https://mariadb.com/docs/server/ref/cs10.6/cli/mariadbd/
https://www.geeksforgeeks.org/how-to-install-mysql-mariadb-in-linux/
https://mariadb.com/docs/server/deploy/topologies/single-node/community-server-10-6/
https://computingpost.medium.com/how-to-install-mariadb-10-6-on-almalinux-9-cbc419de57eb
First set up the repository
sudo yum install curl
curl -LsSO https://r.mariadb.com/downloads/mariadb_repo_setup
echo "6083ef1974d11f49d42ae668fb9d513f7dc2c6276ffa47caed488c4b47268593 mariadb_repo_setup" \
| sha256sum -c -
chmod +x mariadb_repo_setup
sudo ./mariadb_repo_setup \
--mariadb-server-version="mariadb-10.6"
Then install the community server and backup
sudo yum install MariaDB-server MariaDB-backup
vim /etc/my.cnf.d/kwantu.cnf
[mysqld]
datadir=/usr/local/data/mysql
tmpdir=/usr/local/data/mysql_tmp
socket=/usr/local/data/mysql/mysql.sock
user=mysql
bind-address=154.0.175.99
# Disabling symbolic-links is recommended to prevent assorted security risks
symbolic-links=0
character-set-server=utf8
# Recommended in standard MySQL setup
sql_mode=NO_ENGINE_SUBSTITUTION,STRICT_TRANS_TABLES
# Additional options
lower_case_table_names=1
vim /etc/my.cnf.d/kwantu.cnf
Here specify the first 3 lines
[server]
datadir=/usr/local/data/mysql
tmpdir=/usr/local/data/mysql_tmp
socket=/usr/local/data/mysql/mysql.sock
vim /etc/my.cnf.d/client.cnf
Here specify the first 3 lines
[client]
socket=/usr/local/data/mysql/mysql.sock
sudo systemctl edit mariadb
or
vim /etc/systemd/system/mariadb.service.d/override.conf
Add the following lines.
[Service]
# Allow writes to your data directory
ReadWritePaths=/usr/local/data/mysql /usr/local/data/mysql_tmp
# Disable PrivateTmp (to avoid isolated /tmp)
PrivateTmp=false
# Reduce ProtectSystem to "strict" (allows writes to non-core directories)
ProtectSystem=strict
Note that you need to make sure that the temp directory has been created
sudo mkdir /usr/local/data/mysql
sudo chown -R mysql:mysql /usr/local/data/mysql
sudo chmod -R 750 /usr/local/data/mysql
sudo mkdir /usr/local/data/mysql_tmp
sudo chown -R mysql:mysql /usr/local/data/mysql_tmp
sudo chmod -R 750 /usr/local/data/mysql_tmp
Then you need to reinitialise the new data directory
sudo mv /usr/local/data/mysql /usr/local/data/mysql.bak
sudo mariadb-install-db --user=mysql --datadir=/usr/local/data/mysql
sudo chown -R mysql:mysql /usr/local/data/mysql
sudo systemctl daemon-reload
sudo systemctl restart mariadb
sudo systemctl start mariadb
sudo systemctl enable mariadb
sudo systemctl status mariadb
Test that you can access it by typing mariadb. Then run the securing script
/usr/bin/mariadb-secure-installation --socket=/usr/local/data/mysql/mysql.sock
NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MariaDB
SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY!
In order to log into MariaDB to secure it, we'll need the current
password for the root user. If you've just installed MariaDB, and
haven't set the root password yet, you should just press enter here.
Enter current password for root (enter for none):
OK, successfully used password, moving on...
Setting the root password or using the unix_socket ensures that nobody
can log into the MariaDB root user without the proper authorisation.
You already have your root account protected, so you can safely answer 'n'.
Switch to unix_socket authentication [Y/n] n
... skipping.
You already have your root account protected, so you can safely answer 'n'.
Change the root password? [Y/n] y
New password:
Re-enter new password:
Password updated successfully!
Reloading privilege tables..
... Success!
By default, a MariaDB installation has an anonymous user, allowing anyone
to log into MariaDB without having to have a user account created for
them. This is intended only for testing, and to make the installation
go a bit smoother. You should remove them before moving into a
production environment.
