The only agent that thinks for itself

Autonomous Monitoring with self-learning AI built-in, operating independently across your entire stack.

Unlimited Metrics & Logs
Machine learning & MCP
5% CPU, 150MB RAM
3GB disk, >1 year retention
800+ integrations, zero config
Dashboards, alerts out of the box
> Discover Netdata Agents

Centralized metrics streaming and storage

Aggregate metrics from multiple agents into centralized Parent nodes for unified monitoring across your infrastructure.

Stream from unlimited agents
Long-term data retention
High availability clustering
Data replication & backup
Scalable architecture
Enterprise-grade security
> Learn about Parents

Fully managed cloud platform

Access your monitoring data from anywhere with our SaaS platform. No infrastructure to manage, automatic updates, and global availability.

Zero infrastructure management
99.9% uptime SLA
Global data centers
Automatic updates & patches
Enterprise SSO & RBAC
SOC2 & ISO certified
> Explore Netdata Cloud

Deploy Netdata Cloud in your infrastructure

Run the full Netdata Cloud platform on-premises for complete data sovereignty and compliance with your security policies.

Complete data sovereignty
Air-gapped deployment
Custom compliance controls
Private network integration
Dedicated support team
Kubernetes & Docker support
> Learn about Cloud On-Premises

Powerful, intuitive monitoring interface

Modern, responsive UI built for real-time troubleshooting with customizable dashboards and advanced visualization capabilities.

Real-time chart updates
Customizable dashboards
Dark & light themes
Advanced filtering & search
Responsive on all devices
Collaboration features
> Explore Netdata UI

Monitor on the go

Native iOS and Android apps bring full monitoring capabilities to your mobile device with real-time alerts and notifications.

iOS & Android apps
Push notifications
Touch-optimized interface
Offline data access
Biometric authentication
Widget support
> Download apps

The future of infrastructure observability

See our strategic direction across AI-native observability, full-stack signals, operational intelligence, and enterprise platform maturity.

AI-native observability
Full-stack signal coverage
Operational intelligence
Enterprise platform maturity
Agent releases every 6 weeks
Cloud continuous delivery
> Explore Product Roadmap

Best energy efficiency

True real-time per-second

100% automated zero config

Centralized observability

Multi-year retention

High availability built-in

Zero maintenance

Always up-to-date

Enterprise security

Complete data control

Air-gap ready

Compliance certified

Millisecond responsiveness

Infinite zoom & pan

Works on any device

Native performance

Instant alerts

Monitor anywhere

AI-native observability

Continuous delivery

Open source foundation

80% Faster Incident Resolution

AI-powered troubleshooting from detection, to root cause and blast radius identification, to reporting.

True Real-Time and Simple, even at Scale

Linearly and infinitely scalable full-stack observability, that can be deployed even mid-crisis.

90% Cost Reduction, Full Fidelity

Instead of centralizing the data, Netdata distributes the code, eliminating pipelines and complexity.

See and Map Your Entire Network

Live topology, flow analytics, and SNMP device and trap monitoring — unified with your full-stack observability.

Control Without Surrender

SOC 2 Type 2 certified with every metric kept on your infrastructure.

Integrations

800+ collectors and notification channels, auto-discovered and ready out of the box.

800+ data collectors
Auto-discovery & zero config
Cloud, infra, app protocols
Notifications out of the box
> Explore integrations
Real Results
46% Cost Reduction

Reduced monitoring costs by 46% while cutting staff overhead by 67%.

— Leonardo Antunez, Codyas

Zero Pipeline

No data shipping. No central storage costs. Query at the edge.

From Our Users
"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

No Query Language

Point-and-click troubleshooting. No PromQL, no LogQL, no learning curve.

Enterprise Ready
67% Less Staff, 46% Cost Cut

Enterprise efficiency without enterprise complexity—real ROI from day one.

— Leonardo Antunez, Codyas

SOC 2 Type 2 Certified

Zero data egress. Only metadata reaches the cloud. Your metrics stay on your infrastructure.

Full Coverage
800+ Collectors

Auto-discovered and configured. No manual setup required.

Any Notification Channel

Slack, PagerDuty, Teams, email, webhooks—all built-in.

Built for the People Who Get Paged

Because 3am alerts deserve instant answers, not hour-long hunts.

Every Industry Has Rules. We Master Them.

