Managing MySQL semi-sync users
Users are created to access databases in a MySQL semi-sync cluster.
Only the cluster itself is available to users—cluster nodes cannot be accessed as they are located on the Selectel side. By default, all users in a cluster have the same permissions.
Access to a single MySQL semi-sync database can be granted to multiple users.
Create a user
- In the Dashboard, on the top menu click Products and select Managed Databases.
- Open the Active tab.
- Open the database cluster page → Users tab.
- Click Create User.
- Enter a username and password. Save the password—it will not be stored in the Dashboard.
- Click Save.
Change a user password
After a cluster is created, the user password can be changed. Do not forget to update the password in your application.
- In the Dashboard, on the top menu click Products and select Managed Databases.
- Open the Active tab.
- Open the cluster page → Users tab.
- In the user menu, select Change password.
- Enter or generate a new password and save the changes.
Configure database access
Grant access to a user
Access to a single MySQL semi-sync database can be granted to multiple users.
- In the Dashboard, on the top menu, click Products and select Managed Databases.
- Open the Active tab.
- Open the database cluster page → Databases tab → database page.
- In the Have access block, click Add and select a user.
The user can only connect to the database (CONNECT) and cannot perform object operations. To grant the user access to objects, grant them the necessary privileges.
Revoke user access
- In the Dashboard, on the top menu, click Products and select Managed Databases.
- Open the Active tab.
- Open the database cluster page → Databases tab → database page.
- In the Have access block, remove the user.
Configure user privileges
Grant privileges
You can grant database and table privileges to users using the GRANT command. Privileges can be as follows: SELECT, INSERT, DELETE, USAGE and others.
Example of granting read access (SELECT) to the table table in the database database to the user:
GRANT SELECT ON table TO user;
Example of granting read access (SELECT) to the database database to the user:
GRANT SELECT ON database.* TO user;
Create a user with read-only permissions
-
Grant the user access to the database.
-
Create another user who will have only read-only (read-only) privileges.
-
Connect to the database using the first user.
-
Grant read-only privileges to the database to the second user:
REVOKE ALL PRIVILEGES ON <database_name>.* FROM '<username>'@'%';GRANT SELECT ON <database_name>.* TO '<username>'@'%';Specify:
<database_name>— database name;<username>— the name of the user who will be granted read-only rights.
Revoke privileges
You can revoke user privileges using the REVOKE command.
Example of revoking a privilege from user user on table table and database database:
REVOKE SELECT ON table FROM user;
REVOKE SELECT ON database.* FROM user;