All Products
Search
Document Center

Data Management:Practice guide for Data Disaster Recovery (DBS)

Last Updated:Jul 30, 2025

This topic provides solutions for common issues that you may encounter when using Data Disaster Recovery.

How do I configure RAM authorization to back up or restore data across Alibaba Cloud accounts?

  1. Log on to the Resource Access Management (RAM) console using the Alibaba Cloud account that owns the source database instance.

    Note

    Ensure that the AliyunDBSDefaultRole permission is granted to the Alibaba Cloud account that owns the source database instance.

  2. In the navigation pane on the left, choose Identity Management > Roles.

  3. Create a role:

    1. Click Create Role. For Trusted Entity Type, select Alibaba Cloud Account.

    2. For Trusted Entity Name, select Current Cloud Account 164882xxxx and click OK.

    3. In the dialog box that appears, enter a role name, such as ram-for-dbs, and click OK.

  4. Grant permissions to the role:

    1. On the role details page, click the Permission Management tab, and then click Add Permissions.

    2. In the panel that appears, for Permission Type, select System Policy.

      image

    3. You can select the required policies based on the Database Location.

      • RDS Instance: AliyunRDSReadOnlyAccess and AliyunVPCReadOnlyAccess

      • Connecting to a self-managed database over an Express Connect circuit, a VPN Gateway, or a Smart Access Gateway: AliyunVPCReadOnlyAccess

      • PolarDB: AliyunPolardbFullAccess

    4. Click Confirm.

  5. Edit the trust policy:

    1. In the basic information section of the role, choose Trust Policy > Edit Trust Policy.

    2. On the Edit Trust Policy page, click Script Editor and enter the following code in the text box:

      Replace <Account ID> with the ID of the Alibaba Cloud account that you use to manage the backup schedule.

      {
       "Statement": [
           {
               "Action": "sts:AssumeRole",
               "Effect": "Allow",
               "Principal": {
                   "RAM": [
                       "acs:ram::<Account ID>:root"
                   ],
                   "Service": [
                       "<Account ID>@dbs.aliyuncs.com"
                   ]
               }
           }
       ],
       "Version": "1"
      }
  6. Click OK to complete the RAM authorization.

How do I back up and restore data across Alibaba Cloud accounts?

Configure cross-account backup

  1. Create a backup schedule.

  2. Configure a backup schedule.

    1. In the Database Location section, select a destination instance that supports the cross-account feature. Then, click Cross-Alibaba Cloud Account Instance.

      image

    2. Enter the required information in the Cross-Alibaba Cloud Account ID and Role Name text boxes.

      • Cross-Alibaba Cloud Account ID: The ID of the Alibaba Cloud account that owns the source database.

      • Role Name: The name of the role that has the required trust policy. For example, ram-for-dbs.

      image

Configure cross-account restoration

For more information about how to configure cross-account backup and restoration, see Configure a backup schedule and restore data.

Note

You cannot migrate backup sets across Alibaba Cloud accounts in the console.

How do I back up a database across accounts using a public endpoint?

  1. Create a backup schedule.

  2. Configure a backup schedule.

  3. Set Database Location to User-Created Database with Public IP Address <IP Address:Port Number>.

Note

If the User-Created Database with Public IP Address <IP Address:Port Number> option is unavailable, you can search for the DingTalk group ID 35585947 or submit a ticket to request the feature.

How do I automatically archive backup sets to a backup server?

  1. Create a backup schedule. This operation is performed using an operations account.

  2. Manage a backup schedule. This operation is performed using an operations account.

  3. Install a backup gateway on the backup server. This operation is performed using a backup account.

    Note

    If you do not have a backup server, you can purchase a server first.

  4. In the backup schedule list, find the backup schedule you want to manage and click Manage in the Actions column. On the Configure Backup Task page, go to the Backup Set Download section at the bottom of the page and click Set Backup Set Download Rule. In the dialog box that opens, configure the parameters as described in the following table. This operation requires an operations account.

    Note

    If the database engine of the backup instance does not support backup set downloads, or the destination storage class is not DBS Storage, this button is not displayed in the console.

    Parameter

    Description

    Auto-download Status

    Select Enable.

    Destination Type

    The default value is the directory of the server on which the backup gateway is installed. This parameter is fixed.

    Backup Gateway

    Select a backup gateway. DBS uses the backup gateway to connect to the on-premises device.

    Important

    The automatic backup set download feature is not yet commercially available and may have performance bottlenecks. Therefore, do not configure the same backup gateway to download backup data from multiple backup schedules. This prevents data stacking and other exceptions.

    Destination Location

    Select the type of the destination location and set the corresponding directory or path. The backup data is stored in the specified path. The following four types of locations are supported:

    • Server directory

    • FTP path

    • NAS directory

    • Minio path

    Full Data Format

    This parameter uses the default value and cannot be modified.

    Note

    For more information about the data formats of full and incremental backup sets, see the preceding feature limits and format description.

    Incremental Data Format

    This parameter uses the native format by default and cannot be modified.

  5. Click OK to save the settings.

  6. On the Configure Backup Task page, click Backup Set Download in the navigation pane on the left to view the download progress. This operation requires an operations account.

How do I modify the backup lifecycle?

