Changes the ECS security groups to which an ApsaraDB for RDS instance is added.

After an RDS instance is added to an ECS security group, all ECS instances in the security group can access the RDS instance. For more information, see Configure a whitelist for an RDS instance.


OpenAPI Explorer automatically calculates the signature value. For your convenience, we recommend that you call this operation in OpenAPI Explorer. OpenAPI Explorer dynamically generates the sample code of the operation for different SDKs.

Request parameters

Parameter Type Required Example Description
Action String Yes ModifySecurityGroupConfiguration

The operation that you want to perform. Set the value to ModifySecurityGroupConfiguration.

DBInstanceId String Yes rm-uf6wjk5xxxxxx

The ID of the instance.

SecurityGroupId String Yes sg-xxxxxxx

The ID of the ECS security group. Each RDS instance can be added to up to three security groups. Separate the security group IDs with commas (,). To delete an ECS security group for the RDS instance, leave this parameter empty. You can call the DescribeSecurityGroups operation to query the ECS security group list.

Response parameters

Parameter Type Example Description
DBInstanceName String rm-uf6wjk5xxxxxx

The ID of the instance.

Items Array of EcsSecurityGroupRelation

An array that consists of ECS security groups.

NetworkType String VPC

The network type of an ECS security group. Valid values:

  • Classic
  • VPC
RegionId String cn-hangzhou

The ID of the region.

SecurityGroupId String sg-xxxxxxx

The ID of the ECS security group.

RequestId String 8585861B-8F0D-4D17-9460-C42255EB10C0

The ID of the request.


Sample requests

&<Common request parameters>

Sample success responses

XML format


JSON format


Error codes

For a list of error codes, visit the API Error Center.