Deploy MariaDB on Kubernetes using the official mariadb Docker image.
Supports standalone and GTID-based asynchronous replication, six built-in configuration presets, TLS, Prometheus
metrics via mysqld-exporter, and scheduled mariadb-dump backups to S3-compatible storage.
Replication mode enables PDB and pod anti-affinity automatically
When architecture: replication, the chart enables a PodDisruptionBudget (replication.pdb) and configures default
pod anti-affinity rules (replication.scheduling.enableDefaultPodAntiAffinity) to spread source and replica pods
across different nodes. No extra configuration is needed for basic HA scheduling.
Key Features
Two architectures — standalone (Deployment) or replication (StatefulSet + GTID)
GTID-based replication — MASTER_USE_GTID=slave_pos with parallel replica workers
MariaDB 13.0.2 is the stable GA release of the 13.0 rolling line. It adds
atomic CREATE OR REPLACE TABLE, single-table UPDATE ... RETURNING, InnoDB
log archiving and new routine types. Back up databases and validate startup,
replication, application compatibility and restore behavior before this major
upgrade. mariadb-backup does not support the new log-archive format while
innodb_log_archive=ON.
Configuration Reference
Core
Parameter
Type
Default
Description
architecture
string
standalone
Deployment mode: standalone or replication.
nameOverride
string
""
Override the chart name.
fullnameOverride
string
""
Override the full release name.
commonLabels
object
{}
Extra labels added to all resources.
clusterDomain
string
cluster.local
Kubernetes cluster domain.
Image
Parameter
Type
Default
Description
image.repository
string
docker.io/library/mariadb
MariaDB container image.
image.tag
string
"13.0.2"
Image tag.
image.pullPolicy
string
IfNotPresent
Image pull policy.
Authentication
Parameter
Type
Default
Description
auth.rootPassword
string
""
Root password. Auto-generated if empty.
auth.database
string
app
Application database created on first bootstrap.
auth.username
string
app
Application user created on first bootstrap.
auth.password
string
""
Application user password. Auto-generated if empty.
auth.replicationUsername
string
replicator
Replication user (only used in replication mode).
auth.replicationPassword
string
""
Replication password. Auto-generated if empty.
auth.existingSecret
string
""
Existing secret with all MariaDB passwords.
auth.existingSecretRootPasswordKey
string
mariadb-root-password
Key for root password in existingSecret.
auth.existingSecretUserPasswordKey
string
mariadb-user-password
Key for application user password in existingSecret.
Extra my.cnf content appended to the generated configuration.
Initialization
Parameter
Type
Default
Description
initdb.scripts
object
{}
SQL or Shell scripts injected into docker-entrypoint-initdb.d at first boot.
initdb.existingConfigMap
string
""
Existing ConfigMap also mounted into docker-entrypoint-initdb.d.
Persistence
Parameter
Type
Default
Description
persistence.subPath
string
mysql
Data volume subdirectory mounted as /var/lib/mysql; set "" for legacy volume-root installs.
persistence.prepareDataDir.enabled
boolean
false
Opt-in root initContainer for storage drivers that do not honor fsGroup; requires a Pod Security exception.
The default subPath path relies on podSecurityContext.fsGroup and does not render a root initContainer, keeping it
compatible with Pod Security restricted. Enable persistence.prepareDataDir.enabled only for storage drivers that do
not honor fsGroup for subPath directories.
Extra Objects
Parameter
Type
Default
Description
extraObjects
array
[]
Additional Kubernetes manifests rendered with the release.
Standalone Mode
Parameter
Type
Default
Description
standalone.serverId
integer
1
MariaDB server ID.
standalone.persistence.enabled
boolean
true
Enable PVC for data.
standalone.persistence.size
string
8Gi
PVC size.
standalone.persistence.storageClass
string
""
StorageClass for the PVC.
standalone.resources
object
{}
CPU and memory for the pod.
Replication Mode
Set replication passwords before first deployment
All passwords (root, user, replication) must be stable before the StatefulSet first starts. Auto-generated passwords
will change on Helm upgrades if not stored in an existingSecret, causing replicas to lose their replication
credentials.
Parameter
Type
Default
Description
replication.source.serverId
integer
1
Source server ID.
replication.source.persistence.size
string
20Gi
PVC size for the source pod.
replication.source.probes.requireWritable
boolean
true
Source only becomes ready when confirmed writable.
replication.readReplicas.replicaCount
integer
2
Number of read replica pods.
replication.readReplicas.serverIdBase
integer
100
Base server ID for replicas (replica ordinal added to this).
Enable topology spread constraints for replication pods.
TLS
Parameter
Type
Default
Description
tls.enabled
boolean
false
Enable MariaDB server-side TLS.
tls.existingSecret
string
""
Existing Secret with CA, certificate, and private key.
tls.caFilename
string
ca.crt
CA certificate filename in the secret.
tls.certFilename
string
tls.crt
Server certificate filename.
tls.keyFilename
string
tls.key
Server private key filename.
tls.requireSecureTransport
boolean
false
Reject plaintext connections (enforce TLS for all clients).
tls.client.enabled
boolean
false
Use TLS for internal chart client connections.
Backup
Parameter
Type
Default
Description
backup.enabled
boolean
false
Enable scheduled mariadb-dump S3 backup.
backup.schedule
string
"0 3 * * *"
Cron schedule.
backup.archivePrefix
string
mariadb
Prefix for backup archive filenames.
backup.s3.endpoint
string
""
S3-compatible endpoint URL.
backup.s3.bucket
string
""
Target bucket name.
backup.s3.existingSecret
string
""
Existing secret with S3 credentials.
backup.database.mariadbdumpArgs
string
--single-transaction ...
Extra args for mariadb-dump. Includes --routines --events --triggers by default.
Metrics
Parameter
Type
Default
Description
metrics.enabled
boolean
false
Enable mysqld-exporter sidecar.
metrics.image.repository
string
docker.io/prom/mysqld-exporter
Exporter image.
metrics.image.tag
string
"v0.17.2"
Exporter image tag.
metrics.serviceMonitor.enabled
boolean
false
Create a Prometheus Operator ServiceMonitor.
metrics.serviceMonitor.interval
string
30s
Scrape interval.
When metrics are enabled, the chart writes a locked-down mysqld-exporter client config from the same MariaDB Secret used
by the database container. This avoids exposing the root password through DATA_SOURCE_NAME and keeps TLS client settings
aligned with the MariaDB pod.