See how healthcare, finance, and government teams cut monitoring costs 90% while staying audit-ready.

Monitor Any Technology. Configure Nothing.

Install the agent. It already knows your stack.
From Our Users
"A Rare Unicorn"

Netdata gives more than you invest in it. A rare unicorn that obeys the Pareto rule.

— Eduard Porquet Mateu, TMB Barcelona

99% Downtime Reduction

Reduced website downtime by 99% and cloud bill by 30% using Netdata alerts.

— Falkland Islands Government

Real Savings
30% Cloud Cost Reduction

Optimized resource allocation based on Netdata alerts cut cloud spending by 30%.

— Falkland Islands Government

46% Cost Cut

Reduced monitoring staff by 67% while cutting operational costs by 46%.

— Codyas

Real Coverage
"Plugin for Everything"

Netdata has agent capacity or a plugin for everything, including Windows and Kubernetes.

— Eduard Porquet Mateu, TMB Barcelona

"Out-of-the-Box"

So many out-of-the-box features! I mostly don't have to develop anything.

— Simon Beginn, LANCOM Systems

Real Speed
Troubleshooting in 30 Seconds

From 2-3 minutes to 30 seconds—instant visibility into any node issue.

— Matthew Artist, Nodecraft

20% Downtime Reduction

20% less downtime and 40% budget optimization from out-of-the-box monitoring.

— Simon Beginn, LANCOM Systems

Pay per Node. Unlimited Everything Else.

One price per node. Unlimited metrics, logs, users, and retention. No per-GB surprises.

Free tier—forever
No metric limits or caps
Retention you control
Cancel anytime
> See pricing plans

What's Your Monitoring Really Costing You?

Most teams overpay by 40-60%. Let's find out why.

Expose hidden metric charges
Calculate tool consolidation
Customers report 30-67% savings
Results in under 60 seconds
> See what you're really paying

Your Infrastructure Is Unique. Let's Talk.

Because monitoring 10 nodes is different from monitoring 10,000.

On-prem & air-gapped deployment
Volume pricing & agreements
Architecture review for your scale
Compliance & security support
> Start a conversation

Monitoring That Sells Itself

Deploy in minutes. Impress clients in hours. Earn recurring revenue for years.

30-second live demos close deals
Zero config = zero support burden
Competitive margins & deal protection
Response in 48 hours
> Apply to partner

Per-Second Metrics at Homelab Prices

Same engine, same dashboards, same ML. Just priced for tinkerers.

Community: Free forever · 5 nodes · non-commercial
Homelab: $90/yr · unlimited nodes · fair usage
> Get the Homelab Plan

$1,000 Per Referral. Unlimited Referrals.

Your colleagues get 10% off. You get 10% commission. Everyone wins.

10% of subscriptions, up to $1,000 each
Track earnings inside Netdata Cloud
PayPal/Venmo payouts in 3-4 weeks
No caps, no complexity
> Get your referral link
Cost Proof
40% Budget Optimization

"Netdata's significant positive impact" — LANCOM Systems

Calculate Your Savings

Compare vs Datadog, Grafana, Dynatrace

Savings Proof
46% Cost Reduction

"Cut costs by 46%, staff by 67%" — Codyas

30% Cloud Bill Savings

"Reduced cloud bill by 30%" — Falkland Islands Gov

Enterprise Proof
"Better Than Combined Alternatives"

"Better observability with Netdata than combining other tools." — TMB Barcelona

Real Engineers, <24h Response

DPA, SLAs, on-prem, volume pricing

Why Partners Win
Demo Live Infrastructure

One command, 30 seconds, real data—no sandbox needed

Zero Tickets, High Margins

Auto-config + per-node pricing = predictable profit

Homelab Ready
Free Video Course

8-episode Netdata tutorial by LearnLinux.tv

76k+ GitHub Stars

3rd most starred monitoring project

Worth Recommending
Product That Delivers

Customers report 40-67% cost cuts, 99% downtime reduction

Zero Risk to Your Rep

Free tier lets them try before they buy

AI Support Assistant, Available 24/7

Nedi has access to all official documentation, source code, and resources. Ask any question about Netdata—responds in your language.

Deployment & configuration
Troubleshooting & sizing
Alerts & notifications
Evidence-based answers
> Ask Nedi now

Never Fight Fires Alone

Docs, community, and expert help—pick your path to resolution.

