Modifies the ECS security groups associated with an ApsaraDB for RDS instance.

After an ECS security group is added to a whitelist of an RDS instance, all of the ECS instances in the ECS security group are granted access to the RDS instance. For more information, see Configure a whitelist for an RDS MySQL instance.


OpenAPI Explorer automatically calculates the signature value. For your convenience, we recommend that you call this operation in OpenAPI Explorer. OpenAPI Explorer dynamically generates the sample code of the operation for different SDKs.

Request parameters

Parameter Type Required Example Description
Action String Yes ModifySecurityGroupConfiguration

The operation that you want to perform. Set the value to ModifySecurityGroupConfiguration.

DBInstanceId String Yes rm-uf6wjk5xxxxxx

The ID of the RDS instance.

SecurityGroupId String Yes sg-xxxxxxx

The ID of the ECS security groups. Each RDS instance can be associated with up to three ECS security groups. You must separate them with commas (,). To delete an ECS Security group, leave this parameter empty. You can call the DescribeSecurityGroups operation to query the available ECS security group list.

Response parameters

Parameter Type Example Description
RequestId String 8585861B-8F0D-4D17-9460-C42255EB10C0

The ID of the request.

DBInstanceName String rm-uf6wjk5xxxxxx

The ID of the RDS instance.

Items Array

An array that consists of ECS security groups.

RegionId String cn-hangzhou

The ID of the region to which the ECS security group belongs.

SecurityGroupId String sg-xxxxxxx

The ID of the ECS security group.

NetworkType String VPC

The network type of the ECS security group. Valid values:

  • Classic
  • VPC


Sample requests

&<Common request parameters>

Sample success responses

XML format


JSON format


Error codes

For a list of error codes, visit the API Error Center.