All Products
Search
Document Center

Data Transmission Service:Configure RAM authorization for cross-account DTS tasks

Last Updated:Aug 27, 2026

This topic describes how to configure RAM authorization for the Alibaba Cloud account that owns a database instance when configuring a cross-account DTS task.

Note

If you do not need background information, you can directly configure RAM authorization for a database instance where the Replicate Data Across Alibaba Cloud Accounts setting is Yes. For details, see Scenario 1: Source database is cross-account, Scenario 2: Destination database is cross-account, and Scenario 3: Both source and destination databases are cross-account.

Background information

To configure a cross-account DTS task where you select Yes for the Replicate Data Across Alibaba Cloud Accounts parameter, you must first perform RAM authorization. This process designates the Alibaba Cloud account (root account) that creates the DTS task as a trusted account, allowing it to access the cloud resources of the Alibaba Cloud account that owns the database instance through DTS.

What is a cross-account task

A cross-account task is a DTS task where the source or destination database instance belongs to an Alibaba Cloud account other than the one used to create the task.

Scenarios for cross-account tasks

There are three cross-account scenarios, which depend on the Alibaba Cloud account used to create the DTS task in the DTS console.

Note

For more information about accounts, see Accounts.

Scenario

Description

Configuration

Source database is cross-account

For the source database, Yes is selected for the Replicate Data Across Alibaba Cloud Accounts parameter. For the destination database, No is selected for the Replicate Data Across Alibaba Cloud Accounts parameter.

Use Alibaba Cloud account A (source database owner) to configure RAM authorization and account B (destination database owner) to create the DTS task.

Destination database is cross-account

For the source database, No is selected for the Replicate Data Across Alibaba Cloud Accounts parameter. For the destination database, Yes is selected for the Replicate Data Across Alibaba Cloud Accounts parameter.

Use Alibaba Cloud account B (destination database owner) to configure RAM authorization and account A (source database owner) to create the DTS task.

Both source and destination databases are cross-account

For both the source and destination databases, Yes is selected for the Replicate Data Across Alibaba Cloud Accounts parameter.

Alibaba Cloud accounts A (source) and B (destination) must separately configure RAM authorization. A designated Alibaba Cloud account C is then used to create the DTS task.

Supported databases

Whether a database instance supports cross-account access depends on its Database Type and Access Method. The following tables list the supported database instances.

Note

The source database's Replicate Data Across Alibaba Cloud Accounts setting does not affect the available Database Type options for the destination database.

Source database

Type

Access method

MySQL

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS

PolarDB for MySQL

Alibaba Cloud Instance

Tair/Redis

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS, Cloud Enterprise Network (CEN), Database Gateway

SQL Server

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway

PostgreSQL

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway

MongoDB

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS, Cloud Enterprise Network (CEN)

Important

Cross-account configuration is not supported if the source database is an ApsaraDB for MongoDB instance (sharded cluster architecture) that is accessed over Express Connect, VPN Gateway, or Smart Access Gateway.

Oracle

Express Connect, VPN Gateway, or Smart Access Gateway

PolarDB (Compatible with Oracle)

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway

PolarDB for PostgreSQL

Alibaba Cloud Instance

PolarDB-X 1.0

Alibaba Cloud Instance

PolarDB-X 2.0

Alibaba Cloud Instance

DB2 for iSeries (AS/400)

Express Connect, VPN Gateway, or Smart Access Gateway

DB2 for LUW

Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS

MariaDB

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS

ApsaraDB OceanBase for MySQL

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS

SLS

Alibaba Cloud Instance

AnalyticDB for MySQL 3.0

Alibaba Cloud Instance

Kafka

Alibaba Cloud Instance, Express Connect, VPN Gateway, or Smart Access Gateway, Self-managed Database on ECS

Destination database

Type

Access method

MySQL

Alibaba Cloud Instance

PolarDB for MySQL

Alibaba Cloud Instance

AnalyticDB for MySQL 3.0

Alibaba Cloud Instance

Tair/Redis

Alibaba Cloud Instance

ClickHouse

Alibaba Cloud Instance

ApsaraDB for SelectDB

Alibaba Cloud Instance

MongoDB

Alibaba Cloud Instance

Accounts

In a cross-account task, the role of each Alibaba Cloud account (for the source database, destination database, and DTS task) depends on which database is configured as cross-account.