  1. Log on to the Data Management (DMS) 5.0 console.

  2. In the top navigation bar, choose Security and Specifications (DBS) > Data Disaster Recovery (DBS) > Backup Plan.

    Note

    If you use the DMS console in simple mode, move the pointer over the 2023-01-28_15-57-17.png icon in the upper-left corner of the DMS console and choose All Features > Security and Specifications (DBS) > Data Disaster Recovery (DBS) > Backup Plan.

  3. In the Actions column of the backup schedule, click Manage to open the Configure Backup Task page.

  4. In the Lifecycle Information section, click Set Lifecycle.

  5. Set the Retention Period for full or incremental backups, and then click Save.

    fdfdf

    Important
    • The minimum retention period is 7 days and the maximum retention period is 3,650 days. After the retention period expires, the backup set is automatically deleted and cannot be recovered.

    • If you do not enable incremental backup, only the configuration item for the full backup lifecycle is displayed in the console. For more information about how to enable incremental backup, see Enable or disable incremental log backup.

How do I set the minimum retention policy for backup sets?

How do I perform disaster recovery and ensure security for a self-managed database on an ECS instance?

  1. Create a backup schedule and set Backup Method to Logical Backup.

  2. In Manage a backup schedule, select Self-managed Database On ECS for Database Location.

How do I perform geo-redundant backup for an ApsaraDB RDS for MySQL instance?

  1. Ensure that a public endpoint is enabled for the source ApsaraDB RDS for MySQL instance.

  2. Create a backup schedule. For geo-redundant backups, you must purchase a backup schedule in a region different from the data source region. For Backup Method, select Logical Backup.

  3. Manage a backup schedule.

How do I perform geo-redundant backup for a self-managed database?

  1. Create a backup schedule and set Backup Method to Logical Backup.

  2. In the Manage a backup schedule task, select User-Created Database with Public IP Address <IP Address:Port Number> for Database Location.

Note

If the User-Created Database with Public IP Address <IP Address:Port Number> option is unavailable, you can search for the DingTalk group ID 35585947 or submit a ticket to request access to the feature.

How do I use Database Gateway (DG) to back up an on-premises or third-party cloud private database to cloud storage?

  1. Install a backup gateway.

  2. Create a backup schedule and select Logical Backup as the Backup Method.

  3. When you manage a backup schedule, select Self-managed Database Without A Public IP Address And Port (connected Over DG) for Database Location.

How do I back up an on-premises self-managed database that is accessed over an Express Connect circuit to cloud storage?

  1. Create a backup schedule and select Logical Backup as the Backup Method.

  2. Connect the on-premises Internet Data Center (IDC) to Alibaba Cloud using an Express Connect circuit. This allows the virtual private cloud (VPC) on the cloud and the on-premises IDC to communicate with each other. For more information, see Connect an on-premises IDC to a VPC on the cloud using an Express Connect circuit.

  3. On the access device on the customer side of the on-premises IDC, add a static route that points to the DBS IP address range. Command: ip route DBS address range{Alibaba Cloud-side interconnection IP}. For more information about the DBS IP address ranges, see DBS IP address ranges.

  4. For more information, see Manage a backup schedule. For Database Location, select Self-managed Database Connected Over An Express Connect Circuit, A VPN Gateway, Or A Smart Access Gateway.

How do I back up a self-managed Redis database to the cloud?

  1. Create a backup schedule and select Logical Backup as the Backup Method.

    Note
    • When you purchase a backup schedule, select Redis as the Data Source Type and Logical Backup as the Backup Method.

    • For more information about the specific granularity that Data Disaster Recovery supports when it backs up and restores Redis databases, see Supported database engines and features.

  2. Configure a backup schedule and set Database Location to Self-managed Database On ECS.

  3. Restore data to an Alibaba Cloud Redis instance.

  4. Switch the backup to an Alibaba Cloud Redis instance.

How do I perform cloud disaster recovery for a self-managed MySQL database?

Prerequisites

A logical backup must be completed.

Note
  • Only logical backup schedules are supported. Physical backups do not support database-level and table-level restoration.

  • The logical backup of a PolarDB distributed edition supports only the backup of the entire instance. Therefore, database-level and table-level restoration are not supported.

Backup and restoration

For more information, see Cross-cloud or self-managed MySQL logical backup and restoration.

DBS IP address ranges

Region

DBS IP address range

China (Hangzhou)

100.104.217.0/24

China (Beijing)

100.104.119.0/24

China (Qingdao)

100.104.183.0/24

China (Shanghai)

100.104.191.0/24

China (Shenzhen)

100.104.81.0/24

China (Chengdu)

100.104.133.128/26

China (Ulanqab)

100.104.76.192/26

China (Heyuan)

100.104.127.0/26

South Korea (Seoul)

100.104.150.192/26

Thailand (Bangkok)

100.104.119.128/26

China (Hong Kong)

100.104.10.0/24

Singapore

100.104.10.0/24

Japan (Tokyo)

100.104.144.0/24

China (Hohhot)

100.104.40.0/24

China (Zhangjiakou)

100.104.48.0/24

US (Virginia)

100.104.220.0/24

US (Silicon Valley)

100.104.17.0/24

Germany (Frankfurt)

100.104.133.0/24

Malaysia (Kuala Lumpur)

100.104.10.0/24

Indonesia (Jakarta)

100.104.209.0/24

Finance Cloud server CIDR blocks

Finance Cloud region

Finance Cloud server CIDR block

China (Hangzhou)

100.104.255.64/26

China (Shenzhen)

100.104.194.128/26

China (Shanghai)

100.104.45.64/26