cPFence v4 public beta is here.

Explore v4
Enhance CP Tutorials

How to Change MySQL Root Password on an Enhance Server

Mysql Root conceptual feature illustration

Changing the MySQL root password on an older Enhance server used Docker. The original recovery steps are retained below, but current Enhance handles database root access differently.

Current Enhance: On Enhance v12 and later, log in as the operating-system root user on the server with the database role, then run mysql. Enhance uses local socket authentication. Enhance explicitly advises against setting a database root password, because it interferes with panel management. This applies to current Enhance installations on Ubuntu 22.04/24.04; cPFence v4+ does not require changing that authentication.

Original Docker Recovery Steps — Older Installations Only

Use the following only for an older Docker-based MariaDB installation whose recovery procedure you have confirmed with Enhance support. It is not a MySQL-container recipe. You need administrator SSH access, a verified database backup and a maintenance window: stopping MariaDB interrupts every site using that database server.

Confirm the original container name, image and all data/configuration mounts first. The examples use mariadb; container names are case-sensitive. Never run two database processes against the same data directory.

1- Stop the MariaDB Container

docker stop mariadb

2- Start a Temporary MariaDB Container Use the same data directories to create a temporary MariaDB container. If you need to locate these directories, run:

docker inspect --format '{{json .Mounts}}' mariadb

Use docker inspect --format '{{.Image}}' mariadb to identify the exact local image of the original container. Replace SAME_MARIADB_IMAGE below with that image ID, and replace the sample mount paths with your actual mappings. A floating mariadb:lts tag could select a different database version.

Then, start the temporary container with: Keep networking disabled while grant checks are bypassed. Confirm the original container has stopped before proceeding.

docker run -d --name mariadb_temp --network none \
-v /var/local/enhance/mysql/ssl:/etc/mysql/ssl \
-v /etc/ssl/certs:/etc/ssl/certs \
-v /var/local/enhance/mysqlcd-data/data:/var/lib/mysql \
-v /var/local/enhance/mysqlcd-run:/var/run/mysqld \
-v /var/local/enhance/mysql/conf.d:/etc/mysql/conf.d \
--entrypoint "mysqld_safe" SAME_MARIADB_IMAGE --skip-grant-tables --skip-networking

3- Access the MySQL Shell Now, enter the MySQL shell to reset the root password:

docker exec -it mariadb_temp mysql -u root

4- Reset the Password In the MySQL shell, execute the following commands. Replace new_password with a unique password, keep it private, and confirm how this older installation stores the panel’s database credentials before changing it. Do not apply this password reset to current socket-authenticated Enhance servers.

FLUSH PRIVILEGES;
ALTER USER 'root'@'localhost' IDENTIFIED BY 'new_password';
EXIT;

5- Stop and Remove the Temporary Container After changing the password, stop and remove the temporary container:

docker stop mariadb_temp
docker rm mariadb_temp

6- Restart the Original MariaDB Container Finally, restart your original MariaDB container:

docker start mariadb

7- Verify the New Password Test your new root password with:

docker exec -it mariadb mysql -u root -p

After reconnecting, check affected websites and Enhance database management before ending maintenance. If a step fails, stop and inspect the error; do not retry with another database image or delete the data directory. Stop and remove any temporary container before restarting the original. If the password has already changed, keep the new credential and coordinate recovery of the older panel configuration with Enhance support.

Try cPFence Free for One Month

Bring server protection and monitoring together with cPFence v4+ for Enhance on Ubuntu 22.04/24.04.

Start free trial
← Back to all articles
KEEP EXPLORING
All articles