@database-mcp/mysql
Advanced tools
+2
-2
| { | ||
| "name": "@database-mcp/mysql", | ||
| "version": "0.2.1", | ||
| "version": "0.3.0", | ||
| "description": "MCP server for MySQL with read-only guardrails, row caps, and statement timeouts", | ||
@@ -32,3 +32,3 @@ "license": "MIT", | ||
| "dependencies": { | ||
| "@database-mcp/core": "^0.2.0", | ||
| "@database-mcp/core": "^0.3.0", | ||
| "mysql2": "^3.22.6" | ||
@@ -35,0 +35,0 @@ }, |
+70
-12
@@ -8,5 +8,2 @@ # @database-mcp/mysql | ||
| The password comes from the environment or a mounted secret file — never | ||
| from the client config: | ||
| ```json | ||
@@ -21,3 +18,3 @@ { | ||
| "MYSQL_USER": "readonly_user", | ||
| "MYSQL_PASSWORD": "...", | ||
| "MYSQL_PASSWORD": "your-password", | ||
| "MYSQL_DATABASE": "mydb" | ||
@@ -30,12 +27,73 @@ } | ||
| Alternatives: `MYSQL_PASSWORD_FILE=/run/secrets/mysql_password` | ||
| (Docker/K8s-style), a YAML file via `--config` (values support `${VAR}` | ||
| expansion), or `--dsn mysql://user@host:3306/db` (inline DSN passwords are | ||
| discouraged but redacted if used). `--print-config` shows the resolved | ||
| config with the password redacted. | ||
| ## Configuration | ||
| Use whichever method fits your setup. When methods are combined, flags win | ||
| over the YAML file, and the YAML file wins over environment variables. | ||
| ### Environment variables | ||
| `MYSQL_HOST`, `MYSQL_PORT`, `MYSQL_USER`, `MYSQL_PASSWORD`, | ||
| `MYSQL_DATABASE`, as in the quick start above. | ||
| ### Mounted secret file (Docker, Kubernetes) | ||
| Keeps the password out of the environment and out of every config file. | ||
| Point `MYSQL_PASSWORD_FILE` at a file that contains only the password: | ||
| ```json | ||
| "env": { | ||
| "MYSQL_HOST": "127.0.0.1", | ||
| "MYSQL_USER": "readonly_user", | ||
| "MYSQL_PASSWORD_FILE": "/run/secrets/mysql_password", | ||
| "MYSQL_DATABASE": "mydb" | ||
| } | ||
| ``` | ||
| ### YAML config file | ||
| Keeps the client entry down to two lines. Pass an absolute path, since the | ||
| working directory at launch is unpredictable: | ||
| ```json | ||
| "args": ["-y", "@database-mcp/mysql", "--config", "/absolute/path/database-mcp.yaml"] | ||
| ``` | ||
| ```yaml | ||
| # /absolute/path/database-mcp.yaml | ||
| connection: | ||
| host: 127.0.0.1 | ||
| port: 3306 | ||
| user: readonly_user | ||
| password: ${MYSQL_PASSWORD} # expanded from the environment at load time | ||
| # or read it from a mounted file instead: | ||
| # password_file: /run/secrets/mysql_password | ||
| database: mydb | ||
| guardrails: | ||
| readOnly: true | ||
| maxRows: 1000 | ||
| queryTimeoutMs: 30000 | ||
| ``` | ||
| Never write a literal password into the YAML file. Use `${VAR}` expansion or | ||
| `password_file` as shown. | ||
| ### Connection string | ||
| ```json | ||
| "args": ["-y", "@database-mcp/mysql", "--dsn", "mysql://readonly_user@127.0.0.1:3306/mydb"] | ||
| ``` | ||
| Putting the password inside the DSN works but is discouraged. If you do it | ||
| anyway, the server redacts it from any log output. | ||
| ### Checking the result | ||
| Run the server with `--print-config` to see exactly what it resolved. The | ||
| password always prints as `***`. | ||
| ## Tools | ||
| - **`execute_sql`** `{ sql }` — run a single SQL statement. | ||
| - **`search_objects`** `{ table? }` — list tables, or describe one (columns, | ||
| - **`execute_sql`** `{ sql }` runs a single SQL statement. | ||
| - **`search_objects`** `{ table? }` lists tables, or describes one (columns, | ||
| indexes, foreign keys). | ||
@@ -52,3 +110,3 @@ | ||
| Read-only is enforced in two layers: a conservative SQL guard, plus | ||
| `SET SESSION TRANSACTION READ ONLY` on every pooled connection — so writes | ||
| `SET SESSION TRANSACTION READ ONLY` on every pooled connection. Writes | ||
| smuggled through CTEs are rejected by the server itself. | ||
@@ -55,0 +113,0 @@ |
15128
9.73%118
96.67%+ Added
+ Added
- Removed
- Removed
Updated