open-vault/website/source/docs/configuration/storage/mysql.html.md
Igor Katson 88118dce0f Add max_parallel parameter to MySQL backend. (#2760)
* Add max_parallel parameter to MySQL backend.

This limits the number of concurrent connections, so that vault does not die
suddenly from "Too many connections".

This can happen when e.g. vault starts up, and tries to load all the
existing leases in parallel. At the time of writing this, the value
ExpirationRestoreWorkerCount in vault/helper/consts/const.go is set to
64, meaning that if there are enough leases in the vault's DB, it will
generate AT LEAST 64 concurrent connections to MySQL when loading the
data during start-up. On certain configurations, e.g. smaller AWS
RDS/Aurora instances, this will cause Vault to fail startup.

* Fix a typo in mysql storage readme
2017-06-01 15:20:32 -07:00

73 lines
2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
layout: "docs"
page_title: "MySQL - Storage Backends - Configuration"
sidebar_current: "docs-configuration-storage-mysql"
description: |-
The MySQL storage backend is used to persist Vault's data in a MySQL server or
cluster.
---
# MySQL Storage Backend
The MySQL storage backend is used to persist Vault's data in a [MySQL][mysql]
server or cluster.
- **No High Availability** the MySQL storage backend does not support high
availability.
- **Community Supported** the MySQL storage backend is supported by the
community. While it has undergone review by HashiCorp employees, they may not
be as knowledgeable about the technology. If you encounter problems with them,
you may be referred to the original author.
```hcl
storage "mysql" {
username = "user1234"
password = "secret123!"
database = "vault"
}
```
## `mysql` Parameters
- `address` `(string: "127.0.0.1:3306")` Specifies the address of the MySQL
host.
- `database` `(string: "vault")` Specifies the name of the database. If the
database does not exist, Vault will attempt to create it.
- `table` `(string: "vault")` Specifies the name of the table. If the table
does not exist, Vault will attempt to create it.
- `tls_ca_file` `(string: "")` Specifies the path to the CA certificate to
connect using TLS.
- `max_parallel` `(string: "128")` Specifies the maximum number of concurrent
requests to MySQL.
Additionally, Vault requires the following authentication information.
- `username` `(string: <required>)` Specifies the MySQL username to connect to
the database.
- `password` `(string: <required)` Specifies the MySQL password to connect to
the database.
## `mysql` Examples
### Custom Database and Table
This example shows configuring the MySQL backend to use a custom database and
table name.
```hcl
storage "mysql" {
database = "my-vault"
table = "vault-data"
username = "user1234"
password = "pass5678"
}
```
[mysql]: https://dev.mysql.com