Note

Cross-account database: The database for which Yes is selected for the Replicate Data Across Alibaba Cloud Accounts parameter when you configure the DTS task. This is used to determine the cross-account task scenario.

To use this table, first identify which database is cross-account. Then, find that scenario in the Cross-account database column to determine which Alibaba Cloud account to use for each step.

Cross-account database

RAM console account

Trust policy account

DTS task account

DTS task cross-account

Source database

The account that owns the source database.

The account that owns the destination database.

The account that owns the destination database.

In the Source Database section, enter the ID of the Alibaba Cloud account that owns the source database in the Alibaba Cloud Account field.

Destination database

The account that owns the destination database.

The account that owns the source database.

The account that owns the source database.

In the Destination Database section, enter the ID of the Alibaba Cloud account that owns the destination database in the Alibaba Cloud Account field.

Source and destination databases

The accounts that own the source and destination databases.

A designated account.

A designated account.

  • In the Source Database section, enter the ID of the Alibaba Cloud account that owns the source database in the Alibaba Cloud Account field.

    i0z" conref="mcms_dita_dts_web.dita#dts_web/dts.common.field.crossAccount"> field.

  • In the Destination Database section, enter the ID of the Alibaba Cloud account that owns the destination database in the Alibaba Cloud Account field.

    e953dna" conref="mcms_dita_dts_web.dita#dts_web/dts.common.field.crossAccount"> field.

Configuration

  1. Identify the cross-account task scenario.

    The database instance determines the scenario. A task is considered Replicate Data Across Alibaba Cloud Accounts if the instance is owned by a different account, and must be configured as Yes.

    d as Yes.

  2. Get the main account IDs.

    Get the ID of the main account that owns the database instance and the ID of the main account you will use to create the DTS task.

    account that owns the database instance and the ID of the main account you will use to create the DTS task.

  3. Create a RAM role.

    Use the main account that owns the database instance to create the required RAM role.

    the database instance to create the required RAM role.

  4. Grant fine-grained authorization.

    Grant fine-grained authorization to the newly created RAM role.

    c5c8obu">Grant fine-grained authorization to the newly created RAM role.

  5. Modify the trust policy.

    Modify the trust policy of the RAM role.

    Modify the trust policy of the RAM role.

Prerequisites

You have granted DTS permission to access cloud resources.

Considerations

  • Yes, but currently, only two-way synchronization tasks between ApsaraDB RDS for MySQL instances, between PolarDB for MySQL clusters, between Tair (Enterprise Edition) instances, between ApsaraDB for MongoDB (ReplicaSet) instances, or between ApsaraDB for MongoDB (sharded cluster) instances support cross-account two-way synchronization.

  • A cross-account two-way synchronization task involves a source database and a target database in different accounts. Therefore, you must configure RAM authorization for the Alibaba Cloud accounts of both the source and target databases.

    base and a target database in different accounts. Therefore, you must configure RAM authorization for the Alibaba Cloud accounts of both the source and target databases.

  • Synchronization between different account types, such as Financial Cloud and Government Cloud accounts, is not supported.

    count types, such as Financial Cloud and Government Cloud accounts, is not supported.

  • Always log in to the console with a main Alibaba Cloud account. If you use a RAM user, you may encounter an authorization error when you create a DTS task.

    you use a RAM user, you may encounter an authorization error when you create a DTS task.

  • When you select Express Connect, VPN Gateway, or Smart Access Gateway, the Replicate Data Across Alibaba Cloud Accounts option is displayed. Select Yes, enter the other Alibaba Cloud account ID and the cross-account role name, and manually enter the internal IP address, port, database account, and password of the other database.

    other Alibaba Cloud account ID and the cross-account role name, and manually enter the internal IP address, port, database account, and password of the other database.

