Tenants, realms and names
A tenant is your organisation. A realm is a namespace inside it that you delegate to a team. Databases and accounts belong to exactly one realm and live on exactly one cluster.
Naming rules#
Every database and account has a physical name <tenant>_<realm>_<name>.
| Element | Rule |
|---|---|
| Tenant and realm slug | 2–16 characters, lowercase letters and digits, starts with a letter, no underscore or hyphen |
| Database or account name | 1–30 characters, lowercase letters, digits and single underscores, starts with a letter |
| Physical name | at most 64 characters |
Some names are reserved, for example mysql, sys, test, root, admin, default, all and new. Account names can reach 64 characters; tools that assume MySQL's 32-character user-name limit may not accept the longest combinations.
Console roles#
| Role | May |
|---|---|
| Tenant admin | everything in every realm; create and delete realms; manage tenant admins and API tokens; purge a deleted database's backups; see usage |
| Realm admin | everything in the realm, including its members |
| Realm operator | create and delete databases and accounts, rotate passwords, change grants, restore and export databases |
| Realm viewer | read configuration, connection information and usage |
Roles are given to users or groups from your identity provider. They control the console and API only; they are not MariaDB accounts.
Privilege profiles#
Grants are expressed as a profile on a scope — never as a raw privilege list.
| Profile | For | Privileges |
|---|---|---|
dba |
migrations, schema owners | all database-level privileges except GRANT OPTION and EVENT |
readwrite |
application runtime | SELECT, INSERT, UPDATE, DELETE, EXECUTE, SHOW VIEW, CREATE TEMPORARY TABLES, LOCK TABLES |
readonly |
reporting | SELECT, SHOW VIEW, EXECUTE |
The scope is either one database or the whole realm. A realm-scope dba account may run CREATE DATABASE acme_shop_<anything> over SQL; Scuttle picks such databases up within five minutes and shows them in the console.
Account settings#
Accounts always require TLS. You may restrict an account to source networks (IPv4 networks, and single IPv6 addresses), set a connection limit (default 100, up to 500) and a maximum statement time. You can change your own password with SET PASSWORD; a rotation from the console overwrites it.