Passwordless Access to PlanetScale DB

You can seamless zero trust, secret-less access to Planetscale or any SaaS MySQL-based database (read more about MYSQL Services here) without having to share and manage passwords and roles (read more about secret-less access here).

First we need to create a Secret for the database's password as follows:

octeliumctl create secret psdb-password

Now we use the database information (namely the address, user, database and the password Secret name) to create a Service for our database as follows:

1
kind: Service
2
metadata:
3
name: psdb
4
spec:
5
mode: MYSQL
6
port: 3306
7
config:
8
upstream:
9
url: mysql://aws.connect.psdb.cloud
10
mysql:
11
user: <USER>
12
database: <DB>
13
auth:
14
password:
15
fromSecret: psdb-password
16
isTLS: true

You can now apply the creation of the Service as follows (read more here):

octeliumctl apply /PATH/TO/SERVICE.YAML
NOTE

Note that you can also provide dynamic secret-less access where you can set different users, databases and passwords for different Users under different contexts. Read more about dynamic configuration here.

NOTE

You might also want to read about MYSQL mode access control here and access logs here

Now after connecting to the Cluster via the octelium connect command (read more about connecting to Clusters here), we can access the database with whatever relevant tool such as the mysql CLI as follows:

mysql -h psdb
© 2025 octelium.comOctelium Labs, LLCAll rights reserved
Octelium and Octelium logo are trademarks of Octelium Labs, LLC.
WireGuard is a registered trademark of Jason A. Donenfeld