Learn.netdata.cloud docs
Discord, Forums, GitHub
Premium support available
> Get answers now

60 Seconds to First Dashboard

One command to install. Zero config. 850+ integrations documented.

Linux, Windows, K8s, Docker
Auto-discovers your stack
> Read our documentation

76,000+ Engineers Strong

615+ contributors. 1.5M daily downloads. One mission: simplify observability.

Per-Second. 90% Cheaper. Data Stays Home.

Side-by-side comparisons: costs, real-time granularity, and data sovereignty for every major tool.

See why teams switch from Datadog, Prometheus, Grafana, and more.

> Browse all comparisons
Edge-Native Observability, Born Open Source
Per-second visibility, ML on every metric, and data that never leaves your infrastructure.
Founded in 2016
615+ contributors worldwide
Remote-first, engineering-driven
Open source first
> Read our story
Promises We Publish—and Prove
12 principles backed by open code, independent validation, and measurable outcomes.
Open source, peer-reviewed
Zero config, instant value
Data sovereignty by design
Aligned pricing, no surprises
> See all 12 principles
Edge-Native, AI-Ready, 100% Open
76k+ stars. Full ML, AI, and automation—GPLv3+, not premium add-ons.
76,000+ GitHub stars
GPLv3+ licensed forever
ML on every metric, included
Zero vendor lock-in
> Explore our open source
Build Real-Time Observability for the World
Remote-first team shipping per-second monitoring with ML on every metric.
Remote-first, fully distributed
Open source (76k+ stars)
Challenging technical problems
Your code on millions of systems
> See open roles
Meet the Team Behind Netdata
Conferences, meetups, and tradeshows where you can see Netdata in action and talk to the engineers who build it.
Live demos and deep dives
Book 1-on-1 meetings
Talks and panel sessions
Event recaps and photos
> See all events
Talk to a Netdata Human in <24 Hours
Sales, partnerships, press, or professional services—real engineers, fast answers.
Discuss your observability needs
Pricing and volume discounts
Partnership opportunities
Media and press inquiries
> Book a conversation
Your Data. Your Rules.
On-prem data, cloud control plane, transparent terms.
Trust & Scale
76,000+ GitHub Stars

One of the most popular open-source monitoring projects

SOC 2 Type 2 Certified

Enterprise-grade security and compliance

Data Sovereignty

Your metrics stay on your infrastructure

Validated
University of Amsterdam

"Most energy-efficient monitoring solution" — ICSOC 2023, peer-reviewed

ADASTEC (Autonomous Driving)

"Doesn't miss alerts—mission-critical trust for safety software"

Community Stats
615+ Contributors

Global community improving monitoring for everyone

1.5M+ Downloads/Day

Trusted by teams worldwide

GPLv3+ Licensed

Free forever, fully open source agent

Why Join?
Remote-First

Work from anywhere, async-friendly culture

Impact at Scale

Your work helps millions of systems

$ guides / mysql / mysql-tls-encryption-monitoring

Operations Guides

MySQL TLS and encryption monitoring: unencrypted connections and weak auth plugins

MySQL 8.0 generates self-signed certificates on startup and enables TLS by default, but this does not guarantee encrypted traffic. Clients must explicitly request TLS over TCP, and misconfigurations often leave sessions in plaintext without errors. Long-lived accounts frequently remain on mysql_native_password despite its deprecation in MySQL 8.0.34, while caching_sha2_password requires secure transport or RSA key exchange on first connection, causing sporadic authentication failures when client drivers lack encryption configuration. These risks are invisible to standard availability monitoring. This guide covers the status variables, Performance Schema tables, and account audits needed to detect unencrypted connections and weak authentication plugins in production.

flowchart TD
    A[Client connection] --> B{require_secure_transport}
    B -->|ON| C{Secure transport}
    B -->|OFF| D[Allowed: check encryption]
    C -->|No| E[Reject: Error 3159]
    C -->|Yes| F[Allowed: check plugin]
    D --> G{Account REQUIRE SSL}
    G -->|Yes and no TLS| H[Reject]
    G -->|No or TLS| F
    F -->|caching_sha2_password| I{First connect}
    I -->|No TLS/RSA| J[Auth failure]
    I -->|TLS or cached| K[Authenticated]
    F -->|mysql_native_password| L[Deprecated: audit]

What invisible exposure looks like

Unencrypted MySQL traffic usually produces no application errors: connections succeed, queries execute, and metrics look healthy. Exposure only becomes visible when you inspect the transport layer or audit account configuration.

