• /
  • EnglishEspañolFrançais日本語한국어Português
  • EntrarComeçar agora

Install & configure NRDOT for MySQL monitoring with Helm

|View as Markdown (English)

You can install and configure MySQL monitoring on Kubernetes using the mysql-otel Helm chart. Optionally, the chart can also run a setup job that creates the monitoring user for you.

Importante

The chart deploys the collector as a Kubernetes Deployment that reaches MySQL remotely over the network. As a result it always connects over TCP (Unix-socket monitoring isn't supported), and it reports MySQL metrics only (no host or infrastructure metrics for the machine MySQL runs on). Using mysql.*, it monitors one MySQL instance per release; to monitor several instances from a single release, use mysqlMulti.* instead (see Monitor multiple instances from one release below).

Prerequisites

  • A valid New Relic license key.
  • MySQL 5.7 or later.
  • Helm 3.0 or later, and kubectl configured to access your Kubernetes cluster.
  • Network connectivity from your Kubernetes cluster to the MySQL host (or RDS endpoint) and port:
    • Self-hosted: a routed path to the MySQL host (VPN, peering, or shared network), DNS resolution if it's a hostname, and the MySQL-side firewall must allow the connection's actual source IP (which may be a NAT gateway, not the pod IP itself).
    • AWS RDS: VPC peering, a transit gateway, or shared-VPC placement with the RDS instance, and the RDS security group must allow the MySQL port (3306 by default) from the cluster's egress source.
  • Either a monitoring user you've already created, or MySQL admin credentials so the chart's setup job can create one for you. See Configure monitoring credentials below.

Create the namespace

Create the namespace you'll install into. It must exist before you create any secrets in the next step, since helm install --create-namespace only creates the namespace during the final install step:

bash
$
kubectl create namespace newrelic

Dica

Set it as the default namespace for your current kubectl context so you don't need to pass -n on every command below:

bash
$
kubectl config set-context --current --namespace=newrelic

Configure monitoring credentials

Decide whether you want the chart's setup job to create the MySQL monitoring user for you, and if not, how you'll supply its credentials:

Configure the Helm values

Set mysql.topology to match your environment:

Value

Description

self-hosted

Self-hosted MySQL, reached over the network.

rds

MySQL or Aurora on AWS RDS.

Use the values.yaml that matches the credential method you chose in the previous step:

Parameter

Description

licenseKey

Your New Relic license key.

otlpEndpoint

Your region's OTLP/gRPC endpoint, as a bare host:port with no scheme: otlp.nr-data.net:4317 (US) or otlp.eu01.nr-data.net:4317 (EU). For more information, refer to New Relic OTLP endpoints documentation.

mysql.server / mysql.port

Your MySQL host (or RDS endpoint) and port, reachable from the cluster.

mysql.database

Optional. Restrict monitoring to one database. Leave empty to monitor all databases.

additionalReceiverConfig.tls.*

Optional. The chart doesn't declare a tls block and has no mysql.tls.* values. The receiver's own defaults apply (insecure: false, insecure_skip_verify: false), which require an encrypted connection with certificate validation. Override them through additionalReceiverConfig: set additionalReceiverConfig.tls.insecure_skip_verify=true to skip certificate validation (for testing with self-signed certificates only, since it weakens the connection's security), or additionalReceiverConfig.tls.ca_file to point at a CA bundle mounted into the collector container. An Amazon RDS instance with Require SSL/TLS enforcement needs ca_file set to Amazon's RDS CA bundle. The chart deliberately ships no default bundle, since a hardcoded bundle risks going stale as Amazon rotates CAs.

setupJob.image.repository / setupJob.image.tag

The mysql CLI image used by the setup job. Defaults to the official, actively maintained mysql:8.4, so enabling the setup job needs no extra image flags. Override only if you need a different version.

setupJob.enableWaitTimeMetrics

Optional. Also grants UPDATE on performance_schema.setup_consumers, which is needed for wait-time data.

(Optional) Monitor multiple instances from one release

Instead of mysql.*, set mysqlMulti.enabled: true to monitor several MySQL instances (self-hosted or RDS) from a single collector pod in one release. The two modes are mutually exclusive: don't set mysql.server and mysqlMulti.enabled: true in the same release.

Multi-instance mode has no plain-username/password path: every instance needs its own Kubernetes secret with monitoring credentials. Decide whether you also want the setup job to create each monitoring user for you:

Parameter

Description

mysqlMulti.enabled

Set to true to monitor multiple instances from one release instead of mysql.*. Defaults to false.

mysqlMulti.topology

self-hosted or rds, same meaning as mysql.topology, shared by every instance in this release.

mysqlMulti.databases

List of instances to monitor. Each entry requires a unique name, server (port defaults to 3306), and existingSecret; database optionally restricts monitoring to one database (same meaning as mysql.database); add mysqlAdmin.existingSecret per entry only when setupJob.enabled is true.

Dica

Scrape settings (collection interval, TLS, statement events, query sample collection, top query collection) apply identically to every instance in mysqlMulti.databases. There's no per-instance override. Use additionalReceiverConfig for anything that needs to differ. The setup job runs once per instance (<release>-setup-<name>) rather than once per release.

Install the Helm chart

  1. Add the New Relic Helm repository:

    bash
    $
    helm repo add newrelic https://helm-charts.newrelic.com
    $
    helm repo update
  2. Install the chart using your values.yaml file:

    bash
    $
    helm upgrade --install mysql-otel newrelic/mysql-otel \
    >
    -n newrelic \
    >
    --create-namespace \
    >
    -f values.yaml

Verify the installation

  1. Check that the setup job completed (if enabled) and the collector pod is running:

    bash
    $
    kubectl get jobs,pods -n newrelic --watch
  2. Run this query in the query builder to confirm data is arriving:

    SELECT count(*) FROM Metric
    WHERE metricName LIKE 'mysql.%'
    AND instrumentation.provider = 'opentelemetry'
    SINCE 10 minutes ago

Find and use your data

Once your data is being collected, you can access comprehensive MySQL database monitoring through the New Relic UI.

To find your MySQL database entity in New Relic:

  1. Go to one.newrelic.com > All capabilities > Databases.
  2. From the Entity type dropdown, select MySQL instance, then click Apply.
  3. Select your MySQL database from the list of entities.

Introduction to MySQL monitoring with NRDOT

Learn about all the available installation methods for MySQL monitoring with New Relic.

CLI install

Learn how to install and configure MySQL monitoring with a single New Relic CLI command.

Ansible install

Learn how to install and configure MySQL monitoring at scale with the newrelic.newrelic_install Ansible role.

Chef install

Learn how to install and configure MySQL monitoring at scale with the newrelic-install Chef cookbook.

Copyright © 2026 New Relic Inc.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.