MySQL 8.4 LTS · 9.7 LTS · 26.x Innovation · Percona Server · Aurora, RDS, Cloud SQL, Azure, HeatWave
MySQL Consulting, 24×7 Support and Remote DBA
MySQL consulting from MinervaDB covers the whole estate: InnoDB and query performance engineering, Group Replication and Galera high availability, disaster recovery that has actually been drilled, scaling with ProxySQL and sharding, security and regulatory compliance across every jurisdiction our customers operate in, cloud MySQL on AWS, Google Cloud, Azure and Oracle, and 24×7 support with named engineers. Delivered by principals who have run MySQL at web scale since the 5.x days.
01 · The engine in 2026
MySQL in 2026: what changed and what it means for MySQL consulting
The release model changed twice in two years. MySQL consulting that does not start from the lifecycle calendar is guessing, so we start there.
The four facts that decide most MySQL consulting engagements this year
- MySQL 8.0 is out of support. The final build, 8.0.46, shipped in April 2026 alongside 9.7. An 8.0 estate no longer receives security fixes, which is a finding under PCI DSS, SOC 2, ISO 27001 and most regulator guidance, not just a technical debt item.
- There are two LTS lines to choose between. 8.4 LTS (GA April 2024) is the conservative target with the smallest behaviour change from 8.0. 9.7 LTS (21 April 2026) carries the features Oracle moved from Enterprise to Community: the hypergraph optimizer, JSON duality views with full DML, the telemetry component for Prometheus and OpenTelemetry, replication applier metrics and the Group Replication flow-control, resource-manager and primary-election controls.
- Calendar versioning started with 26.7.0 on 31 July 2026. Innovation releases are now YY.M.P and are supported only until the next one. 26.7 adds the change-stream applier for multithreaded replication (1 to 1,024 workers per channel), post-quantum TLS with OpenSSL 3.5, and moves the Thread Pool plugin into Community Edition.
- Upgrades cannot skip an LTS. 8.4 goes to 9.7 before anything calendar-versioned; only 9.7 upgrades into the 26.x lineage. Estates still on 5.7 have a two- or three-hop project ahead of them, and we plan it as one.
Editions and forks MySQL consulting has to work across
| Distribution | Where it fits | What to know |
|---|---|---|
| MySQL Community 8.4 LTS / 9.7 LTS | Default for most estates | Free; Thread Pool (26.x), telemetry and hypergraph optimizer now included; no MEB, Audit, Firewall, Data Masking or keyring-vault TDE |
| MySQL Enterprise Edition | Regulated estates wanting Oracle-supported audit, TDE with external key management, masking and firewall | Subscription per server; features tracked per release; we scope whether the Percona equivalents suffice before you sign |
| Percona Server for MySQL | Community estates that need audit logging, encryption with vault integration and PMM at no licence cost | Drop-in; XtraBackup for hot backups; MyRocks for write-heavy, compressed workloads |
| MariaDB Community / Enterprise | Diverged fork; different GTID, optimizer, JSON handling | Not a MySQL patch level; migrations in either direction are projects. See our MariaDB practice |
| HeatWave MySQL (OCI) | Oracle-managed with in-memory analytics and Lakehouse | Version tracks and forced upgrades set by Oracle; we run the exit path as well as the adoption path |
02 · Scope
What MySQL consulting from MinervaDB covers
One practice, eight lines of work, the same engineers on all of them. Nothing here is resold; we hold no vendor quota for MySQL Enterprise, HeatWave or any cloud.
| Line of work | What it includes | Typical trigger |
|---|---|---|
| Performance engineering | InnoDB and OS tuning, query and index engineering, schema review, benchmarking with sysbench and tpcc-mysql, plan regressions after upgrades | p95 latency regressions, CPU saturation, replication lag, a cloud bill that grew faster than traffic |
| High availability and disaster recovery | InnoDB Cluster and Group Replication, Galera and Percona XtraDB Cluster, semi-synchronous replication, Orchestrator, MySQL Router and ProxySQL, DR replicas with drilled promotion | An outage that took hours, a failover nobody trusts, an audit asking for the RTO evidence |
| Scalability | Read scaling, ProxySQL query routing, connection pooling and thread pool, partitioning, sharding with Vitess or application-level keys, archival tiers | Write throughput ceiling, a single hot table, connection storms from autoscaled services |
| Security and regulatory compliance | TDE and key management, TLS, roles and least privilege, audit logging, data masking, retention, residency, and the evidence packs auditors ask for | An audit finding, a new market, a customer security questionnaire, 8.0 end of life |
| Cloud MySQL | Aurora MySQL, RDS for MySQL, Cloud SQL, Azure Database for MySQL Flexible Server, HeatWave; parameter groups, Multi-AZ and read replicas, cost modelling, exits | Cloud cost review, cross-cloud move, managed-service limits hit |
| Upgrades and migrations | 5.7 and 8.0 to 8.4 or 9.7 LTS, 9.7 to 26.x, Oracle and SQL Server to MySQL, MariaDB to MySQL and back, on-premises to cloud and back | End of life, licence renewal, a data-centre exit |
| 24×7 support and remote DBA | Named engineers, S1 in 15 minutes, monitoring with PMM, monthly health reports, quarterly restore and failover drills | A team of one DBA, a vacancy, a compliance requirement for 24×7 coverage |
| Data recovery | Dropped databases, corrupted InnoDB files, broken XtraBackup sets, replication chains that will not resync, file-system damage | The 3 a.m. call |
Every MySQL consulting engagement starts with measurement, not opinion. Recommendations name the counter, table or plan that justifies them, and every change carries a rollback path. Test on non-production first; keep verified backups and a drilled DR posture.
03 · Performance
MySQL consulting for performance, with evidence attached
The MySQL consulting work we are called for most often. We do not tune by folklore; we read the counters, attach the plan and change one thing at a time.
InnoDB and server parameters MySQL consulting sets from measurement
| Parameter | Set from | Common mistake |
|---|---|---|
innodb_buffer_pool_size |
Working-set size from innodb_buffer_pool_stats hit ratio and page reads, not a percentage of RAM |
75% rule on a box that also runs the application |
innodb_redo_log_capacity |
Checkpoint age and log write rate at peak; large enough that fuzzy checkpointing never stalls writes | Left at default on a write-heavy 8.x estate |
innodb_io_capacity / _max |
Measured device IOPS and the flush pressure in innodb_metrics |
Set to the NVMe spec sheet, starving foreground I/O |
innodb_flush_log_at_trx_commit, sync_binlog |
The durability the business signed off, in writing | Set to 2 and 0 to fix latency, then forgotten |
thread_pool_size, max_connections |
Concurrency measured at the proxy; Thread Pool is now Community in 26.x | 10,000 connections and no pooler |
replica_parallel_workers |
Applier lag per worker from replication_applier_status_by_worker |
Parallel replication switched on without WRITESET dependency tracking |
innodb_page_size, compression |
Row size, read amplification, storage cost per TiB | Compression enabled on a CPU-bound host |
Query and schema work in MySQL consulting
Most latency lives in a small number of statements, and most MySQL consulting hours go there. We pull them from the slow log and the digest tables in performance_schema, run EXPLAIN ANALYZE on the production data distribution, and fix the plan with an index, a rewrite, a covering index, an invisible-index trial or, occasionally, an optimizer hint. Schema work follows: data types that match the domain, primary keys that are monotonic where InnoDB wants them, foreign keys that exist, and partitioning only where the pruning is real.
Upgrades change plans. 9.7 ships the hypergraph optimizer in Community Edition; we capture digests before and after and compare, rather than hoping. Where an upgrade regresses a plan we pin it, file it and hand the case back with evidence.
-- The five statements that cost the most time since the last reset
SELECT digest_text,
count_star AS calls,
ROUND(sum_timer_wait / 1e12, 1) AS total_s,
ROUND(avg_timer_wait / 1e9, 2) AS avg_ms,
sum_rows_examined / GREATEST(sum_rows_sent, 1) AS examined_per_sent
FROM performance_schema.events_statements_summary_by_digest
WHERE schema_name NOT IN ('mysql', 'performance_schema', 'sys')
ORDER BY sum_timer_wait DESC
LIMIT 5;
Benchmarks we run for you use sysbench and tpcc-mysql on your schema and data shape, and every figure we report carries its method. We do not publish generic percentage improvements because they are not yours.
04 · Availability
MySQL consulting for high availability and disaster recovery that have been drilled
An availability design is a claim until it has been failed over on purpose. Our MySQL consulting for HA ends with a drill record, not a diagram.