Remove anonymous users? [Y/n] y
... Success!
Normally, root should only be allowed to connect from 'localhost'. This
ensures that someone cannot guess at the root password from the network.
Disallow root login remotely? [Y/n] y
... Success!
By default, MariaDB comes with a database named 'test' that anyone can
access. This is also intended only for testing, and should be removed
before moving into a production environment.
Remove test database and access to it? [Y/n] y
firewall-cmd --permanent --add-port=3306/tcp
firewall-cmd --reload
Open the mariadb client
mariadb -u root -S /usr/local/data/mysql/mysql.sock -p
Specify the root and kwantu user access
-- Grant remote access to root from any IP
GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY 'your_strong_password_here';
-- Flush privileges to apply changes
FLUSH PRIVILEGES;
For a large-scale MariaDB deployment handling ~1 million records per day, you need to optimize performance, reliability, and logging while ensuring efficient resource usage. Below are recommended server configurations and logging settings for a production environment.
🔧 Recommended MariaDB Server Configuration
CPU: 8+ cores (preferably Intel/AMD with high clock speed)
RAM: 32GB+ (adjust innodb_buffer_pool_size accordingly)
Storage: NVMe SSD (for high IOPS) or fast SAS/SATA SSD in RAID 10 (avoid HDDs)
OS: Linux (Ubuntu 22.04 LTS / RHEL 8+ / Debian 11+)
[mysqld]
# General Settings
datadir = /var/lib/mysql
socket = /var/lib/mysql/mysql.sock
pid-file = /var/run/mysqld/mysqld.pid
# Performance & Memory
innodb_buffer_pool_size = 16G # ~70-80% of total RAM
innodb_buffer_pool_instances = 8 # For multi-core scaling
innodb_log_file_size = 2G # Larger log files reduce disk I/O
innodb_log_buffer_size = 256M
innodb_flush_log_at_trx_commit = 2 # Balance durability & speed (1 for full ACID)
innodb_flush_method = O_DIRECT # Bypass OS cache for InnoDB
innodb_read_io_threads = 16
innodb_write_io_threads = 16
innodb_io_capacity = 2000 # Higher for SSDs
innodb_io_capacity_max = 4000
# Query Optimization
query_cache_type = 0 # Disable query cache (often harmful in MariaDB 10+)
query_cache_size = 0
table_open_cache = 4000
thread_cache_size = 100
max_connections = 300 # Adjust based on application needs
tmp_table_size = 256M
max_heap_table_size = 256M
# Replication & High Availability (if applicable)
server-id = 1
log_bin = /var/log/mysql/mysql-bin.log
binlog_format = ROW # Recommended for data consistency
sync_binlog = 1 # Durability (set to 0 for performance if needed)
expire_logs_days = 7 # Auto-clean old binary logs
[mysqld]
# Error Log (for debugging crashes/errors)
log_error = /var/log/mysql/mysql-error.log
# Slow Query Log (identify performance bottlenecks)
slow_query_log = 1
slow_query_log_file = /var/log/mysql/mysql-slow.log
long_query_time = 2 # Log queries taking >2 sec
log_queries_not_using_indexes = 1 # Log queries without index usage
# General Log (Avoid in production unless debugging)
general_log = 0
general_log_file = /var/log/mysql/mysql-general.log
binlog_format = ROW
binlog_row_image = FULL
expire_logs_days = 7
sync_binlog = 1 # Slower but safer (0 for performance)
sudo nano /etc/logrotate.d/mysql
Add:
/var/log/mysql/mysql-error.log
/var/log/mysql/mysql-slow.log
{
daily
rotate 7
missingok
compress
delaycompress
notifempty
create 640 mysql mysql
postrotate
/usr/bin/mysqladmin flush-logs
endscript
}
Use Partitioning if dealing with large tables (e.g., time-based partitioning).
Optimize Indexes (avoid over-indexing, use EXPLAIN to analyze queries).
Enable Monitoring (Prometheus + Grafana, or mytop/pt-query-digest).
Source: 192.10.10.3
Destination: 192.10.10.7
This will allow for anything happening with the source server, so that we can switch over to the backup server without significant delay.