  • Cross-account synchronization does not require connecting two VPCs in advance. After you select Yes, the VPC selection box is disabled. DTS accesses resources in the other account through RAM role authentication.

    -isbold="true" id="ui-nc-yes-2">, the VPC selection box is disabled. DTS accesses resources in the other account through RAM role authentication.

  • The ECS instance list shows only ECS instances of the current account. Selecting ECS instances from the other account is not supported. In cross-account scenarios, enter the database IP address manually.

    ccount. Selecting ECS instances from the other account is not supported. In cross-account scenarios, enter the database IP address manually.

Prerequisites

Source database's primary account ID

Log in to the Alibaba Cloud console with this account. Go to the or Security Settings page. Get the Account ID .

Destination database's primary account ID

Log in to the Alibaba Cloud console with this account. Go to the or Security Settings page. Get the Account ID .

Primary account ID for the DTS task

Log in to the Alibaba Cloud console with this account. Go to the or Security Settings page. Get the Account ID .

Scenario 1: Source database in a different account

Step 1: Create a RAM role

  1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

    k"> with the Alibaba Cloud account (main account) that owns the source database.

  2. In the left-side navigation pane, choose Identities > Role.

    Important

    Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

    error occurs.

  3. On the Role page, click Create Role.

    id="uicontrol_znn_dnk_zbi">Create Role.

  4. In the Create Role panel, configure the RAM role.

    1. For Principal Type, select Cloud Account.

    2. For Principal Name, select Other Account and enter the ID of the Alibaba Cloud account (main account) that owns the destination database.

    3. At the bottom of the page, click OK.

    4. In the Create Role panel, enter a name for the RAM role and click OK.

      In this example, enter ram-for-dts.

    g="uicontrol" id="a73e158de1l6x" conref="mcms_dita_dts_web.dita#dts_web/dts.common.ok">.

    In this example, enter ram-for-dts.

    on.ok">.

    In this example, enter ram-for-dts.

Step 2: Grant precise permissions

AliyunDTSRolePolicy cannot be found through the search feature of Add Permissions. In the Permissions tab, click Precise Permission. Enter AliyunDTSRolePolicy in the policy name text box, and then click OK to complete the authorization.

From the success page

  1. On the Permissions tab, click Grant Permission.

    g">Permissions tab, click Grant Permission.

  2. In the Grant Permission panel, set Policy Type to System Policy.

    ission panel, set Policy Type to System Policy.

  3. In the Policy Name field, enter AliyunDTSRolePolicy.

    /b> field, enter AliyunDTSRolePolicy.

  4. Click OK.

    You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

    side of the Permissions tab to confirm that the permission has been granted.

From the role list

  1. Go to the details page of the RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

      k"> with the Alibaba Cloud account (main account) that owns the source database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, find and click the target RAM role.

    ind and click the target RAM role.d click the target RAM role.

  2. On the Permissions tab, click Grant Permission.

    g">Permissions tab, click Grant Permission.

  3. In the Grant Permission panel, set Policy Type to System Policy.

    ission panel, set Policy Type to System Policy.

  4. In the Policy Name field, enter AliyunDTSRolePolicy.

    /b> field, enter AliyunDTSRolePolicy.

  5. Click OK.

    You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

    side of the Permissions tab to confirm that the permission has been granted.

Step 3: Update the trust policy

From the authorization success page

  1. Click the Trust Policy tab.

    Click Edit Trust Policy.

    >

    Click Edit Trust Policy.

  2. On the Trust Policy tab, click Edit Trust Policy.

    >Trust Policy tab, click Edit Trust Policy.

  3. On the JSON tab, replace the existing code in the policy editor with the following code.

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::<Alibaba Cloud account ID>:root"
                    ],
                    "Service": [
                        "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    /div>

  4. Replace both <Alibaba Cloud account ID> placeholders with the ID of the Alibaba Cloud account (main account) that owns the destination database.

