MySQL

View as Markdown
  • PATCH
  • /workspaces
  • /:workspace
  • /targets
  • /:target_id

Update MySQL target configuration

Request

REQUIRED SCOPES
TARGET_WRITE
URL PARAMETERS
workspacerequiredstring
The human-readable ID of the workspace

Example: "my-company"

target_idrequiredstring
Target unique identifier (hash ID)

Example: "tgt-1234567890abcdef"

BODY PARAMETERS
typestring
The type of the target

Value: MYSQL

idstring
The ID of the target
identifierrequiredstring
A human-readable ID. Alphanumeric characters, underscores, and hyphens (hyphens cannot appear at the start or end).
namestring
The name of the target
projectShortProjectView
Short representation of a project
pipelineShortPipelineView
Short representation of a pipeline
environmentShortEnvironmentView
permissionsPermissionsView
Access permissions configuration
pipelines_access_levelstring enum
Pipelines access level for this target
Allowed enum:
DENIED,
READ_ONLY,
USE_ONLY,
BLIND,
RUN_ONLY,
READ_WRITE,
MANAGE,
DEFAULT,
ALLOWED,
STAGE,
COMMIT
allowed_pipelinesAllowedPipelineView[]
List of specific pipelines allowed to use this target
sandboxes_access_levelstring enum
Sandboxes access level for this target
Allowed enum:
DENIED,
READ_ONLY,
USE_ONLY,
BLIND,
RUN_ONLY,
READ_WRITE,
MANAGE,
DEFAULT,
ALLOWED,
STAGE,
COMMIT
allowed_sandboxesAllowedSandboxView[]
List of specific sandboxes allowed to use this target
disabledboolean
Indicates if this target is disabled (default: false)
tagsstring[]
The list of tags associated with the target

Constraints: Unique items required

use_asUseAsView
Defines how the target can be used (as deployment target, proxy, or both)
notestring
Note for this resource
agent_notestring
YAML note for AI agents operating on this resource
hostrequiredstring
The hostname or IP address of the MySQL server
portstring
The port of the MySQL server. Default: 3306
databasestring
The default database name
ssl_modestring enum
SSL connection mode. Default: REQUIRE (encrypted, server certificate not validated), applied on the tunneled hop too when a proxy is set. REQUIRE is advisory on Target Exec: the MariaDB client used there has no --ssl-mode, and encryption silently falls back to plaintext when the server offers no TLS - use VERIFY_FULL to make it mandatory. VERIFY_FULL with a proxy requires the server certificate to cover the tunnel endpoint (127.0.0.1) in its SAN, otherwise hostname validation fails.
Allowed enum:
DISABLE,
REQUIRE,
VERIFY_FULL
ca_certificatestring
PEM-encoded CA certificate (required when sslMode is VERIFY_FULL)
authrequiredMysqlAuthView
MySQL authentication credentials
proxyTargetK8sProxyView
SSH proxy target for tunneling to private ClickHouse servers

Response

RESPONSE BODY
typestring
The type of the target

Value: MYSQL

urlread-onlystring
API endpoint to GET this object
html_urlread-onlystring
Web URL to view this object in Buddy.works
idstring
The ID of the target
identifierrequiredstring
A human-readable ID. Alphanumeric characters, underscores, and hyphens (hyphens cannot appear at the start or end).
namestring
The name of the target
projectShortProjectView
Short representation of a project
pipelineShortPipelineView
Short representation of a pipeline
environmentShortEnvironmentView
permissionsPermissionsView
Access permissions configuration
pipelines_access_levelstring enum
Pipelines access level for this target
Allowed enum:
DENIED,
READ_ONLY,
USE_ONLY,
BLIND,
RUN_ONLY,
READ_WRITE,
MANAGE,
DEFAULT,
ALLOWED,
STAGE,
COMMIT
allowed_pipelinesAllowedPipelineView[]
List of specific pipelines allowed to use this target
sandboxes_access_levelstring enum
Sandboxes access level for this target
Allowed enum:
DENIED,
READ_ONLY,
USE_ONLY,
BLIND,
RUN_ONLY,
READ_WRITE,
MANAGE,
DEFAULT,
ALLOWED,
STAGE,
COMMIT
allowed_sandboxesAllowedSandboxView[]
List of specific sandboxes allowed to use this target
disabledboolean
Indicates if this target is disabled (default: false)
tagsstring[]
The list of tags associated with the target

Constraints: Unique items required

use_asUseAsView
Defines how the target can be used (as deployment target, proxy, or both)
notestring
Note for this resource
agent_notestring
YAML note for AI agents operating on this resource
hostrequiredstring
The hostname or IP address of the MySQL server
portstring
The port of the MySQL server. Default: 3306
databasestring
The default database name
ssl_modestring enum
SSL connection mode. Default: REQUIRE (encrypted, server certificate not validated), applied on the tunneled hop too when a proxy is set. REQUIRE is advisory on Target Exec: the MariaDB client used there has no --ssl-mode, and encryption silently falls back to plaintext when the server offers no TLS - use VERIFY_FULL to make it mandatory. VERIFY_FULL with a proxy requires the server certificate to cover the tunnel endpoint (127.0.0.1) in its SAN, otherwise hostname validation fails.
Allowed enum:
DISABLE,
REQUIRE,
VERIFY_FULL
ca_certificatestring
PEM-encoded CA certificate (required when sslMode is VERIFY_FULL)
authrequiredMysqlAuthView
MySQL authentication credentials
proxyTargetK8sProxyView
SSH proxy target for tunneling to private ClickHouse servers

Last modified on Oct 6, 2026

Request example

curl -X PATCH "https://api.buddy.works/workspaces/:workspace/targets/:target_id" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "Content-Type: application/json" \ -d '{ "type": "MYSQL", "identifier": "production-db", "name": "Production MySQL", "host": "db.example.com", "port": 3306, "database": "myapp", "auth": { "method": "PASSWORD", "username": "deploy_user", "password": "secured" }, "tags": [ "mysql", "production" ] }'
STATUS
200 OK