  • Silent plaintext sessions: The server reports have_ssl = YES, but application connection strings omit TLS flags. In performance_schema.threads, TCP connections show CONNECTION_TYPE = 'TCP/IP' instead of 'SSL/TLS'. Health checks that open TCP, send SELECT 1, and close without negotiating TLS inflate the unencrypted connection count without carrying sensitive data, but application queries carrying credentials or user data over the same channel create real exposure.
  • Deprecated plugin persistence: Accounts created before an upgrade to MySQL 8.0 retain mysql_native_password. The server emits warning [MY-013360] to the error log on each use, but these warnings are often lost in log noise.
  • First-connect caching_sha2_password failures: After a password rotation, an application’s first connection attempt fails because the client driver lacks TLS or RSA configuration. The second attempt succeeds because the credential is now cached, making the failure transient and hard to reproduce.
  • Secure transport mismatches: An account with REQUIRE SSL rejects Unix socket connections even though sockets are treated as secure by the server-side require_secure_transport logic. This breaks local admin tools and containerized applications that rely on socket connections.

TLS connection signals to monitor

Global TLS counters and context

Do not rely on have_ssl alone. It indicates the server was built with SSL support and certificates are available, but does not prove clients are using them.

  • Ssl_accepts: Cumulative accepted SSL connections. Compare its growth to total new connections. If Ssl_accepts is flat while connection volume grows, traffic is likely falling back to plaintext.
  • Ssl_finished_accepts and Ssl_finished_connects: Successful SSL connections to the server and from the server to replication sources, respectively.
  • Tls_library_version: Reports the linked OpenSSL version. Confirms TLSv1.3 eligibility, which requires OpenSSL 1.1.1 or newer.

MySQL 8.0 also exposes current_tls_version, current_tls_cipher, and related current_tls_* status variables. These reflect the active TLS context after the last ALTER INSTANCE RELOAD TLS, not the static system variable values. If a runtime reload fails or the server falls back to compiled-in defaults, the current_tls_* values reveal the effective configuration.

Per-connection transport verification

To inspect active connections individually, query performance_schema.threads:

SELECT PROCESSLIST_USER,
       PROCESSLIST_HOST,
       CONNECTION_TYPE
FROM performance_schema.threads
WHERE TYPE = 'FOREGROUND';

CONNECTION_TYPE returns SSL/TLS, TCP/IP, or Socket. Any production TCP connection showing TCP/IP instead of SSL/TLS is a candidate for remediation.

For the current session, SHOW SESSION STATUS LIKE 'Ssl_version' returns an empty string when encryption is not in use. The same applies to Ssl_cipher. These are useful for ad-hoc verification from application client hosts.

Structured channel status

performance_schema.tls_channel_status (available since MySQL 8.0.21) provides a structured view of TLS properties per channel, such as mysql_main and mysql_admin. The PROPERTY column includes the active protocol version and cipher suite, making it easier to parse than legacy global status variables. Query this table after rotating certificates or reloading TLS at runtime to confirm the new context took effect without requiring a restart.

Authentication plugin audit

Detecting deprecated and weak plugins

Inventory all accounts and their authentication plugins:

SELECT user, host, plugin, ssl_type
FROM mysql.user
WHERE user != '';

Flag any account using mysql_native_password. This plugin is deprecated as of MySQL 8.0.34, disabled by default in MySQL 8.4, and removed in MySQL 9.0.0. The server writes warning [MY-013360] to the error log on each connection that uses it.

For environments using roles, remember that role assignments do not change the underlying account plugin. Audit the base user accounts, not just active roles.

caching_sha2_password first-connect requirements

caching_sha2_password is the default authentication plugin in MySQL 8.0. The first connection after account creation or a password change must occur over a secure transport (TLS, Unix socket, or shared memory) or use RSA key-pair password exchange. After the first successful connection, the credential is cached and subsequent connections may succeed even without TLS.

This creates a specific failure signature: after credential rotation, applications that were previously working suddenly produce authentication errors on the first connection attempt, then recover on retry. If you see a spike in Aborted_connects correlated with a password change event but no corresponding persistent outage, check whether the client driver is configured to use TLS or whether the server has been configured with an RSA public key for the plugin.