    Example (click to expand)

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::164682176356****:root"
                    ],
                    "Service": [
                        "164682176356****@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    "164682176356****@dts.aliyuncs.com" ] } } ], "Version": "1" }

  5. Click OK to save the trust policy.<Alibaba Cloud account ID>@dts.aliyuncs.com" to "dts.aliyuncs.com", it indicates that the specified <Alibaba Cloud account ID> is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.

    If, after you save the trust policy, the Service section of the code automatically changes from "<Alibaba Cloud account ID>@dts.aliyuncs.com" to "dts.aliyuncs.com", the <Alibaba Cloud account ID> is incorrectly configured. You need to enter the Alibaba Cloud account ID of the destination database, but you entered the Alibaba Cloud account ID of the source database.

    Note

    For more information about which Alibaba Cloud account to use for signing in and which account ID to specify in the trust policy, see Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.

From the role list

  1. Go to the details page of the RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

      k"> with the Alibaba Cloud account (main account) that owns the source database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, find and click the target RAM role.

    OPIC">

  2. Click the Trust Policy tab.

    Click Edit Trust Policy.

    >

    Click Edit Trust Policy.

  3. On the Trust Policy tab, click Edit Trust Policy.

    >Trust Policy tab, click Edit Trust Policy.

  4. On the JSON tab, replace the existing code in the policy editor with the following code.

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::<Alibaba Cloud account ID>:root"
                    ],
                    "Service": [
                        "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    /div>

  5. Replace both <Alibaba Cloud account ID> placeholders with the ID of the Alibaba Cloud account (main account) that owns the destination database.

    Example (click to expand)

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::164682176356****:root"
                    ],
                    "Service": [
                        "164682176356****@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    "164682176356****@dts.aliyuncs.com" ] } } ], "Version": "1" }

  6. Click OK to save the trust policy.<Alibaba Cloud account ID>@dts.aliyuncs.com" to "dts.aliyuncs.com", it indicates that the specified <Alibaba Cloud account ID> is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.is incorrect. Make sure that you provide the ID of the Alibaba Cloud account that owns the destination database, not the source database.

    If, after you save the trust policy, the Service section of the code automatically changes from "<Alibaba Cloud account ID>@dts.aliyuncs.com" to "dts.aliyuncs.com", the <Alibaba Cloud account ID> is incorrectly configured. You need to enter the Alibaba Cloud account ID of the destination database, but you entered the Alibaba Cloud account ID of the source database.

    Note

    For more information about which Alibaba Cloud account to use for signing in and which account ID to specify in the trust policy, see Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.-node="17089" baseurl="t17089_v1_14_13.xdita" data-tag="xref" id="40bb40df41xbf" href="#ae3f1fb80bnxf">Account information.

Scenario 2: Destination in another account

Step 1: Create a RAM role

  1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

    "> with the Alibaba Cloud root account that owns the destination database.

  2. In the left-side navigation pane, choose Identities > Role.

    Important

    Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

    error occurs.

  3. On the Role page, click Create Role.

    id="uicontrol_znn_dnk_zbi">Create Role.

  4. In the Create Role panel, configure the RAM role.

    1. For Principal Type, select Cloud Account.

    2. For Principal Name, select Other Account, and then enter the ID of the Alibaba Cloud root account that owns the source database.

    3. At the bottom of the page, click OK.

    4. In the Create Role panel, enter a name for the RAM role and click OK.

      In this example, enter ram-for-dts.

    d">Obtain the ID of the Alibaba Cloud root account that owns the source database.

Step 2: Grant permissions to the RAM role

From the success page

  1. On the Permissions tab, click Grant Permission.

    g">Permissions tab, click Grant Permission.

  2. In the Grant Permission panel, set Policy Type to System Policy.

    ission panel, set Policy Type to System Policy.

  3. In the Policy Name field, enter AliyunDTSRolePolicy.

    /b> field, enter AliyunDTSRolePolicy.

  4. Click OK.

    You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

    side of the Permissions tab to confirm that the permission has been granted.

From the role list

  1. Go to the details page of the RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

      "> with the Alibaba Cloud root account that owns the destination database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, find and click the target RAM role.