Topologies our MySQL consulting team designs and operates
| Topology | Best for | Watch out for |
|---|---|---|
| InnoDB Cluster (Group Replication, single-primary) | Most transactional estates on 8.4 or 9.7 LTS wanting automatic failover with a supported toolset | Large transactions and flow control; certification conflicts in multi-primary; three voting members minimum |
| Galera / Percona XtraDB Cluster | Multi-writer with synchronous certification, WAN-tolerant with segments | Write-set size, DDL with TOI, SST cost on large datasets |
| Asynchronous and semi-synchronous replication with Orchestrator | Read scaling and DR, legacy estates, cross-region | GTID gaps, errant transactions, replica lag under bulk loads |
| Delayed replica | Undo for dropped tables and bad deploys | Must be rehearsed; becomes stale if lag is not monitored |
| MySQL NDB Cluster | Sub-millisecond, telecom-grade workloads with a specific data model | Not a general-purpose InnoDB replacement; schema constraints |
Disaster recovery MySQL consulting can prove
RPO and RTO are set by the business and written into the runbook; MySQL consulting turns them into a topology. We then build to them: binlog archiving for point-in-time recovery, XtraBackup or MySQL Enterprise Backup with encryption and off-site copies, a cross-region replica with GTID auto-positioning, and a promotion procedure that has been run, timed and recorded. Quarterly drills are part of every support retainer, and the drill record is the document your auditor asks for under DORA, PCI DSS 12.10, ISO 27001 A.5.30 or HIPAA contingency planning.
Failover automation is only as good as its fencing. We configure super_read_only, Router or ProxySQL health checks, and Orchestrator or MySQL Shell AdminAPI so that a partition cannot produce two writers, and we test the split-brain case deliberately.
05 · Scale
MySQL consulting for scale: growing without rewriting the application first
Most estates have three or four cheap scaling moves left before sharding. MySQL consulting on scale is about finding them in order.
| Move | What it buys | When it stops working |
|---|---|---|
| Query and index work | Often the largest single gain; removes rows examined, not just latency | When the workload is already lean and CPU-bound on the primary |
| Connection pooling and Thread Pool | Survives connection storms from autoscaled services; Thread Pool is Community in 26.x | When the bottleneck is lock contention, not scheduling |
| Read scaling through Router or ProxySQL | Moves reads to secondaries with lag-aware routing and query rules | Read-after-write consistency needs; write-heavy workloads |
| Partitioning and archival | Pruning for time-series and tenant data; smaller hot set | Queries that do not filter on the partition key |
| Vertical scaling | Fastest to execute; buys time for the moves above | Price per vCPU and the largest instance in the region |
| Sharding (Vitess, ProxySQL sharding rules, application keys) | Horizontal write scaling; per-tenant isolation | Cross-shard transactions and reporting; operational maturity required |
| Offload analytics | Moves reporting to ClickHouse, HeatWave or a warehouse; primary returns to OLTP | When the report needs the row that was written a second ago |
Where sharding is the right answer, MySQL consulting designs the key from access patterns in the digest tables, not from the largest table, and we run the migration behind a routing layer so that tenants move one at a time. Where analytics is the load, our ClickHouse practice takes the reporting workload off the primary.
06 · Security and regulatory compliance
MySQL consulting for security and regulatory compliance, by country and by industry
Compliance is a set of technical controls plus the evidence that they held, which is why MySQL consulting and compliance work are the same engagement here. Our MySQL consulting implements the controls, produces the evidence and keeps both current as regulations change. Legal interpretation stays with your counsel; we make the database defensible.
