This topic provides solutions for common issues that you may encounter when using Data Disaster Recovery.
How do I configure RAM authorization to back up or restore data across Alibaba Cloud accounts?
Log on to the Resource Access Management (RAM) console using the Alibaba Cloud account that owns the source database instance.
NoteEnsure that the AliyunDBSDefaultRole permission is granted to the Alibaba Cloud account that owns the source database instance.
In the navigation pane on the left, choose Identity Management > Roles.
Create a role:
Click Create Role. For Trusted Entity Type, select Alibaba Cloud Account.
For Trusted Entity Name, select
Current Cloud Account 164882xxxxand click OK.In the dialog box that appears, enter a role name, such as
ram-for-dbs, and click OK.
Grant permissions to the role:
On the role details page, click the Permission Management tab, and then click Add Permissions.
In the panel that appears, for Permission Type, select System Policy.

You can select the required policies based on the Database Location.
RDS Instance:
AliyunRDSReadOnlyAccessandAliyunVPCReadOnlyAccessConnecting to a self-managed database over an Express Connect circuit, a VPN Gateway, or a Smart Access Gateway:
AliyunVPCReadOnlyAccessPolarDB:
AliyunPolardbFullAccess
Click Confirm.
Edit the trust policy:
In the basic information section of the role, choose Trust Policy > Edit Trust Policy.
On the Edit Trust Policy page, click Script Editor and enter the following code in the text box:
Replace
<Account ID>with the ID of the Alibaba Cloud account that you use to manage the backup schedule.{ "Statement": [ { "Action": "sts:AssumeRole", "Effect": "Allow", "Principal": { "RAM": [ "acs:ram::<Account ID>:root" ], "Service": [ "<Account ID>@dbs.aliyuncs.com" ] } } ], "Version": "1" }
Click OK to complete the RAM authorization.
How do I back up and restore data across Alibaba Cloud accounts?
Configure cross-account backup
In the Database Location section, select a destination instance that supports the cross-account feature. Then, click Cross-Alibaba Cloud Account Instance.

Enter the required information in the Cross-Alibaba Cloud Account ID and Role Name text boxes.
Cross-Alibaba Cloud Account ID: The ID of the Alibaba Cloud account that owns the source database.
Role Name: The name of the role that has the required trust policy. For example,
ram-for-dbs.