    OPIC">

  2. On the Permissions tab, click Grant Permission.

    g">Permissions tab, click Grant Permission.

  3. In the Grant Permission panel, set Policy Type to System Policy.

    ission panel, set Policy Type to System Policy.

  4. In the Policy Name field, enter AliyunDTSRolePolicy.

    /b> field, enter AliyunDTSRolePolicy.

  5. Click OK.

    You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

    side of the Permissions tab to confirm that the permission has been granted.

Step 3: Update the trust policy

From the success page

  1. Click the Trust Policy tab.

    Click Edit Trust Policy.

    >

    Click Edit Trust Policy.

  2. On the Trust Policy tab, click Edit Trust Policy.

    >Trust Policy tab, click Edit Trust Policy.

  3. On the JSON tab, replace the existing code in the policy editor with the following code.

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::<Alibaba Cloud account ID>:root"
                    ],
                    "Service": [
                        "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    /div>

  4. Replace both <Alibaba Cloud account ID> placeholders with the ID of the Alibaba Cloud root account that owns the source database.

    Example (click to expand)

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::164682176356****:root"
                    ],
                    "Service": [
                        "164682176356****@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    Id="4967131" docType="TOPIC" data-node="17089" data-latest="1" conref="#a80e7d098eh5q">

  5. Click OK, save the trust policy.

    If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID of the source database, but you configured the destination database's account ID)。

    Note

    For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

    13db5dcx99" type="note" data-init-id="9894a6a1436ab">

    For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

From the role list

  1. Go to the details page of the RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

      "> with the Alibaba Cloud root account that owns the destination database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, find and click the target RAM role.

    OPIC">

  2. Click the Trust Policy tab.

    Click Edit Trust Policy.

    >

    Click Edit Trust Policy.

  3. On the Trust Policy tab, click Edit Trust Policy.

    >Trust Policy tab, click Edit Trust Policy.

  4. On the JSON tab, replace the existing code in the policy editor with the following code.

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::<Alibaba Cloud account ID>:root"
                    ],
                    "Service": [
                        "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    /div>

  5. Replace both <Alibaba Cloud account ID> placeholders with the ID of the Alibaba Cloud root account that owns the source database.

    Example (click to expand)

    {
        "Statement": [
            {
                "Action": "sts:AssumeRole",
                "Effect": "Allow",
                "Principal": {
                    "RAM": [
                        "acs:ram::164682176356****:root"
                    ],
                    "Service": [
                        "164682176356****@dts.aliyuncs.com"
                    ]
                }
            }
        ],
        "Version": "1"
    }

    Id="4967131" docType="TOPIC" data-node="17089" data-latest="1" conref="#a80e7d098eh5q">

  6. Click OK, save the trust policy.

    If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID of the source database, but you configured the destination database's account ID)。

    Note

    For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

    13db5dcx99" type="note" data-init-id="9894a6a1436ab">

    For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

Scenario 3: Cross-account source and destination databases

Step 1: Configure RAM for the source account

  1. Create a RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

      k"> with the Alibaba Cloud account (main account) that owns the source database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, click Create Role.

      id="uicontrol_znn_dnk_zbi">Create Role.

    4. In the Create Role panel, configure the RAM role.

      1. For Principal Type, select Cloud Account.

      2. For Principal Name, select Other Account, and enter the ID of the designated root account for creating the DTS task.

      3. At the bottom of the page, click OK.

      4. In the Create Role panel, enter a name for the RAM role and click OK.

        In this example, enter ram-for-dts.

    >

  2. Grant precise permissions to the RAM role.

    From the success page

    1. On the Permissions tab, click Grant Permission.

      g">Permissions tab, click Grant Permission.

    2. In the Grant Permission panel, set Policy Type to System Policy.

      ission panel, set Policy Type to System Policy.

    3. In the Policy Name field, enter AliyunDTSRolePolicy.

      /b> field, enter AliyunDTSRolePolicy.

    4. Click OK.

      You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

      side of the Permissions tab to confirm that the permission has been granted.

    From the role list

    1. Go to the details page of the RAM role.

      1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

        k"> with the Alibaba Cloud account (main account) that owns the source database.

