Restricting SSH to "known-good" IP addresses is less flexible and less secure than public key authentication.
(Restricting mysql access to localhost and using an SSH tunnel is fine practice, AFAIK.)
(Restricting mysql access to localhost and using an SSH tunnel is fine practice, AFAIK.)