This creates actual backup files on the remote server, with the ability to do point in time recovery if needed. This will cover for actual database corruption that impacts the replication, or catastrophic data loss.
The strategy is to have a weekly full backup to a remote server running that sunday morning at 0h30
Four hourly incremental backups running at the following hours:
00,04,08,12,16,20:00:00
And a continuous backup of the binary logs to allow for point in time restore.
SOURCE
192.10.10.3
datadir: /home/mysql/data/mysql
DESTINATION
192.10.10.7
backup root: /backup/mariadb
SSH user: backup
POLICY
Full physical backup: Sunday 00:30
Incremental physical backup: every 4 hours
Binary logs: continuous remote archive
Retention: 4 weekly physical backup chains
sudo mkdir -p /backup/mariadb/{physical/chains,state,binlog}
sudo chown -R backup:backup /backup/mariadb
sudo chmod 750 /backup/mariadb
Install/copy:
destination/mariadb-backup-retention.sh -> /usr/local/sbin/
destination/start-binlog-archive.sh -> /usr/local/sbin/
systemd-destination/* -> /etc/systemd/system/
sudo chmod 755 /usr/local/sbin/mariadb-backup-retention.sh
sudo chmod 755 /usr/local/sbin/start-binlog-archive.sh
Create /etc/mysql/mariadb-backup.cnf on 192.10.10.3, root:root mode 600:
[client]
user=backup
password=CHANGE_ME
socket=/home/mysql/data/mysql/mysql.sock
Use the MariaDB backup privileges appropriate to your 10.6 installation.
Test with:
mariadb --defaults-extra-file=/etc/mysql/mariadb-backup.cnf -e "SELECT VERSION();"
Copy:
source/mariadb-backup-helper -> /usr/local/sbin/
source/mariadb-full-remote.sh -> /usr/local/sbin/
source/mariadb-incremental-remote.sh -> /usr/local/sbin/
systemd-source/* -> /etc/systemd/system/
Root ownership:
sudo chown root:root /usr/local/sbin/mariadb-backup-helper
sudo chmod 755 /usr/local/sbin/mariadb-backup-helper
Other scripts:
sudo chown root:root /usr/local/sbin/mariadb-full-remote.sh
sudo chown root:root /usr/local/sbin/mariadb-incremental-remote.sh
sudo chmod 755 /usr/local/sbin/mariadb-full-remote.sh
sudo chmod 755 /usr/local/sbin/mariadb-incremental-remote.sh
Run visudo and add:
backup ALL=(root) NOPASSWD: /usr/local/sbin/mariadb-backup-helper
Do NOT grant passwordless sudo directly to arbitrary mariadb-backup arguments.
From source, as backup:
ssh backup@192.10.10.7 hostname
It must work without a password for unattended systemd jobs.
On source:
sudo -u backup /usr/local/sbin/mariadb-full-remote.sh
sudo -u backup /usr/local/sbin/mariadb-incremental-remote.sh
Check destination:
find /backup/mariadb/physical/chains -maxdepth 2 -type d
cat /backup/mariadb/state/current_chain
cat /backup/mariadb/state/latest_backup
On source:
sudo systemctl daemon-reload
sudo systemctl enable --now mariadb-full-remote.timer
sudo systemctl enable --now mariadb-incremental-remote.timer
systemctl list-timers 'mariadb'
On destination:
sudo systemctl daemon-reload
sudo systemctl enable --now mariadb-backup-retention.timer
First confirm on source:
mariadb -e "SHOW VARIABLES LIKE 'log_bin';"
mariadb -e "SHOW VARIABLES LIKE 'binlog_format';"
mariadb -e "SHOW BINARY LOGS;"
Create a restricted account on source that can be used from 192.10.10.7.