The MySQL controls behind every regulation our MySQL consulting implements
| MySQL control | How we implement it | Regulations it typically satisfies |
|---|---|---|
| Encryption at rest | InnoDB tablespace, redo and undo encryption with keyring_file (dev only), keyring_okv, keyring_aws, keyring_hashicorp or Percona keyring_vault; binlog encryption; encrypted backups | PCI DSS 3.5, HIPAA 164.312(a)(2)(iv), GDPR Art. 32, DPDP reasonable safeguards, NYDFS 500.15, GLBA Safeguards |
| Encryption in transit | TLS 1.2 minimum, TLS 1.3 preferred, require_secure_transport, certificate rotation, post-quantum cipher trials on 26.x with OpenSSL 3.5 |
PCI DSS 4.2, HIPAA 164.312(e), GDPR Art. 32, MAS TRM, APRA CPS 234 |
| Identity and least privilege | Roles, caching_sha2_password, password validation and expiry, account locking, LDAP or Kerberos via authentication plugins, per-service accounts, proxy-enforced MFA |
SOX ITGC, PCI DSS 7 and 8, ISO 27001 A.5.15, SOC 2 CC6, FedRAMP AC family |
| Audit logging | MySQL Enterprise Audit or Percona audit_log_filter, filtered to DDL, privilege and data access events; forwarded to SIEM; retention and integrity checks |
SOX, PCI DSS 10, HIPAA 164.312(b), GDPR accountability, RBI and SEBI system audit, DORA logging |
| Data masking and minimisation | MySQL Enterprise Data Masking, Percona data masking component, views and column grants, de-identified copies for non-production | GDPR Art. 5 and 25, CCPA/CPRA, PCI DSS 3.4, HIPAA de-identification, DPDP purpose limitation |
| Backup, retention and deletion | Encrypted PITR with retention matched to the statute, tested restores, documented erasure procedure across replicas and backups | GDPR Art. 17, DPDP erasure, HIPAA 164.316, SOX record retention, LGPD Art. 18 |
| Availability and resilience | Drilled DR, tested failover, RTO/RPO evidence, incident and problem records | DORA Art. 11 and 12, NIS2 Art. 21, PCI DSS 12.10, HIPAA contingency plan, APRA CPS 230 |
| Change and configuration control | Baseline hardening (CIS MySQL Benchmark), drift detection, change records with approval and rollback, CVE patch calendar now that 8.0 is unsupported | SOX, ISO 27001 A.8.9, SOC 2 CC8, PCI DSS 6, CMMC CM family |
| Residency and transfer | Region-pinned primaries and replicas, no cross-border replica without a documented basis, cloud region selection, localisation for payment and health data | China PIPL, Russia 242-FZ, India RBI payment-data rule, Indonesia PDP, Saudi PDPL, EU SCCs and EU-US DPF |
Americas
| Jurisdiction and regulation | What it asks of a MySQL estate | What we deliver |
|---|---|---|
| United States: HIPAA and HITECH | ePHI encrypted in transit and at rest, access logging, contingency plan, minimum necessary access, BAAs with any managed provider | TDE and TLS, audit filter for PHI tables, drilled restore, role review, BAA-ready documentation for cloud MySQL |
| United States: PCI DSS 4.0.1 | Cardholder data encrypted or tokenised, key management, quarterly reviews, logging with one year retention, no unsupported software | PAN column controls or tokenisation design, keyring with external KMS, audit retention, upgrade off 8.0 with evidence |
| United States: SOX | IT general controls over financial data: access, change, operations | Segregated accounts, change records with approval, audit log evidence, quarterly access certification |
| United States: GLBA Safeguards Rule, FFIEC, NYDFS 23 NYCRR 500 | Risk-based programme, encryption, MFA, logging, incident notification within 72 hours (NYDFS) | Control mapping, encryption everywhere, proxy MFA, incident runbook with notification timeline |
| United States: FedRAMP, FISMA, NIST SP 800-53, CMMC 2.0 | Control families for access, audit, configuration, contingency; FIPS-validated cryptography | FIPS mode OpenSSL, CIS hardening, SSP-ready configuration evidence, continuous monitoring exports |
| United States: CCPA/CPRA and state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others) | Consumer access, deletion and correction; data inventory; reasonable security | Data inventory of PI columns, erasure procedure across replicas and backups, access-request query pack |
| United States: FERPA and COPPA | Student and children’s data access limits, parental consent records | Role design per institution, masking for support staff, audit of exports |
| Canada: PIPEDA and Quebec Law 25 | Consent, safeguards, breach records, privacy impact assessments, Quebec residency assessments for transfers | Canadian-region hosting where required, encryption and logging, transfer assessment inputs |
| Brazil: LGPD | Legal basis, data subject rights, security measures, ANPD incident reporting | Rights-request query pack, encryption, audit trail, retention schedule |
