Typing a password straight after -p is the habit this guide on mysql exists to break. Here is a repeatable way to connect to MariaDB, run a read-only check, execute a saved SQL file, and capture output without leaving a credential in your shell history. On this machine, mysql is the compatibility name for the MariaDB client, and both commands report MariaDB 10.11.14.
Allow about fifteen minutes. You need the mariadb-client-core package, a MariaDB account, and a reachable server. The examples use placeholders for the host, user and database: replace them with values from your environment. Most checks are ordinary unprivileged commands. Do not use sudo to compensate for a wrong database account or host.
Start with a local, read-only check. The installed program is named mariadb; mysql is its symlink-compatible name.
$ command -v mariadb
/usr/bin/mariadb
$ mariadb --version
mariadb Ver 15.1 Distrib 10.11.14-MariaDB, for debian-linux-gnu (x86_64) using EditLine wrapper
$ mysql --version
mariadb Ver 15.1 Distrib 10.11.14-MariaDB, for debian-linux-gnu (x86_64) using EditLine wrapper
The package version and client version are related but not identical labels. If your output differs, keep the behaviour in this guide anchored to the help and manpage installed with your client:
$ mariadb --help | sed -n '1,24p'
Checkpoint: Stop here if the command is missing or the version is not the one you intended to use. Installing packages is outside this query workflow.
Use -u for the database user, -h for the server and an optional final argument for the default database. Put -p at the end of the connection options with no password attached. The client then prompts privately.
$ mariadb --host=DB_HOST --user=DB_USER --password DB_NAME
Enter password:
Do not paste a real password after --password= or -p. Command-line arguments can be visible to other users while the process is running, and the command can be saved in shell history. An option file can hold connection settings, but protect that file carefully and follow the permissions and credential policy for your host.
If the server listens on a non-standard port, add --port=DB_PORT. For a local Unix socket, use --socket=/path/to/mariadb.sock. Supplying --port forces TCP in the cases described by the manpage, while supplying --socket selects the socket protocol: do not add both until you understand which connection you want.
On success, you will see a prompt similar to this:
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is CONNECTION_ID
Server version: 10.11.x-MariaDB MariaDB Server
MariaDB [DB_NAME]>
The connection ID and server version vary. A timeout, access denied message or unknown host is a connection problem to investigate; it is not fixed by running the client as root.
At the prompt, SQL statements normally end with a semicolon. Start with information that does not change data:
SELECT DATABASE(), CURRENT_USER(), VERSION();
You should receive one row containing the selected database, authenticated account and server version. The exact table borders and version string depend on the server. Use \G instead of the semicolon when a wide row is easier to read vertically:
SELECT DATABASE(), CURRENT_USER(), VERSION()\G
Useful client commands are different from SQL. Type status; for connection details, \s for the short form, help; for client help, and quit; or \q to leave. A client command must be used in the form expected by the client; do not assume that every backslash command is SQL.
Checkpoint: You have a working session only when the verification query returns and the displayed database and user are the ones you expected. If you are unsure, quit and reconnect with explicit host, user and database values.
For a script or a quick diagnostic, --execute (or -e) runs one statement and exits. Add --batch and --skip-column-names when a stable, machine-friendly value is useful:
$ mariadb --host=DB_HOST --user=DB_USER --password --batch --skip-column-names --execute='SELECT COUNT(*) FROM TABLE_NAME;'
Enter password:
ROW_COUNT
Replace TABLE_NAME with a table you are authorised to inspect. The command's output is tab-separated in batch mode. Do not use --skip-column-names if a person needs the heading; for a wider result, omit it or use --vertical.
Before changing data, stop and review the statement, database and affected rows. UPDATE and DELETE without the intended WHERE clause can be destructive and cannot be undone by the client. For a guardrail during exploration, --safe-updates limits updates and deletes that do not identify rows through key values, and also applies automatic limits to some queries. It is a safety aid, not a replacement for a backup or a reviewed transaction.
Keep the SQL file separate from the command line and redirect it into the client. This avoids an interactive copy-and-paste session and makes the input reviewable:
$ sed -n '1,80p' ./checked.sql
$ mariadb --host=DB_HOST --user=DB_USER --password DB_NAME < ./checked.sql
Enter password:
Review the file before running it. Look especially for DROP, broad DELETE or UPDATE, privilege changes, and statements that target a different database. The shell redirection reads the file; it does not validate its intent. By default, an SQL error can leave later input still being processed. Add --abort-source-on-error when using the client source command and you want that source operation to stop at an error. Do not use --force casually: it explicitly continues after SQL errors.
For a saved result, redirect standard output to a new file after checking that its name is not valuable:
$ mariadb --host=DB_HOST --user=DB_USER --password --batch DB_NAME < ./report.sql > ./report.tsv
Enter password:
$ test -s ./report.tsv && sed -n '1,5p' ./report.tsv
Shell > truncates an existing destination before the client starts. Use a new filename first. If you created an unwanted report, remove only that known file after checking its path; there is no client undo for shell redirection.
Interactive queries use an ASCII table. Non-interactive output is tab-separated, and options change the format:
--batch produces rows separated by tabs and escapes special characters.--raw disables those batch-mode escapes, so use it only when the consumer expects literal tabs, newlines or backslashes.--html and --xml produce structured alternatives, but still treat the values as data rather than trusted markup.--quick prints rows as they arrive instead of caching the whole result. It reduces client memory pressure, but a slow consumer can make the server work longer.For large exports, select only the columns and rows you need, test the query with a limit where appropriate, and write to a filesystem with enough space. The client does not make an accidental full-table query safe merely because --quick is present.
On Unix, interactive statements are normally written to $HOME/.mysql_history. That history can contain sensitive SQL, including a password accidentally typed inside a statement. Check its permissions and avoid putting credentials in SQL text. If you intentionally do not want a history file for a session, set it to /dev/null before starting the client:
$ MYSQL_HISTFILE=/dev/null mariadb --host=DB_HOST --user=DB_USER --password DB_NAME
Enter password:
This changes history handling for that process only; it does not erase an existing history file. If a secret was already recorded, leave the session, remove or redact the known sensitive entry according to your local policy, and rotate the credential if it may have been exposed.
When output looks wrong, check the client character set with an explicit --default-character-set=CHARSET; the manpage notes that the installed client can otherwise format multi-byte output unexpectedly. When results are too wide, use \G, --vertical or a pager in interactive Unix sessions. A pager is not used in batch mode.
mysql compatibility name.