For MariaDB 10.6 a typical setup uses replication-related privileges; validate
against your security requirements before running:
CREATE USER 'binlog_backup'@'192.10.10.7' IDENTIFIED BY 'xxxxxx';
GRANT REPLICATION SLAVE, REPLICATION CLIENT ON . TO
'binlog_backup'@'192.10.10.7';
On destination create /home/backup/.mariadb-binlog.cnf, mode 600:
[client]
user=binlog_backup
password=CHANGE_ME
protocol=tcp
Then:
chown backup:backup /home/backup/.mariadb-binlog.cnf
chmod 600 /home/backup/.mariadb-binlog.cnf
Test:
mariadb --defaults-extra-file=/home/backup/.mariadb-binlog.cnf
-h 192.10.10.3 -e "SHOW BINARY LOGS;"
Enable:
sudo systemctl enable --now mariadb-binlog-archive.service
journalctl -u mariadb-binlog-archive.service -f
IMPORTANT:
The supplied binlog service is a practical baseline. Before treating it as
your sole PITR mechanism, explicitly test service stop/restart behavior and a
point-in-time restore. Physical backups are not a substitute for validating
your binlog recovery chain.
Do NOT prepare the live retained backup chain automatically. Preparing
modifies the base backup. For a restore, copy the selected chain to a restore
working area, then:
mariadb-backup --prepare --target-dir=/restore/full
mariadb-backup --prepare --target-dir=/restore/full
--incremental-dir=/restore/inc-YYYYMMDD-HHMMSS
...apply increments IN ORDER...
MariaDB requires increments to be applied in chain order.
Source:
journalctl -u mariadb-full-remote.service
journalctl -u mariadb-incremental-remote.service
Destination:
journalctl -u mariadb-backup-retention.service
journalctl -u mariadb-binlog-archive.service
#!/bin/bash
# Root-owned helper. This is the ONLY command willem should be allowed to run
# passwordlessly with sudo.
set -Eeuo pipefail
MODE="${1:-}"
DATADIR="/home/mysql/data/mysql"
CNF="/etc/mysql/mariadb-backup.cnf"
MARIADB_BACKUP="/usr/bin/mariadb-backup"
case "$MODE" in
full)
exec "$MARIADB_BACKUP" \
--defaults-extra-file="$CNF" \
--backup \
--datadir="$DATADIR" \
--stream=xbstream
;;
incremental)
BASEDIR="${2:-}"
# The caller creates a temporary directory containing the previous
# xtrabackup_checkpoints file fetched from the backup server.
if [[ -z "$BASEDIR" || "$BASEDIR" != /var/tmp/mariadb-backup-meta.* ]]; then
echo "ERROR: invalid incremental metadata directory" >&2
exit 2
fi
if [[ ! -f "$BASEDIR/xtrabackup_checkpoints" ]]; then
echo "ERROR: xtrabackup_checkpoints not found in $BASEDIR" >&2
exit 2
fi
exec "$MARIADB_BACKUP" \
--defaults-extra-file="$CNF" \
--backup \
--datadir="$DATADIR" \
--incremental-basedir="$BASEDIR" \
--stream=xbstream
;;
*)
echo "Usage: $0 {full|incremental <metadata-dir>}" >&2
exit 2
;;
esac
#!/bin/bash
set -Eeuo pipefail
BACKUP_HOST="192.10.10.7"
BACKUP_USER="backup"
BACKUP_ROOT="/backup/mariadb"
HELPER="/usr/local/sbin/mariadb-backup-helper"
LOCK="/var/tmp/mariadb-remote-backup.lock"
exec 9>"$LOCK"
if ! flock -n 9; then
echo "Another MariaDB physical backup is already running; exiting."
exit 0
fi
STAMP="$(date +%Y%m%d-%H%M%S)"
CHAIN_REL="physical/chains/${STAMP}"
PARTIAL_REL="${CHAIN_REL}/full.partial"
FINAL_REL="${CHAIN_REL}/full"
cleanup_remote() {
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"rm -rf '${BACKUP_ROOT}/${PARTIAL_REL}'" >/dev/null 2>&1 || true
}
trap cleanup_remote ERR
echo "[$(date -Is)] Starting FULL backup ${STAMP}"
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"mkdir -p '${BACKUP_ROOT}/${PARTIAL_REL}' '${BACKUP_ROOT}/state'"
sudo -n "$HELPER" full \
| ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"mbstream -x -C '${BACKUP_ROOT}/${PARTIAL_REL}'"