| Mexico: LFPDPPP; Argentina: PDPA 25.326; Chile and Colombia data protection laws | Notice, consent, security measures, cross-border transfer conditions | Region selection, control baseline, transfer documentation |
Europe and the United Kingdom
| Jurisdiction and regulation | What it asks of a MySQL estate | What we deliver |
|---|---|---|
| European Union: GDPR | Lawful basis, minimisation, security of processing (Art. 32), breach notification within 72 hours, data subject rights, records of processing, transfers under SCCs or the EU-US Data Privacy Framework | Encryption, pseudonymisation and masking, erasure that reaches replicas and backups, access logging, EU-region pinning, DPIA inputs |
| European Union: DORA (in force 17 January 2025) | ICT risk management, incident reporting, resilience testing, third-party risk for financial entities | Drilled failover and restore with records, incident classification runbook, ICT third-party register entries for cloud MySQL |
| European Union: NIS2 | Risk measures, incident handling, business continuity, supply-chain security for essential and important entities | Hardening baseline, logging to SIEM, DR evidence, patch calendar |
| European Union: PSD2, EBA outsourcing guidelines, MiFID II record keeping | Strong customer authentication data protection, outsourcing registers, retention of records | Access controls, retention configuration, outsourcing documentation for managed MySQL |
| European Union: EU AI Act | Data governance for training and inference data held in databases | Lineage and access evidence for datasets served from MySQL |
| United Kingdom: UK GDPR and Data Protection Act 2018, FCA and PRA operational resilience | As GDPR, with UK adequacy and IDTA for transfers; impact tolerances for important business services | UK-region hosting, transfer paperwork inputs, RTO evidence against impact tolerances |
| Switzerland: revised FADP (2023) | Privacy by design, breach notification, transfer rules | Encryption, logging, region selection |
| Germany: BDSG and BaFin BAIT/VAIT; France: CNIL guidance; Netherlands: DNB Good Practice | Sector supplements to GDPR for banks and insurers | Control mapping to the supervisor’s expectations, audit-ready configuration |
Middle East and Africa
| Jurisdiction and regulation | What it asks of a MySQL estate | What we deliver |
|---|---|---|
| United Arab Emirates: Federal PDPL, DIFC DP Law, ADGM DP Regulations, ICT Health Law, CBUAE and DFSA rules | Consent and security, in-country storage for health data, financial-sector outsourcing and cloud rules | UAE-region hosting, encryption, audit trail, outsourcing documentation |
| Saudi Arabia: PDPL, SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls | Data localisation with limited transfer exceptions, encryption, logging, SAMA-aligned resilience | In-Kingdom deployment, NCA ECC mapping, drilled DR |
| Qatar PDPPL and QCB; Bahrain PDPL and CBB; Kuwait CITRA; Oman PDPL | Data protection and financial-sector security requirements | Regional hosting, control baseline, evidence packs |
| Israel: Protection of Privacy Law and Data Security Regulations 2017 | Database registration and tiered security obligations by sensitivity | Tier-appropriate controls, access logging, encryption |
| South Africa: POPIA | Processing conditions, security safeguards, breach notification, operator agreements | Encryption, access reviews, retention schedule |
| Nigeria: NDPA 2023; Kenya: Data Protection Act 2019; Ghana, Egypt, Morocco data protection laws | Registration, security measures, transfer conditions | Control baseline, residency where required |
Asia-Pacific
| Jurisdiction and regulation | What it asks of a MySQL estate | What we deliver |
|---|---|---|
| India: DPDP Act 2023 and DPDP Rules 2025, CERT-In directions, RBI payment-data localisation, SEBI CSCRF, IRDAI, MeitY empanelment for government workloads | Reasonable security safeguards, breach notice to the Board and principals, log retention and 6-hour incident reporting under CERT-In, payment data stored only in India, phased Rules obligations through 2027 | India-region hosting for payment and government data, audit log retention, incident runbook aligned to CERT-In and RBI timelines, erasure procedure, evidence for SEBI and IRDAI system audits |
| Singapore: PDPA, MAS Technology Risk Management and Outsourcing guidelines | Protection and retention obligations, breach notification, MAS expectations on resilience and cloud | Encryption, logging, DR evidence, outsourcing documentation for managed MySQL |
| Australia: Privacy Act and APPs, APRA CPS 234 and CPS 230, Notifiable Data Breaches scheme | Information security capability, operational risk and resilience, breach notification | Control baseline, DR evidence against CPS 230 tolerances, breach runbook |
