4 min read Sep 26, 2026

How to Secure MySQL or MariaDB on Your VPS

Lock down MariaDB or MySQL on your VPS: run the secure installation script, create least-privilege users, keep the database off the internet and connect remotely through an SSH tunnel.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

A fresh database server is working but not yet hardened: it may contain a test database, anonymous accounts and, on some systems, listen on every network interface. A few minutes of setup removes those risks. The steps are written for MariaDB, the default on Debian, Ubuntu and AlmaLinux; notes for MySQL are included.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Step 1: Run the secure installation script

sudo mariadb-secure-installation

(On MySQL, or older MariaDB, the command is sudo mysql_secure_installation.) Suggested answers:

QuestionAnswerWhy
Enter current password for rootPress EnterA new install has none
Switch to unix_socket authenticationn if it says root is already protected, otherwise YLets only the Linux root user log in as database root, with no password to steal
Change the root passwordn (with socket login) or YSocket login doesn't need one
Remove anonymous usersYAnyone could log in without a name otherwise
Disallow root login remotelyYRoot should only connect from the server itself
Remove test databaseYIt is open to all users
Reload privilege tablesYApplies the changes now

Afterwards, open the database shell as root with sudo mariadb (no password needed, thanks to socket authentication).

Step 2: Give each application its own user

Never let a website connect as root. Create a database and a user that can only touch that database:

sudo mariadb

Then, at the MariaDB [(none)]> prompt:

CREATE DATABASE shopdb CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'shopuser'@'localhost' IDENTIFIED BY 'a-long-random-password';
GRANT ALL PRIVILEGES ON shopdb.* TO 'shopuser'@'localhost';
FLUSH PRIVILEGES;
EXIT;

If the site is hacked, the attacker only reaches this one database. Generate the password with openssl rand -base64 24.

Review existing accounts at any time:

SELECT User, Host, plugin FROM mysql.user;

Remove any you don't recognise with DROP USER 'name'@'host';.

Step 3: Keep the database off the internet

Check which address the server listens on:

sudo ss -tlnp | grep -E '3306|mariadb|mysqld'

You want to see 127.0.0.1:3306. If you see 0.0.0.0:3306 or *:3306, set the bind address:

  • Ubuntu/Debian: /etc/mysql/mariadb.conf.d/50-server.cnf
  • AlmaLinux/Rocky: /etc/my.cnf.d/mariadb-server.cnf
  • MySQL on Ubuntu: /etc/mysql/mysql.conf.d/mysqld.cnf

Under the [mysqld] section add or change:

bind-address = 127.0.0.1

Then restart with sudo systemctl restart mariadb (or mysql). Also make sure port 3306 is not allowed in your firewall.

Step 4: Connect remotely the safe way (SSH tunnel)

To use a desktop tool such as HeidiSQL, DBeaver or MySQL Workbench, don't open port 3306. Tunnel through SSH instead; most of these tools have an SSH tunnel option built in. From a terminal:

ssh -L 3307:127.0.0.1:3306 [email protected]

While that window stays open, point your database tool at host 127.0.0.1, port 3307, with your database user and password.

If another server truly must connect directly, create a user limited to that server's IP ('appuser'@'198.51.100.20'), allow only that IP to port 3306 in the firewall, change bind-address to 0.0.0.0, and require TLS for that user.

More good practice

  • phpMyAdmin: avoid installing it on a public URL. If you must, put it behind HTTPS plus an extra password or IP restriction in Nginx.
  • Updates: database security fixes arrive through normal package updates. See automatic security updates.
  • Backups: dump databases every day. See How to Back Up Your VPS.
  • MySQL's password component: on MySQL, the setup script offers the VALIDATE PASSWORD component, which rejects weak passwords. Choosing the medium level is a sensible default.

Common problems

  • Access denied for user 'root'@'localhost' when running mariadb: use sudo mariadb; socket login needs the Linux root user.
  • A website can't connect after hardening: the app must use host localhost (or 127.0.0.1) and its own user, not root.
  • MariaDB won't start after editing the config: check sudo journalctl -u mariadb -n 50 for the line with the typo.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer