mysql_secure_installation makes four fixes: a root password, no remote root, no anonymous accounts, no test database. First it offers the validate_password component, which checks every later password. The mysql:9.7 image lacks the tool, but it is an ordinary client, so the Ubuntu 225 host's copy secures the container of Running MySQL in Docker (answers follow each prompt):
mysql_secure_installation -h 127.0.0.1 -P 3301 -u rootEnter password for user root: ... Please enter 0 = LOW, 1 = MEDIUM and 2 = STRONG: 2 ... Estimated strength of the password: 25 Change the password for root ? ((Press y|Y for Yes, any other key for No) : n ... Disallow root login remotely? (Press y|Y for Yes, any other key for No) : y Success. ... All done!
STRONG demands eight characters, digits, mixed case, a symbol and, if configured, a dictionary check; 25 out of 100 is its verdict on root's secret. The changes apply at once:
mysql -h 127.0.0.1 -P 3301 -uroot -psecret -e "SELECT 1"
docker exec mysql97 mysql -uroot -psecret \
-e "CREATE USER 'report'@'localhost' IDENTIFIED BY 'bookshop2026'"mysql: [Warning] Using a password on the command line interface can be insecure. ERROR 1130 (HY000): Host '172.17.0.1' is not allowed to connect to this MySQL server mysql: [Warning] Using a password on the command line interface can be insecure. ERROR 1819 (HY000) at line 1: Your password does not satisfy the current policy requirements
The host arrives from the Docker 514 bridge address, which only the deleted root@'%' matched; docker exec still works through the container's socket. VALIDATE_PASSWORD_STRENGTH() scores a candidate first: bookshop2026 got 50 here, Bk-Shop#2026 100. On Ubuntu, root's auth_socket leaves no password to guess, but the other fixes still apply (CREATE and ALTER USER).