---
title: "MySQL sync user management"
sidebar_label: "User management"
sidebar_position: 7
description: "How to create a user, change their password, configure MySQL sync database access, and manage privileges"
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import MoreVerticalIcon from '@selectel/docux/icons/more-vertical'

# MySQL sync user management

Users are created to access databases in a MySQL sync cluster.

Users only have access to the cluster itself—there is no access to cluster nodes, as they are managed by Selectel. By default, all users in a cluster have the same permissions.

Access to a single MySQL sync database can be granted to multiple users.

## Create a user \{#create-user}

1. In the [Dashboard](https://my.selectel.ru/vpc/default/dbaas/), on the top menu, click **Products** and select **Managed Databases**.
2. Open the **Active** tab.
3. Open the database cluster page → **Users** tab.
4. Click **Create user**.
5. Enter a name and password. Save the password—it will not be stored in the dashboard.
6. Click **Save**.

## Change a user password \{#change-user-password}

After a cluster is created, the user password can be changed. Remember to update the password in your application.

1. In the [Dashboard](https://my.selectel.ru/vpc/default/dbaas/), on the top menu, click **Products** and select **Managed Databases**.
2. Open the **Active** tab.
3. Open the cluster page → **Users** tab.
4. In the  user menu, select **Change password**.<MoreVerticalIcon />
5. Enter or generate a new password and save the changes.

## Configure database access \{#configure-access-to-database}

### Grant access to a user \{#grant-user-access}

Access to a single MySQL sync database can be granted to multiple users.

1. In the [Dashboard](https://my.selectel.ru/vpc/default/dbaas/), on the top menu click **Products** and select **Managed Databases**.
2. Open the **Active** tab.
3. Open the database cluster page → **Databases** tab → database page.
4. In the **Have access** block, click **Add** and select a user.

The user can only connect to the database (`CONNECT`) and cannot perform operations on objects. To grant the user access to objects, [grant them the necessary privileges](/managed-databases/mysql-sync/manage-users.mdx#grant-privileges).

### Revoke access for a user \{#revoke-access-for-user}

1. In the [Dashboard](https://my.selectel.ru/vpc/default/dbaas/), on the top menu click **Products** and select **Managed Databases**.
2. Open the **Active** tab.
3. Open the database cluster page → **Databases** tab → database page.
4. In the **Have access** block, remove the user.

## Configure user privileges \{#configure-user-privileges}

### Grant privileges \{#grant-privileges}

You can grant users database and table privileges using the [GRANT](https://dev.mysql.com/doc/refman/8.0/en/grant.html) command. Privileges can be as follows: `SELECT`, `INSERT`, `DELETE`, `USAGE` and others.

Example of granting read access (`SELECT`) to the table `table` in the database `database` to user `user`:

```bash
GRANT SELECT ON table TO user;
```

Example of granting read access (`SELECT`) to the database `database` to user `user`:

```bash
GRANT SELECT ON database.* TO user;
```

### Create a read-only user \{#create-read-only-user}

1. [Create a user](#create-user).
2. [Grant the user access](/managed-databases/mysql-sync/manage-users.mdx#grant-user-access) to the database.
3. Create another user who will have read-only (read-only) privileges.
4. [Connect to the database](/managed-databases/mysql-sync/connect-to-cluster.mdx) with the first user.
5. Grant read-only privileges to the database for the second user:

   ```bash
   REVOKE ALL PRIVILEGES ON <database_name>.* FROM '<username>'@'%';
   GRANT SELECT ON <database_name>.* TO '<username>'@'%';
   ```

   Specify:

   * `<database_name>` — database name;
   * `<username>` — name of the user to be granted read-only rights.

### Revoke privileges \{#revoke-privileges}

You can revoke user privileges using the [REVOKE](https://dev.mysql.com/doc/refman/8.0/en/revoke.html) command.

Example of revoking privileges from user `user` for table `table` and database `database`:

```bash
REVOKE SELECT ON table FROM user;
REVOKE SELECT ON database.* FROM user;
```

<Formbricks />
