prometheus-mysqld-exporter
Secure by Design, Built for Speed, Hardened Container Images on a minimal base CleanStart OS.
10K+
The CleanStart Prometheus-Mysqld-Exporter image provides a production-ready, security-hardened database server optimized for enterprise environments. Built on a minimal base OS with comprehensive security hardening, this image delivers reliable data storage with advanced security features.
š Base Foundation: Production-ready container from cleanstart.
Image Path: cleanstart/prometheus-mysqld-exporter
Registry: cleanstart Registry
Download the container image from the registry
docker pull cleanstart/prometheus-mysqld-exporter:latest
docker pull cleanstart/prometheus-mysqld-exporter:latest-dev
Note: cleanstart/prometheus-mysqld-exporter:latest does not support the standard DATA_SOURCE_NAME environment variable used by the upstream mysqld_exporter ā instead it requires a .my.cnf config file mounted into the container and the --config.my-cnf= flag passed as an argument; to resolve, create a Kubernetes ConfigMap containing a [client] section with user, password, host, and port, mount it as a volume, and add --config.my-cnf=/etc/mysql/.my.cnf to the container args.
cat > /tmp/.my.cnf << 'EOF'
[client]
user=exporter
password=exporterpassword
host=mysql-host
port=3306
EOF
Run the container with basic configuration
docker run -it --name prometheus-mysqld-exporter \
-v /tmp/.my.cnf:/etc/mysql/.my.cnf:ro \
cleanstart/prometheus-mysqld-exporter:latest \
--config.my-cnf=/etc/mysql/.my.cnf
Deploy with production security settings
docker run -d --name prometheus-mysqld-exporter-prod \
--security-opt=no-new-privileges \
--user 1000:1000 \
--restart unless-stopped \
-p 9104:9104 \
-v /tmp/.my.cnf:/etc/mysql/.my.cnf:ro \
cleanstart/prometheus-mysqld-exporter:latest \
--config.my-cnf=/etc/mysql/.my.cnf
Volume Mount Mount local directory for persistent data
docker run -v /app:/app \
-v /tmp/.my.cnf:/etc/mysql/.my.cnf:ro \
cleanstart/prometheus-mysqld-exporter:latest \
--config.my-cnf=/etc/mysql/.my.cnf
Port Forwarding Run with custom port mappings
docker run -p 9104:9104 \
-v /tmp/.my.cnf:/etc/mysql/.my.cnf:ro \
cleanstart/prometheus-mysqld-exporter:latest \
--config.my-cnf=/etc/mysql/.my.cnf
With Additional Collectors Enable specific MySQL metric collectors
docker run -d --name prometheus-mysqld-exporter-full \
-p 9104:9104 \
-v /tmp/.my.cnf:/etc/mysql/.my.cnf:ro \
cleanstart/prometheus-mysqld-exporter:latest \
--config.my-cnf=/etc/mysql/.my.cnf \
--collect.global_status \
--collect.global_variables \
--collect.info_schema.innodb_metrics \
--collect.info_schema.tables \
--collect.perf_schema.eventsstatements
Recommended security context for Kubernetes deployments
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsUser: 1000
runAsGroup: 1000
Essential links and resources for further information
Vulnerability Disclaimer
CleanStart offers Docker images that include third-party open-source libraries and packages maintained by independent contributors. While CleanStart maintains these images and applies industry-standard security practices, it cannot guarantee the security or integrity of upstream components beyond its control.
Users acknowledge and agree that open-source software may contain undiscovered vulnerabilities or introduce new risks through updates. CleanStart shall not be liable for security issues originating from third-party libraries, including but not limited to zero-day exploits, supply chain attacks, or contributor-introduced risks.
Security remains a shared responsibility: CleanStart provides updated images and guidance where possible, while users are responsible for evaluating deployments and implementing appropriate controls.
Content type
Image
Digest
sha256:9f6787702ā¦
Size
60.8 MB
Last updated
about 19 hours ago
docker pull cleanstart/prometheus-mysqld-exporter:latest-arm64-dev