Inspect MariaDB Option Files with my_print_defaults

A client that connects with settings nobody remembers configuring is the moment my_print_defaults earns its keep. It prints exactly which options a MariaDB process will inherit from its option files, without starting a service. Allow about ten minutes. You need the mariadb-client-core package and read access to the configuration you want to inspect. The examples below use MariaDB client core 10.11.14 on Debian Linux.

This is a read-only investigation. It does not edit a configuration file, reload MariaDB or connect to a server. Treat the output as sensitive, though: a password stored in an option file can be printed in plain text.

1. Confirm the installed command

Start by checking which binary is being run and which package supplied it:

$ command -v my_print_defaults
/usr/bin/my_print_defaults
$ dpkg-query -W -f='${Package} ${Version}\n' mariadb-client-core
mariadb-client-core 1:10.11.14-0ubuntu0.24.04.1
$ my_print_defaults --version
my_print_defaults  Ver 1.8 for debian-linux-gnu at x86_64

The exact package version and architecture will differ elsewhere; keep this checkpoint when comparing output between hosts. The installed manual page is dated 18 December 2023 and identifies the documented command as part of MariaDB 10.11.

2. See which configuration files are in scope

Run the help output before inspecting a group. On this installation, the normal search order is /etc/my.cnf, /etc/mysql/my.cnf, then ~/.my.cnf:

$ my_print_defaults --help
Default options are read from the following files in the given order:
/etc/my.cnf /etc/mysql/my.cnf ~/.my.cnf

That list is the command's compiled default view. Included files can add more configuration: for example, this host's /etc/mysql/my.cnf includes directories under /etc/mysql/conf.d/ and /etc/mysql/mariadb.conf.d/. Inspect those files as well if you need to explain a particular option:

$ find /etc/mysql -maxdepth 3 -type f -name '*.cnf' -print | sort

Reading a system file normally needs no elevated privilege. If permissions block the inspection, use sudo only for the read command that needs it. Do not make the configuration world-readable just to make this tool convenient.

3. Inspect the groups used by a client

Pass one or more option group names after the options. A client commonly reads a tool-specific group plus the shared client group. For example:

$ my_print_defaults client mysql
--socket=/run/mysqld/mysqld.sock

Output is one option per line, in the form a program could use on its command line. Your result depends on local files. If there is no matching option, the command can produce no output and still exit successfully, so check that distinction explicitly:

$ my_print_defaults client mysql
$ printf 'exit status: %s\n' "$?"
exit status: 0

Do not assume an empty result proves that a client has no configuration. You may have named the wrong group, used a different home directory, or inspected a machine whose configuration is elsewhere.

4. Inspect the server groups

Use --mariadbd to ask for the same set of groups that the MariaDB server binary reads. The older --mysqld spelling is also accepted by this installation and represents the historical binary name:

$ my_print_defaults --mariadbd
--socket=/run/mysqld/mysqld.sock
--pid-file=/run/mysqld/mysqld.pid
--basedir=/usr
--bind-address=127.0.0.1,172.17.0.1
$ my_print_defaults --mysqld > /tmp/mysqld-options.txt
$ wc -l /tmp/mysqld-options.txt
15 /tmp/mysqld-options.txt

The count and values are host-specific. Saving output under /tmp is useful for a short comparison, but it is not a secure archive. Remove the file after inspection if it contains credentials or other sensitive settings:

$ rm -- /tmp/mysqld-options.txt

That removal is irreversible. Confirm the path before running rm; never replace it with a broad wildcard such as /tmp/*.

5. Make a script ignore all defaults

The --no-defaults option returns an empty string. It is useful when a script needs to establish a clean baseline or test whether its own arguments are sufficient:

$ my_print_defaults --no-defaults client mysql
$ printf 'exit status: %s\n' "$?"
exit status: 0

This option does not delete or disable any configuration file, it affects this invocation only. Keep the option before the group names, and do not confuse an empty output with a failed command.

6. Use an isolated option file carefully

The manual documents --defaults-file=FILE as a way to read only one option file when it is the first option. This is useful for troubleshooting a supplied configuration, but it changes which files are consulted. Verify the file first and avoid placing real passwords in a temporary example.

$ test -r /path/to/example.cnf && echo readable
readable
$ my_print_defaults --defaults-file=/path/to/example.cnf client mysql

If you need to add one file to the normal global search, the manual also documents --defaults-extra-file=FILE. It is read after the global option file and before the user option file on Unix. Both file-selection options should be placed first. A misspelled path or a file with invalid option syntax is a configuration problem to fix at the source, not a reason to copy settings into a different location.

7. Avoid leaking secrets while debugging

my_print_defaults prints values, not redacted summaries. If an option file contains password=..., the output can contain --password=.... Do not paste the output into a ticket, shell transcript or chat without removing secrets first. Prefer filtering a copy of the output after the command has run, and remember that shell history can still record the command and its arguments.

The --verbose option prints more information about what the program does. Use it when you need to understand file processing, but do not treat verbose output as a safe replacement for secret handling. The --debug option writes a debugging log and, according to the manual, defaults to /tmp/my_print_defaults.trace; avoid it unless you have a reason to handle another potentially sensitive file.

Common traps

Done means