ServerAvatarDocs
Databases

Create a database

The create form end to end — name, engine, the user that comes with it, and where that user may connect from.

Applications that need a database get one when you create them, so this form is for the extra ones: a second database for an application, something for a script, or a database you want to exist before the code that uses it does.

The panel creates the database and a user for it in the same step, then hands you a connection string. You do not have to touch GRANT or createuser.

Before you start

Decide two things, because changing them afterwards is more work than getting them right now:

  • Which engine — see Database engines. The dropdown only lists engines installed on this server.
  • Where it will be connected to from — the panel opens firewall ports to match, and the safe default is "nowhere but here".

Steps

Open Databases and click Create database. The form opens as a dialog over the list.

The Create a database dialog with fields for database name, engine, used by, a generated username, and three options for where it can connect from

Name the database. This is the real name on the engine, so the engine's rules apply: letters, digits and underscores, no spaces. demo_shop, analytics, acme_crm. The panel suggests the shape with its my_app placeholder.

Pick the engine. Every engine installed on the server is listed. With one SQL engine and MongoDB installed, that is two choices; on a server with only the SQL engine, the dropdown has one entry and nothing to decide.

Choose what uses it, under Used by. Linking the database to an application is what puts it in that application's backups — the list screen warns about databases that are not linked, and this is the field it means. Leave it on Not linked to an application only for databases you will back up some other way.

Leave Also create a user on, unless the database should have no login of its own. The panel fills in a random username like db_mhu7amwjak; replace it with something you will recognise in a connection string six months from now.

The password is not a field. The panel generates a strong one and shows it once, at the end.

The create form filled in with the name demo_shop and the username demo_shop_app

Choose where it can connect from. This writes a firewall rule as well as a grant, so it is the one setting here with a security consequence.

OptionWhat it doesWhen
This server onlyThe user may connect from 127.0.0.1. The database port stays shut to the outside.The default, and right for an application running on this same server.
From one addressOpens the database port in the firewall for the single address you enter.A separate application server, or your office IP for a migration.
From anywhereOpens the database port to the whole internet.Almost never. Anyone who guesses the password can connect.

From anywhere means from anywhere

There is no second gate behind this option — no IP allow-list, no VPN requirement. If you need remote access for one job, use From one address, and narrow it again when the job is done.

Open Advanced only if you need a specific character set. It holds Character set and Collation, both set to Server default. Collation stays disabled until you pick a character set — the hint under it says Choose a character set first.

The create dialog with Advanced expanded, showing Character set and a disabled Collation field

Server default is almost always right. On MySQL and MariaDB that means utf8mb4, which is what current application installers expect. Override it only when you are matching an existing database you are about to import.

Click Create database. It takes a moment, then the panel confirms with everything the application needs.

The demo_shop is ready dialog showing a connection string with the password masked, plus host, port, database, username and password fields

The connection string is the whole thing on one line, which is what most frameworks want in a DATABASE_URL. Below it, the same details broken out as Host, Port, Database, Username and Password, each with its own copy button.

Copy the password now

This dialog is the only place the password is shown in full. The database's own page shows it masked afterwards. If you lose it, the fix is to delete the user and add a new one — not to recover the old password.

A note on the escaped password

The panel points out, under the fields, that "the password is escaped inside the connection string, so it looks different there. Both are correct."

Generated passwords contain characters that are not legal unescaped inside a URL — = becomes %3D, and so on. The Password field shows the real password, which is what a form or a config field with a separate password setting wants. The connection string shows the URL-encoded one, which is what belongs in a mysql:// or postgresql:// URL. Do not "fix" either of them.

What happens next

Done closes the dialog and returns to the list, where the new database is now a row. Open database goes straight to its own page — connection details, users, tables and exports. See Manage a database.

On this page