| New Zealand: Privacy Act 2020 | Security safeguards, breach notification, overseas disclosure rules | Encryption and logging, region selection |
| Japan: APPI (2022 amendments), FISC guidelines for financial institutions | Security control measures, breach reporting, transfer conditions | Japan-region hosting, FISC-aligned controls, evidence |
| South Korea: PIPA, Credit Information Act, ISMS-P | Strong encryption for resident registration numbers, access logging, localisation for some financial data | Column-level encryption, audit trail, in-country deployment |
| China: PIPL, Data Security Law, Cybersecurity Law, MLPS 2.0 | Localisation of personal and important data, security assessments for transfers, graded protection | In-country MySQL estates with no cross-border replicas, MLPS-aligned hardening, transfer assessment inputs |
| Hong Kong: PDPO; Taiwan: PDPA; Macau: PDPA | Data protection principles, security, breach handling | Encryption, access controls, logging |
| Indonesia: PDP Law 2022; Malaysia: PDPA 2010 (2024 amendments); Philippines: DPA 2012; Thailand: PDPA; Vietnam: Decree 13 and PDP Law 2025 | Consent, security, localisation in some sectors, breach notification windows as short as 72 hours | Regional hosting, control baseline, breach runbook, retention |
By industry
| Industry | Frameworks that usually apply | What it means for MySQL |
|---|---|---|
| Banking, payments and fintech | PCI DSS 4.0.1, SOX, GLBA, FFIEC, DORA, PSD2, Basel BCBS 239, RBI, MAS TRM, APRA, SAMA, NYDFS | Cardholder data isolation, key management, audit retention, drilled resilience, localisation of payment data, supported versions only |
| Insurance | IRDAI, NAIC Model Law, Solvency II data quality, GDPR, DPDP | Data quality controls, retention, encryption of policyholder data, DR evidence |
| Healthcare and life sciences | HIPAA and HITECH, HITRUST CSF, FDA 21 CFR Part 11, EU Annex 11, GxP, GDPR special categories, ABDM in India | PHI encryption and audit, validated change control, electronic-record integrity, de-identified analytics copies |
| SaaS and technology | SOC 2 Type II, ISO 27001, 27017 and 27018, CSA STAR, GDPR and CCPA as processors | Tenant isolation, evidence automation, customer-facing security questionnaires answered from configuration facts |
| Telecommunications | CPNI (US), TRAI and DoT (India), ePrivacy Directive, lawful intercept retention rules | Retention schedules, access logging, subscriber data masking |
| Retail and e-commerce | PCI DSS, consumer privacy laws, marketplace data rules | Tokenisation, PII masking for analytics, peak-season capacity with compliance intact |
| Public sector and government | FedRAMP, FISMA, CMMC, UK Cyber Essentials Plus, IRAP (Australia), MeitY empanelment (India), Government of Canada PBMM | Sovereign hosting, FIPS cryptography, continuous monitoring exports |
| Manufacturing, automotive and energy | TISAX, UNECE R155, IEC 62443, NERC CIP, NIS2 | Segmented OT and IT data stores, hardened configuration, change control |
| Education | FERPA, COPPA, GDPR for EU students | Role-based access by institution, masking, export audit |
How a MySQL consulting compliance engagement runs
- Inventory, the first MySQL consulting step: which schemas and columns hold regulated data, which jurisdictions the data subjects are in, where every replica and backup physically sits.
- Gap assessment against the regulations that apply, with the CIS MySQL Benchmark as the technical baseline.
- Implementation in staged changes: encryption and key management first, then access and audit, then masking, retention and erasure, then resilience evidence.
- Evidence pack: configuration baseline, access review export, audit log retention proof, restore and failover drill records, change records. Refreshed quarterly on a support retainer.
- Change watch: we track regulatory updates (DPDP Rules phasing, PCI DSS future-dated requirements, DORA technical standards, state privacy laws) and tell you what changes on the database side.
What MySQL consulting from MinervaDB will not do
We will not certify you. SOC 2, ISO 27001, PCI DSS and HITRUST attestations come from auditors and QSAs; our job is to make sure the MySQL evidence they ask for exists, is accurate and is repeatable. We will not give legal advice on whether a regulation applies to you; we will tell you exactly what your MySQL estate does today and what it would take to meet the control as written. And we will not run regulated data on MySQL 8.0 or 5.7 without a written risk acceptance from you, because unsupported software is a finding under every framework above.
Our database security services page covers the cross-engine programme; this section is the MySQL-specific implementation.