# Only publish/update state AFTER both sides of the pipeline succeeded.
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" bash -s -- \
"$BACKUP_ROOT" "$PARTIAL_REL" "$FINAL_REL" "$CHAIN_REL" <<'REMOTE'
set -Eeuo pipefail
ROOT="$1"; PARTIAL="$2"; FINAL="$3"; CHAIN="$4"
mv "$ROOT/$PARTIAL" "$ROOT/$FINAL"
printf '%s\n' "$CHAIN" > "$ROOT/state/current_chain.tmp"
mv "$ROOT/state/current_chain.tmp" "$ROOT/state/current_chain"
printf '%s\n' "$FINAL" > "$ROOT/state/latest_backup.tmp"
mv "$ROOT/state/latest_backup.tmp" "$ROOT/state/latest_backup"
touch "$ROOT/$FINAL/.complete"
REMOTE
trap - ERR
echo "[$(date -Is)] FULL backup complete: ${BACKUP_HOST}:${BACKUP_ROOT}/${FINAL_REL}"
#!/bin/bash
set -Eeuo pipefail
BACKUP_HOST="192.10.10.7"
BACKUP_USER="backup"
BACKUP_ROOT="/backup/mariadb"
HELPER="/usr/local/sbin/mariadb-backup-helper"
LOCK="/var/tmp/mariadb-remote-backup.lock"
exec 9>"$LOCK"
if ! flock -n 9; then
echo "Another MariaDB physical backup is already running; exiting."
exit 0
fi
# Read authoritative chain state from the backup server.
CHAIN_REL="$(ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"cat '${BACKUP_ROOT}/state/current_chain' 2>/dev/null" || true)"
BASE_REL="$(ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"cat '${BACKUP_ROOT}/state/latest_backup' 2>/dev/null" || true)"
if [[ -z "$CHAIN_REL" || -z "$BASE_REL" ]]; then
echo "ERROR: no completed full backup chain exists. Run full backup first." >&2
exit 1
fi
# Fetch ONLY the previous backup checkpoint metadata. No physical backup
# is retained on the source server.
META_DIR="$(mktemp -d /var/tmp/mariadb-backup-meta.XXXXXX)"
trap 'rm -rf "$META_DIR"' EXIT
scp -q \
"${BACKUP_USER}@${BACKUP_HOST}:${BACKUP_ROOT}/${BASE_REL}/xtrabackup_checkpoints" \
"${META_DIR}/xtrabackup_checkpoints"
STAMP="$(date +%Y%m%d-%H%M%S)"
PARTIAL_REL="${CHAIN_REL}/inc-${STAMP}.partial"
FINAL_REL="${CHAIN_REL}/inc-${STAMP}"
cleanup_remote() {
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"rm -rf '${BACKUP_ROOT}/${PARTIAL_REL}'" >/dev/null 2>&1 || true
}
trap cleanup_remote ERR
echo "[$(date -Is)] Starting INCREMENTAL ${STAMP}, base=${BASE_REL}"
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"mkdir -p '${BACKUP_ROOT}/${PARTIAL_REL}'"
sudo -n "$HELPER" incremental "$META_DIR" \
| ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" \
"mbstream -x -C '${BACKUP_ROOT}/${PARTIAL_REL}'"
ssh -o BatchMode=yes "${BACKUP_USER}@${BACKUP_HOST}" bash -s -- \
"$BACKUP_ROOT" "$PARTIAL_REL" "$FINAL_REL" <<'REMOTE'
set -Eeuo pipefail
ROOT="$1"; PARTIAL="$2"; FINAL="$3"
mv "$ROOT/$PARTIAL" "$ROOT/$FINAL"
printf '%s\n' "$FINAL" > "$ROOT/state/latest_backup.tmp"
mv "$ROOT/state/latest_backup.tmp" "$ROOT/state/latest_backup"
touch "$ROOT/$FINAL/.complete"
REMOTE
trap - ERR
echo "[$(date -Is)] INCREMENTAL complete: ${BACKUP_HOST}:${BACKUP_ROOT}/${FINAL_REL}"
[Unit]
Description=MariaDB weekly full backup streamed to 192.10.10.7
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
User=backup
ExecStart=/usr/local/sbin/mariadb-full-remote.sh
[Unit]
Description=Weekly MariaDB full backup timer
[Timer]
# Sunday at 00:30
OnCalendar=Sun *-*-* 00:30:00
Persistent=true
RandomizedDelaySec=0
[Install]
WantedBy=timers.target
[Unit]
Description=MariaDB incremental backup streamed to 192.10.10.7
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
User=backup
ExecStart=/usr/local/sbin/mariadb-incremental-remote.sh
[Unit]
Description=Four-hourly MariaDB incremental backup timer
[Timer]
OnCalendar=*-*-* 00,04,08,12,16,20:00:00
Persistent=true
RandomizedDelaySec=0
[Install]