If the client cannot use TLS and the server has not been configured for RSA key exchange, the authentication fails with an access-denied error. The error is transient from the application’s perspective because once any client successfully caches the credential, subsequent connections from that host may succeed depending on the driver’s caching behavior. This makes the failure appear random during connection pool churn or after failover events.

Account-level SSL requirements

Individual accounts can enforce TLS with REQUIRE SSL. However, REQUIRE SSL demands an SSL connection specifically. It rejects Unix socket and shared memory connections even though those transports are considered secure by the server-side require_secure_transport logic. Before applying REQUIRE SSL broadly, confirm that local tools and sidecar containers do not rely on socket connections.

Server configuration and enforcement checks

require_secure_transport

Setting require_secure_transport = ON causes MySQL to reject any connection that does not use a secure transport. The client receives error 3159 (Connections using insecure transport are prohibited). This is effective lockdown, but a blunt instrument. Before enabling it globally, verify that:

  • All application connection strings explicitly enable TLS or use Unix sockets.
  • All replicas using TCP are configured with SOURCE_SSL=1 (or MASTER_SSL=1 on older versions). Otherwise the replication I/O thread connects over plaintext TCP and is rejected immediately, breaking replication with error 3159 in the replica’s error log.
  • Monitoring and backup tools that connect over TCP support TLS.

tls_version and cipher configuration

tls_version controls which protocols the server permits. In MySQL 8.4 and later, the default is TLSv1.2,TLSv1.3; TLSv1 and TLSv1.1 were removed as of MySQL 8.0.28.

Incorrect cipher configuration can disable encrypted connections entirely. Verify that have_ssl remains YES after any cipher changes.

Certificate expiry

Certificate expiry is a silent failure. The server continues running, but new TLS connections fail when clients enforce validity dates. This manifests as a sudden application-side connection storm while MySQL continues to accept TCP connections. Monitor the certificate files referenced by your TLS configuration. The current_tls_* global status variables show the active certificate paths, which helps confirm which files to check on disk. Schedule file-system validation of those PEM files as part of certificate lifecycle management.

Signals to monitor summary

SignalSourceWhy it mattersWarning sign
Ssl_acceptsSHOW GLOBAL STATUSTracks accepted SSL handshakesFlat or slow growth while total connections increase
CONNECTION_TYPEperformance_schema.threadsShows whether a session uses TCP, SSL, or socketActive TCP entries without SSL/TLS
Ssl_version (session)SHOW SESSION STATUSEmpty string means unencryptedEmpty value on TCP client connections
current_tls_versionSHOW GLOBAL STATUSEffective TLS protocol in useProtocol older than site policy
Tls_library_versionSHOW GLOBAL STATUSLinked OpenSSL versionOpenSSL too old for TLSv1.3
mysql_native_password accountsmysql.userDeprecated pluginAny production account still using it
caching_sha2_password first-connect failuresError log + Aborted_connectsRequires TLS or RSA on first connectionSporadic auth failures after credential rotation
require_secure_transportSHOW GLOBAL VARIABLESGlobal enforcement switchUnexpected error 3159 spikes after enablement
Certificate validityFile system / current_tls_*Expired certs break new TLS connectionsExpiration within planned rotation window

How Netdata helps

  • Correlate encryption adoption with connection health: Netdata tracks Ssl_accepts and total connection rates. A widening gap between total connections and SSL accepts signals plaintext leakage that standard health checks miss.
  • Link auth failures to TLS context changes: Correlate spikes in Aborted_connects with certificate rotation events or ALTER INSTANCE RELOAD TLS operations. This distinguishes caching_sha2_password first-connect failures from brute-force attacks.
  • Audit plugin distribution: Use Netdata’s custom query monitoring to run periodic audits of mysql.user plugin assignments and alert on any account using mysql_native_password.
  • Track TLS version drift: Monitor current_tls_version and Tls_library_version to detect configuration regressions or hosts running outdated OpenSSL builds.
The Netdata solution

MySQL monitoring with Netdata

Netdata monitors MySQL and MariaDB with per-second metrics and ML anomaly detection. Track connection usage, query throughput, slow queries, redo-log pressure, and replication lag alongside the host and storage signals that explain them.