Configure cross-account restoration
For more information about how to configure cross-account backup and restoration, see Configure a backup schedule and restore data.
You cannot migrate backup sets across Alibaba Cloud accounts in the console.
How do I back up a database across accounts using a public endpoint?
Set Database Location to User-Created Database with Public IP Address <IP Address:Port Number>.
If the User-Created Database with Public IP Address <IP Address:Port Number> option is unavailable, you can search for the DingTalk group ID 35585947 or submit a ticket to request the feature.
How do I automatically archive backup sets to a backup server?
Create a backup schedule. This operation is performed using an operations account.
Manage a backup schedule. This operation is performed using an operations account.
Install a backup gateway on the backup server. This operation is performed using a backup account.
NoteIf you do not have a backup server, you can purchase a server first.
In the backup schedule list, find the backup schedule you want to manage and click Manage in the Actions column. On the Configure Backup Task page, go to the Backup Set Download section at the bottom of the page and click Set Backup Set Download Rule. In the dialog box that opens, configure the parameters as described in the following table. This operation requires an operations account.
NoteIf the database engine of the backup instance does not support backup set downloads, or the destination storage class is not DBS Storage, this button is not displayed in the console.
Parameter
Description
Auto-download Status
Select Enable.
Destination Type
The default value is the directory of the server on which the backup gateway is installed. This parameter is fixed.
Backup Gateway
Select a backup gateway. DBS uses the backup gateway to connect to the on-premises device.
ImportantThe automatic backup set download feature is not yet commercially available and may have performance bottlenecks. Therefore, do not configure the same backup gateway to download backup data from multiple backup schedules. This prevents data stacking and other exceptions.
Destination Location
Select the type of the destination location and set the corresponding directory or path. The backup data is stored in the specified path. The following four types of locations are supported:
Server directory
FTP path
NAS directory
Minio path
Full Data Format
This parameter uses the default value and cannot be modified.
NoteFor more information about the data formats of full and incremental backup sets, see the preceding feature limits and format description.
Incremental Data Format
This parameter uses the native format by default and cannot be modified.
Click OK to save the settings.
On the Configure Backup Task page, click Backup Set Download in the navigation pane on the left to view the download progress. This operation requires an operations account.
How do I modify the backup lifecycle?
Log on to the Data Management (DMS) 5.0 console.
In the top navigation bar, choose Security and Specifications (DBS) > Data Disaster Recovery (DBS) > Backup Plan.
NoteIf you use the DMS console in simple mode, move the pointer over the
icon in the upper-left corner of the DMS console and choose All Features > Security and Specifications (DBS) > Data Disaster Recovery (DBS) > Backup Plan. In the Actions column of the backup schedule, click Manage to open the Configure Backup Task page.
In the Lifecycle Information section, click Set Lifecycle.
Set the Retention Period for full or incremental backups, and then click Save.
ImportantThe minimum retention period is 7 days and the maximum retention period is 3,650 days. After the retention period expires, the backup set is automatically deleted and cannot be recovered.
If you do not enable incremental backup, only the configuration item for the full backup lifecycle is displayed in the console. For more information about how to enable incremental backup, see Enable or disable incremental log backup.
How do I set the minimum retention policy for backup sets?
You can set the lifecycle of backup sets when you configure a backup schedule or modify the lifecycle as needed. You can use the following methods:
When you configure a backup schedule, no DBS storage fees are generated for backup data stored in User OSS. DBS storage fees are generated for backup data stored in DBS Storage. The storage fees are calculated based on the actual storage data size and retention period. For more information, see Differences between DBS Storage and user-owned OSS buckets and Storage billing.
NoteIf you have a large amount of data, we recommend that you purchase a DBS storage plan for backup instances to offset the storage fees generated by the backup schedule. For more information, see Use a storage plan.
If necessary, you can also manually delete backup sets to reduce storage fees.
How do I perform disaster recovery and ensure security for a self-managed database on an ECS instance?
Create a backup schedule and set Backup Method to Logical Backup.
In Manage a backup schedule, select Self-managed Database On ECS for Database Location.
How do I perform geo-redundant backup for an ApsaraDB RDS for MySQL instance?
Ensure that a public endpoint is enabled for the source ApsaraDB RDS for MySQL instance.
Create a backup schedule. For geo-redundant backups, you must purchase a backup schedule in a region different from the data source region. For Backup Method, select Logical Backup.
How do I perform geo-redundant backup for a self-managed database?
Create a backup schedule and set Backup Method to Logical Backup.
In the Manage a backup schedule task, select User-Created Database with Public IP Address <IP Address:Port Number> for Database Location.
If the User-Created Database with Public IP Address <IP Address:Port Number> option is unavailable, you can search for the DingTalk group ID 35585947 or submit a ticket to request access to the feature.
How do I use Database Gateway (DG) to back up an on-premises or third-party cloud private database to cloud storage?
Create a backup schedule and select Logical Backup as the Backup Method.
When you manage a backup schedule, select Self-managed Database Without A Public IP Address And Port (connected Over DG) for Database Location.
How do I back up an on-premises self-managed database that is accessed over an Express Connect circuit to cloud storage?
Create a backup schedule and select Logical Backup as the Backup Method.
Connect the on-premises Internet Data Center (IDC) to Alibaba Cloud using an Express Connect circuit. This allows the virtual private cloud (VPC) on the cloud and the on-premises IDC to communicate with each other. For more information, see Connect an on-premises IDC to a VPC on the cloud using an Express Connect circuit.
On the access device on the customer side of the on-premises IDC, add a static route that points to the DBS IP address range. Command:
ip route DBS address range{Alibaba Cloud-side interconnection IP}. For more information about the DBS IP address ranges, see DBS IP address ranges.For more information, see Manage a backup schedule. For Database Location, select Self-managed Database Connected Over An Express Connect Circuit, A VPN Gateway, Or A Smart Access Gateway.
How do I back up a self-managed Redis database to the cloud?
Create a backup schedule and select Logical Backup as the Backup Method.
NoteWhen you purchase a backup schedule, select Redis as the Data Source Type and Logical Backup as the Backup Method.
For more information about the specific granularity that Data Disaster Recovery supports when it backs up and restores Redis databases, see Supported database engines and features.
Configure a backup schedule and set Database Location to Self-managed Database On ECS.
How do I perform cloud disaster recovery for a self-managed MySQL database?
Prerequisites
A logical backup must be completed.
Only logical backup schedules are supported. Physical backups do not support database-level and table-level restoration.
The logical backup of a PolarDB distributed edition supports only the backup of the entire instance. Therefore, database-level and table-level restoration are not supported.
Backup and restoration
For more information, see Cross-cloud or self-managed MySQL logical backup and restoration.
DBS IP address ranges
Region | DBS IP address range |
China (Hangzhou) | 100.104.217.0/24 |
China (Beijing) | 100.104.119.0/24 |
China (Qingdao) | 100.104.183.0/24 |
China (Shanghai) | 100.104.191.0/24 |
China (Shenzhen) | 100.104.81.0/24 |
China (Chengdu) | 100.104.133.128/26 |
China (Ulanqab) | 100.104.76.192/26 |
China (Heyuan) | 100.104.127.0/26 |
South Korea (Seoul) | 100.104.150.192/26 |
Thailand (Bangkok) | 100.104.119.128/26 |
China (Hong Kong) | 100.104.10.0/24 |
Singapore | 100.104.10.0/24 |
Japan (Tokyo) | 100.104.144.0/24 |
China (Hohhot) | 100.104.40.0/24 |
China (Zhangjiakou) | 100.104.48.0/24 |
US (Virginia) | 100.104.220.0/24 |
US (Silicon Valley) | 100.104.17.0/24 |
Germany (Frankfurt) | 100.104.133.0/24 |
Malaysia (Kuala Lumpur) | 100.104.10.0/24 |
Indonesia (Jakarta) | 100.104.209.0/24 |
Finance Cloud server CIDR blocks
Finance Cloud region | Finance Cloud server CIDR block |
China (Hangzhou) | 100.104.255.64/26 |
China (Shenzhen) | 100.104.194.128/26 |
China (Shanghai) | 100.104.45.64/26 |