WantedBy=timers.target
#!/bin/bash
# Run as willem on 192.10.10.7.
# Keeps the newest four complete weekly chains.
set -Eeuo pipefail
ROOT="/backup/mariadb"
CHAINS="$ROOT/physical/chains"
KEEP=4
mkdir -p "$CHAINS" "$ROOT/state"
CURRENT=""
if [[ -f "$ROOT/state/current_chain" ]]; then
CURRENT="$(cat "$ROOT/state/current_chain")"
fi
mapfile -t ALL < <(find "$CHAINS" -mindepth 1 -maxdepth 1 -type d \
-printf '%T@ %p\n' | sort -nr | awk '{print $2}')
count=0
for path in "${ALL[@]}"; do
rel="${path#"$ROOT/"}"
# Never remove the currently active chain.
if [[ "$rel" == "$CURRENT" ]]; then
((count+=1))
continue
fi
if (( count < KEEP )); then
((count+=1))
continue
fi
echo "Deleting expired backup chain: $path"
rm -rf -- "$path"
done
#!/bin/bash
# Run continuously on 192.10.10.7 as willem.
# Requires /home/willem/.mariadb-binlog.cnf and a MariaDB account on 192.10.10.3.
set -Eeuo pipefail
SOURCE_HOST="192.10.10.3"
ROOT="/backup/mariadb"
BINLOG_DIR="$ROOT/binlog"
CNF="/home/backup/.mariadb-binlog.cnf"
mkdir -p "$BINLOG_DIR"
# Start with the oldest binlog still present on the source if this is the
# first run. On subsequent starts, start from the newest local raw binlog.
# Re-reading the newest file is preferable to leaving a gap; a controlled
# restart should be tested in your environment before relying on PITR.
LAST_LOCAL="$(find "$BINLOG_DIR" -maxdepth 1 -type f -printf '%f\n' \
| grep -E '\.[0-9]{6}$' | sort | tail -1 || true)"
if [[ -n "$LAST_LOCAL" ]]; then
START_FILE="$LAST_LOCAL"
else
START_FILE="$(mariadb --defaults-extra-file="$CNF" -h "$SOURCE_HOST" -NBe \
"SHOW BINARY LOGS" | awk 'NR==1 {print $1}')"
fi
if [[ -z "$START_FILE" ]]; then
echo "ERROR: could not determine a source binary log file." >&2
exit 1
fi
echo "[$(date -Is)] Starting raw binlog archive at ${START_FILE}"
cd "$BINLOG_DIR"
exec mariadb-binlog \
--defaults-extra-file="$CNF" \
--read-from-remote-server \
--raw \
--stop-never \
--host="$SOURCE_HOST" \
--result-file="$BINLOG_DIR/" \
"$START_FILE"
scription=Daily MariaDB backup retention timer
[Timer]
OnCalendar=*-*-* 07:00:00
Persistent=true
[Install]
WantedBy=timers.target
[Unit]
Description=MariaDB backup retention cleanup
[Service]
Type=oneshot
User=backup
ExecStart=/usr/local/sbin/mariadb-backup-retention.sh
[Unit]
Description=MariaDB backup retention cleanup
[Service]
Type=oneshot
User=backup
ExecStart=/usr/local/sbin/mariadb-backup-retention.sh
[root@report01 system]# cat /etc/systemd/system/mariadb-binlog-archive.service
[Unit]
Description=Continuously archive MariaDB binary logs from 192.10.10.3
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=backup
ExecStart=/usr/local/sbin/start-binlog-archive.sh
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target