07 · Cloud MySQL
Cloud MySQL consulting on AWS, Google Cloud, Azure and Oracle
Managed MySQL changes who runs the platform, not who owns the schema, the plans, the replication design or the bill. That part is still MySQL consulting.
| Service | What the provider runs | What stays with you (and us) | Watch |
|---|---|---|---|
| Amazon Aurora MySQL | Storage layer, failover, patching, backups | Schema, indexes, parameter groups, reader routing, cost model, exit plan | Aurora versions track MySQL 8.0 compatibility; check the engine version calendar before relying on 8.4 or 9.7 features |
| Amazon RDS for MySQL | Host, Multi-AZ, automated backups, minor upgrades | Parameter groups, replication design, PITR testing, storage IOPS sizing | 8.0 end-of-life handling and RDS Extended Support fees |
| Google Cloud SQL for MySQL | Host, HA failover, backups, maintenance | Flags, read replicas, connection pooling, query insights review | Maintenance windows and Enterprise Plus edition features |
| Azure Database for MySQL Flexible Server | Host, zone-redundant HA, backups | Server parameters, read replicas, private link design, cost | Burstable tiers under sustained load |
| HeatWave MySQL on OCI | Managed MySQL with in-memory analytics, Lakehouse, AutoML | Schema for HeatWave offload, cluster sizing, exit path | Version tracks and forced upgrades set by Oracle |
| Self-managed on EC2, GCE, Azure VMs, Kubernetes (Percona Operator) | Nothing | Everything, with full control and any version including 26.x | Operational load unless a remote DBA carries it |
MySQL consulting on cloud models every option with your measured profile and the provider’s current price list, including extended-support surcharges for unsupported major versions. When the numbers favour self-managed MySQL with a remote DBA, we say so; when they favour Aurora or HeatWave, we say that too.
08 · Upgrades and migrations
MySQL consulting for upgrades off 8.0 and migrations into MySQL
Every 8.0 estate is now an upgrade project with a compliance deadline attached. Every 5.7 estate is two of them.
The upgrade method our MySQL consulting team uses
- Inventory with
mysqlsh util.checkForServerUpgrade()on the real dataset; removed features, reserved words, charset and collation changes, authentication plugin migration offmysql_native_password. - Plan capture: digests and
EXPLAINoutput for the top statements before the upgrade, compared after; 9.7’s hypergraph optimizer is the usual source of plan change. - Rehearsal on a clone with the application regression suite, then a replica-first rollout: upgrade replicas, verify replication and plans, switch the primary with Router or ProxySQL, keep the old primary as a downgrade path for the agreed soak period.
- Path discipline: 5.7 to 8.0.46 to 8.4 LTS, or on to 9.7 LTS; 9.7 only into 26.x. No skipping an LTS series.
- Cloud estates: engine version availability and extended-support pricing are checked first; on Aurora the compatibility line, not the community version, sets the plan.
MySQL consulting for migrations into and out of MySQL
| Path | Method | Long pole |
|---|---|---|
| Oracle Database to MySQL | Schema and PL/SQL conversion, data load with reconciliation, application changes | Procedural code, sequences, date and NULL semantics |
| SQL Server to MySQL | T-SQL conversion, identity and collation mapping, replication cutover | Stored procedures and cross-database queries |
| MariaDB to MySQL and MySQL to MariaDB | Logical dump or replication where versions permit; GTID formats differ | Divergent features: sequences, system-versioned tables, JSON handling |
| Aurora or HeatWave to self-managed (and back) | Replication-based cutover with DMS or native replication | Provider-specific features and parameter parity |
| Sharding and re-platforming | Vitess or routing-layer moves, tenant by tenant | Cross-shard reporting |
09 · Support
24×7 MySQL support and remote DBA: MySQL consulting that never signs off
The support retainer is where MySQL consulting becomes a standing relationship. Same engineers, same evidence discipline, around the clock.
MySQL consulting severity matrix
| Severity | Definition | Acknowledgement |
|---|---|---|
| S1 | Production down or data at risk; business halted | 15 minutes, 24×7 |
| S2 | Production degraded; a business function directly affected | 12 hours |
| S3 | Non-production affected, or production issue with a workaround | 24 hours |
| S4 | Advice, best-practice questions, planned work | 48 hours |
Every S1 ends with a written root-cause analysis: timeline, evidence, fix and the change that prevents recurrence.
What the MySQL consulting retainer includes
- Onboarding health check and an operational runbook for your estate
- Monitoring with Percona Monitoring and Management, Prometheus or Datadog; alert thresholds we own and tune
- Monthly health report: top statements, InnoDB headroom, replication lag, backup validation, patch status, cost against plan
- Quarterly restore and failover drills with measured recovery time; the record doubles as compliance evidence
- Security patch calendar and CVE triage, now mandatory for anything still on 8.0
- Advisory hours for schema review, capacity questions and version planning
- Vacation DBA cover with full handover documentation when your resident DBA is away
Emergency help is available to non-customers as well; our MySQL support and MySQL remote DBA pages describe the standing services in detail.
