Skip to content

MariaDB MariaDB

Description / nameInput element
Container Registry
Container Configuration Root Path
Timezone
User ID
Group ID
MariaDB Host Port
MariaDB /config Path

Build Status Last Commit OCI Pulls

Drop-in replacement for MySQL built by the original authors — extends core MySQL functionality with alternate storage engines, server optimizations, and patches.

Port 3306
Registry ghcr.io/daemonless/mariadb
Daemonless daemonless/mariadb
Source MariaDB/server
Website mariadb.org

Version Tags

Multi-arch manifests — resolve automatically to the right image for your platform.

Tag Description Best For
10.11 / 10.11-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
11.4 / 11.4-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
11.8 / 11.8-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
12.3 / 12.3-pkg-latest / latest / pkg / pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
Tag Description Best For
10.11-amd64 / 10.11-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
11.4-amd64 / 11.4-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
11.8-amd64 / 11.8-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
12.3-amd64 / 12.3-pkg-latest-amd64 / latest-amd64 / pkg-amd64 / pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
Tag Description Best For
10.11-aarch64 / 10.11-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
11.4-aarch64 / 11.4-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
11.8-aarch64 / 11.8-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
12.3-aarch64 / 12.3-pkg-latest-aarch64 / latest-aarch64 / pkg-aarch64 / pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  mariadb:
    image: "ghcr.io/daemonless/mariadb:latest"
    container_name: mariadb
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - MYSQL_ROOT_PASSWORD=changeme  # Root password (required on first run)
      - MYSQL_DATABASE=mydb  # Database to create on first run
      - MYSQL_USER=myuser  # User to create on first run
      - MYSQL_PASSWORD=mypassword  # Password for MYSQL_USER
    volumes:
      - "/path/to/containers/mariadb:/config"
    ports:
      - "3306:3306"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

podman run -d --name mariadb \
  -p 3306:3306 \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e MYSQL_ROOT_PASSWORD=changeme \
  -e MYSQL_DATABASE=mydb \
  -e MYSQL_USER=myuser \
  -e MYSQL_PASSWORD=mypassword \
  -v /path/to/containers/mariadb:/config \
  ghcr.io/daemonless/mariadb:latest

Save as run.sh, then run sh run.sh.

- name: Deploy mariadb
  containers.podman.podman_container:
    name: mariadb
    image: "ghcr.io/daemonless/mariadb:latest"
    state: started
    restart_policy: always
    env:
      PUID: "1000"
      PGID: "1000"
      TZ: "UTC"
      MYSQL_ROOT_PASSWORD: "changeme"
      MYSQL_DATABASE: "mydb"
      MYSQL_USER: "myuser"
      MYSQL_PASSWORD: "mypassword"
    ports:
      - "3306:3306"
    volumes:
      - "/path/to/containers/mariadb:/config"

Save as mariadb-deploy.yaml, then run ansible-playbook mariadb-deploy.yaml.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

# .env

DIRECTOR_PROJECT=mariadb
PUID=1000
PGID=1000
TZ=UTC
MYSQL_ROOT_PASSWORD=changeme
MYSQL_DATABASE=mydb
MYSQL_USER=myuser
MYSQL_PASSWORD=mypassword
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  mariadb:
    name: mariadb
    options:
      - container: 'args:--pull'
      - expose: '3306:3306 proto:tcp'
    oci:
      user: root
      environment:
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - MYSQL_ROOT_PASSWORD: !ENV '${MYSQL_ROOT_PASSWORD}'
        - MYSQL_DATABASE: !ENV '${MYSQL_DATABASE}'
        - MYSQL_USER: !ENV '${MYSQL_USER}'
        - MYSQL_PASSWORD: !ENV '${MYSQL_PASSWORD}'
    volumes:
      - MARIADB_CONFIG_PATH: /config
volumes:
  MARIADB_CONFIG_PATH:
    device: '/path/to/containers/mariadb'
1
2
3
4
5
6
7
# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/mariadb:${tag}

Save the files above, then run appjail-director up.

appjail oci run -Pd \
  -o overwrite=force \
  -o container="args:--pull" \
  -o virtualnet=":<random> default" \
  -o nat \
  -o expose="3306:3306 proto:tcp" \
  -e PUID=1000 \
  -e PGID=1000 \
  -e TZ=UTC \
  -e MYSQL_ROOT_PASSWORD=changeme \
  -e MYSQL_DATABASE=mydb \
  -e MYSQL_USER=myuser \
  -e MYSQL_PASSWORD=mypassword \
  -o fstab="/path/to/containers/mariadb /config <pseudofs>" \
  ghcr.io/daemonless/mariadb:latest mariadb

Save the files above, then run sh run.sh.

Experimental

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  mariadb:
    name: mariadb
    image: "ghcr.io/daemonless/mariadb:latest"
    network:
      - mode: host
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - MYSQL_ROOT_PASSWORD=changeme
      - MYSQL_DATABASE=mydb
      - MYSQL_USER=myuser
      - MYSQL_PASSWORD=mypassword
    volumes:
      - "/path/to/containers/mariadb:/config"

Save as bastille-compose.yml, then run bastille up.

bastille create -O \
  --env PUID=1000 \
  --env PGID=1000 \
  --env TZ=UTC \
  --env MYSQL_ROOT_PASSWORD=changeme \
  --env MYSQL_DATABASE=mydb \
  --env MYSQL_USER=myuser \
  --env MYSQL_PASSWORD=mypassword \
  --volume /path/to/containers/mariadb /config \
  mariadb ghcr.io/daemonless/mariadb:latest inherit

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
PUID 1000
PGID 1000
TZ Etc/UTC
MYSQL_ROOT_PASSWORD changeme Root password (required on first run)
MYSQL_DATABASE mydb Database to create on first run
MYSQL_USER myuser User to create on first run
MYSQL_PASSWORD mypassword Password for MYSQL_USER

Volumes

Path Description
/config MariaDB configuration and data

Ports

Port Protocol Description
3306 TCP MariaDB port

Implementation Details

  • Architectures: amd64, aarch64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).

Need help? Join our Discord community.