// Engineering Log

Databases: Part 7 — Proxies for MySQL: ProxySQL, MySQL Router and MaxScale

Published on 2026-09-22

// Fast route

This article belongs to the topic Servers and infrastructure.

A proxy for MySQL is a program between an application and database servers. The application connects to the proxy like a regular MySQL server, and the proxy decides which server to send a query to: writes — to the primary, reads — to replicas, and if the primary fails — to a new primary. For the application, the database topology can change while the connection address stays the same.

Why you need it

  • Read/write split. When a database has replicas, the proxy sends SELECT to them and changes to the primary server. The application does not need to be rewritten to handle multiple addresses.
  • Connection pooling and multiplexing. Hundreds of client connections are served by a smaller number of real server connections.
  • High availability. The proxy checks servers and stops sending queries to an unavailable one.
  • Rules and protection. You can restrict or rewrite dangerous queries, redirect heavy reporting to a separate replica, or cache frequent responses.

A proxy does not replace replication and backups: it only distributes queries between already configured servers. How replication in MySQL works — in the second part of the series.

MySQL Proxy — historical name

The MySQL Proxy project has not been actively developed for a long time: its GitHub repository has been archived, with the last changes dated July 2015. It is still sometimes searched for under that name, but for new installations people use the tools below.

ProxySQL

ProxySQL is the most widely used proxy for MySQL and MariaDB, licensed under GPLv3; the current branch is 3.0 (release 3.0.11 was published in August 2026).

Key concepts:

  • hostgroup — a group of servers with the same role: e.g., 1 — primary server for writes, 2 — replicas for reads;
  • query rules (mysql_query_rules) — regular expressions on the query text that send it to the appropriate group;
  • admin interface — configuration is stored in tables and changed via SQL commands; changes are applied with LOAD … TO RUNTIME and saved with SAVE … TO DISK.

Example of read/write split from the ProxySQL documentation. Commands are executed in the admin interface:

sql
-- servers: 1 — write, 2 — read
INSERT INTO mysql_servers (hostgroup_id, hostname, port) VALUES (1, '10.0.0.10', 3306);
INSERT INTO mysql_servers (hostgroup_id, hostname, port) VALUES (2, '10.0.0.11', 3306);
INSERT INTO mysql_servers (hostgroup_id, hostname, port) VALUES (2, '10.0.0.12', 3306);
LOAD MYSQL SERVERS TO RUNTIME;
SAVE MYSQL SERVERS TO DISK;

-- by default the user writes to group 1
UPDATE mysql_users SET default_hostgroup = 1;
LOAD MYSQL USERS TO RUNTIME;

-- SELECT ... FOR UPDATE — to the primary server, other SELECT — to replicas
INSERT INTO mysql_query_rules (rule_id, active, match_digest, destination_hostgroup, apply)
VALUES (1, 1, '^SELECT.*FOR UPDATE', 1, 1),
       (2, 1, '^SELECT', 2, 1);
LOAD MYSQL QUERY RULES TO RUNTIME;
SAVE MYSQL QUERY RULES TO DISK;

The SELECT ... FOR UPDATE rule is placed first: such queries lock rows and must be executed where writes occur. ProxySQL developers recommend not starting by sending all SELECT to replicas; first use statistics (stats_mysql_query_digest) to find the heaviest queries and move only them to replicas.

The main risk of read/write splitting is replica lag: immediately after a write a replica may not yet contain the new data, and a user won’t see what was just saved. Queries that read just-written data should be left on the primary server.

MySQL Router

MySQL Router is a lightweight router from Oracle, part of the MySQL InnoDB Cluster and InnoDB ClusterSet ecosystem. It obtains cluster membership information from metadata and automatically switches the application to a new primary after a failure. It does not have query rules like ProxySQL: read and write are usually separated by different ports, and the application chooses where to connect. Router is appropriate when the cluster is already built with Oracle tools (MySQL Shell, Group Replication).

MaxScale

MaxScale is MariaDB’s proxy with read/write split, query filters, and automatic failover. An important detail is the license: it is not open source but uses the Business Source License 1.1. For version 24.08 free use is allowed if there are fewer than three database servers in production in total; after the specified period (for 24.08 — 09.09.2027) the code will switch to GPL. For larger installations a commercial subscription from MariaDB is required.

What to choose

SituationChoice
A primary server and replicas MySQL or MariaDB, need a pool and flexible rulesProxySQL
MySQL InnoDB Cluster from OracleMySQL Router
Infrastructure on MariaDB with a subscriptionMaxScale
One server without replicasproxy not needed: just configure a connection pool in the application

The proxy itself becomes a single point of failure, so in production it is deployed in at least two instances — for example, next to each application server or as a pair behind a shared address.

Common mistakes

  • All SELECT to replicas without accounting for lag. The user saves data and doesn’t see it after refreshing the page.
  • Single proxy instance. Proxy failure stops the application just like a database failure.
  • Admin interface exposed externally. Close its port with a firewall and change default credentials.
  • Changes only in runtime. Without SAVE … TO DISK settings will be lost after a restart.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Servers and infrastructure

VPS, Linux, web stack, migrations, hosting, databases, and core operations.

Typical tasks behind this topic

  • Move a site or service to a new server
  • Set up Linux, Nginx, databases, and backups
  • Figure out why the system behaves unstably

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply