, the last few lines before it died are the useful ones.
- Get the exit code with
docker inspect <container> --format '{{.State.ExitCode}}' - Still stuck? Redeploy once with the restart policy set to
noso the failure stays visible.
Stack won't deploy
Compose stacks fail fast on small mistakes, and Portainer shows the reason just above the editor.
- YAML only accepts spaces for indentation, a single tab breaks the whole file.
Raise an issue
Found something which isn't working as it should? Here's how to report it.
- Bug within the app: Open an issue within mysql's repo
- Template not working: Open an issue on deployable-sh/stacks
- This website not working: Open an issue on lissy93/portainer-templates
A Compose stack
MySQL (stack) is a Compose stack, a set of containers defined in one file and brought up together by Portainer, then started and stopped as a single app.
The app image
An image is the app packed up ready to go, everything MySQL (stack) needs bundled into one download. This template pulls mysql:8.4, which Docker fetches once (about 258 MB) and then starts your own copy from.
Where the image comes from
Docker pulls its images from registries, public libraries of ready-built apps. MySQL (stack)'s comes from Docker Hub as one of its official, curated images.
Version tags
The bit after the colon in the image name is the version tag. This one pins 8.4, so every redeploy gives you that exact build until you bump it yourself.
Which machines it runs on
Every image is built for particular CPU types. This one ships for amd64, arm64/v8, so it runs on both regular x86 servers and ARM boards like a Raspberry Pi.
Ports
A port is the door the app answers on. A mapping like 3306:3306 means it's reachable on port 3306 of your server, where the left number is yours to change and the right one belongs to the app. It opens:
3306:3306
Volumes
A volume is where MySQL (stack) keeps its files so they survive an update or a restart. Without one, anything it saves would sit inside the container and vanish the moment it's recreated. This template mounts:
/var/lib/mysqlkept in themysqldatavolume Docker manages
Environment variables
Environment variables are the settings you hand over when you deploy, things like a password or a timezone. MySQL (stack) takes 4 of them, all with defaults you can leave alone or tweak:
MYSQL_ROOT_PASSWORD, pulled from your own environment. Root password (required).MYSQL_DATABASE, defaults toapp. Application database + user created on first boot.MYSQL_USER, defaults toappMYSQL_PASSWORD, pulled from your own environment
Restart policy
The restart policy here is unless-stopped, so Docker restarts MySQL (stack) after a crash or reboot, but leaves it off when you stop it on purpose. You can change this on the deploy screen. The choices are no (never restart), on-failure (only after a crash), unless-stopped (restart unless you stop it), and always (bring it back no matter what).
Health check
A health check is how Docker tells whether MySQL (stack) is really working, not just switched on. It runs mysqladmin ping -h 127.0.0.1 every 10s and flags the container as unhealthy if that keeps failing.
Networking
Nothing custom is set, so MySQL (stack) sits on Docker's default bridge network: its own private space that reaches the outside world only through the ports it publishes.
Container name
Once it's deployed, Portainer names the container mysql. That's what you'll spot in the containers list and use in commands like docker logs mysql.
Platform
The platform is linux, the kind of system the container is built to run on. Docker and Portainer handle this on a normal Linux server.
Portainer app templates
Zooming out, this whole page comes from a Portainer app template: a short recipe telling Portainer how to set MySQL (stack) up. Add the template list to Portainer once, then deploying MySQL (stack) is a click rather than a wall of config.
ClickHouse Cluster Databases
MariaDB Galera Databases
MariaDB Replication Databases
MongoDB Replica Set Databases
MySQL InnoDB Cluster Databases
Mysql-workbench Databases
Oracle Database Free Databases
- Percona Server Databases
- Percona XtraDB Cluster Databases
Phpmyadmin Databases
Sqlitebrowser Databases