10 · Pricing
MySQL consulting pricing and engagement models
Published MySQL consulting rates, no infrastructure overhead, principal-level engineers on every engagement.
On-site MySQL consulting
USD 600 per hour, plus travel
Architecture reviews, infrastructure assessments, workshops, implementation oversight and executive briefings at your data centre or office.
Remote MySQL consulting
USD 350 per hour
Performance engineering, scaling and HA design, DR implementation, security hardening, schema and code review, delivered over secure remote access.
Flexible consulting plans
From USD 1,200 per month
4 to 40 hours a month for teams that need a senior MySQL engineer on call without a long-term contract. Quarterly, half-yearly and annual billing.
Data recovery
USD 500 per hour, 24×7
Dropped databases, corrupted InnoDB files, broken XtraBackup sets, replication chains that will not resync, file-system damage.
Support and remote DBA retainers are quoted on cluster count, data volume and coverage window after a scoping call. Standing conditions: changes are tested on non-production first, verified backups precede any schema or version change, and regulated estates keep a drilled DR posture.
11 · FAQ
MySQL consulting: questions we are asked before a scoping call
Short MySQL consulting answers; the sections above carry the detail.
Is MySQL 8.0 still safe to run?
It is out of support since April 2026; 8.0.46 was the final build and no further security fixes will be issued. Under PCI DSS, SOC 2, ISO 27001 and most regulator guidance that is a finding. Our MySQL consulting team plans the move to 8.4 LTS or 9.7 LTS as a staged, rehearsed upgrade with a downgrade path.
Should we choose MySQL 8.4 LTS or 9.7 LTS?
8.4 LTS is the conservative target with the least behaviour change from 8.0. 9.7 LTS carries the features Oracle moved into Community Edition in 2026 and is the only line that upgrades into the calendar-versioned 26.x series. We recommend from your extension, driver and plan-stability inventory rather than by default.
Do you support Percona Server and MariaDB as well as Oracle MySQL?
Yes. Our MySQL consulting practice runs Percona Server for MySQL widely for its audit, encryption and backup tooling. MariaDB is a diverged fork with its own practice at MinervaDB; migrations between MariaDB and MySQL in either direction are projects, not patches.
Which regulations can you help us meet on MySQL?
The section above lists the jurisdictions and industries we work in, from GDPR, UK GDPR, DORA and NIS2 through HIPAA, PCI DSS 4.0.1, SOX and FedRAMP to DPDP, RBI, MAS, APRA, PIPL, LGPD, POPIA and the Gulf data protection laws. We implement the MySQL controls and produce the evidence; certification and legal interpretation stay with your auditors and counsel.
Can you run MySQL for us 24×7?
Yes. The support retainer provides named engineers, S1 acknowledgement in 15 minutes around the clock, monitoring, monthly health reports, quarterly restore and failover drills and a written root cause after every S1.
Do you work on Aurora, RDS, Cloud SQL, Azure and HeatWave?
Yes. The provider runs the host; the schema, plans, replication design, parameter groups and cost model are still yours, which is where MySQL consulting earns its keep, and that is where our MySQL consulting work sits. We also plan exits from managed services when the numbers or the feature gaps call for it.
How do you approach performance problems?
By measurement. MySQL consulting at MinervaDB reads the operating system, InnoDB, server, replication and query layers in that order, attach the plan and the counters to every finding, change one thing at a time on a clone first, and verify against the same counter that raised the issue.
How do we start?
Book a MySQL consulting scoping call. Existing estates usually begin with a health check or a compliance gap assessment; 8.0 and 5.7 estates begin with an upgrade plan.
Related
Further reading
Adjacent MinervaDB practices and the primary sources our MySQL consulting work relies on.
MinervaDB
- 24×7 MySQL support and MySQL remote DBA
- MariaDB remote DBA for the diverged fork
- Database security services: the cross-engine compliance programme
- PostgreSQL consulting when the workload belongs there
- ClickHouse consulting for analytics offload
- Database transformation services
Next step
Talk to a Principal Architect about MySQL
A 30-minute MySQL consulting scoping call, then a written scope. If your estate is on 8.0 or 5.7, bring the version inventory; that conversation is overdue.