      2. In the left-side navigation pane, choose Identities > Role.

        Important

        Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

        error occurs.

      3. On the Role page, find and click the target RAM role.

      ind and click the target RAM role.d click the target RAM role.

    2. On the Permissions tab, click Grant Permission.

      g">Permissions tab, click Grant Permission.

    3. In the Grant Permission panel, set Policy Type to System Policy.

      ission panel, set Policy Type to System Policy.

    4. In the Policy Name field, enter AliyunDTSRolePolicy.

      /b> field, enter AliyunDTSRolePolicy.

    5. Click OK.

      You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

      side of the Permissions tab to confirm that the permission has been granted.

  3. Modify the trust policy of the RAM role.

    From the Precise Permission success page

    1. Click the Trust Policy tab.

      Click Edit Trust Policy.

      >

      Click Edit Trust Policy.

    2. On the Trust Policy tab, click Edit Trust Policy.

      >Trust Policy tab, click Edit Trust Policy.

    3. On the JSON tab, replace the existing code in the policy editor with the following code.

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::<Alibaba Cloud account ID>:root"
                      ],
                      "Service": [
                          "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }

      /div>

    4. Replace the two <Alibaba Cloud account ID> placeholders in the code with the ID of the Alibaba Cloud account that is used to create the DTS task.

      Example (click to expand)

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::164682176356****:root"
                      ],
                      "Service": [
                          "164682176356****@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }
    5. Click OK, save the trust policy.

      If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID that created the DTS task, but you configured the source database's account ID)。

      Note

      For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

    From the RAM role list

    1. Go to the details page of the RAM role.

      1. Sign in to the RAM console with the Alibaba Cloud account (main account) that owns the source database.

        k"> with the Alibaba Cloud account (main account) that owns the source database.

      2. In the left-side navigation pane, choose Identities > Role.

        Important

        Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

        error occurs.

      3. On the Role page, find and click the target RAM role.

    2. Click the Trust Policy tab.

      Click Edit Trust Policy.

      >

      Click Edit Trust Policy.

    3. On the Trust Policy tab, click Edit Trust Policy.

      >Trust Policy tab, click Edit Trust Policy.

    4. On the JSON tab, replace the existing code in the policy editor with the following code.

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::<Alibaba Cloud account ID>:root"
                      ],
                      "Service": [
                          "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }

      /div>

    5. Replace the two <Alibaba Cloud account ID> placeholders in the code with the ID of the Alibaba Cloud account that is used to create the DTS task.

      Example (click to expand)

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::164682176356****:root"
                      ],
                      "Service": [
                          "164682176356****@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }
    6. Click OK, save the trust policy.

      If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID that created the DTS task, but you configured the source database's account ID)。

      Note

      For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

Step 2: Configure RAM authorization using the Alibaba Cloud account (primary account) of the destination database

  1. Create a RAM role.

    1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

      "> with the Alibaba Cloud root account that owns the destination database.

    2. In the left-side navigation pane, choose Identities > Role.

      Important

      Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

      error occurs.

    3. On the Role page, click Create Role.

      id="uicontrol_znn_dnk_zbi">Create Role.

    4. In the Create Role panel, configure the RAM role.

      1. For Principal Type, select Cloud Account.

      2. For Principal Name, select Other Account, and enter the ID of the designated root account for creating the DTS task.

      3. At the bottom of the page, click OK.

      4. In the Create Role panel, enter a name for the RAM role and click OK.

        In this example, enter ram-for-dts.

  2. Grant precise permissions to the RAM role.

    From the success page

    1. On the Permissions tab, click Grant Permission.

      g">Permissions tab, click Grant Permission.

    2. In the Grant Permission panel, set Policy Type to System Policy.

      ission panel, set Policy Type to System Policy.

    3. In the Policy Name field, enter AliyunDTSRolePolicy.

      /b> field, enter AliyunDTSRolePolicy.

    4. Click OK.

      You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

      side of the Permissions tab to confirm that the permission has been granted.

    From the role list

    1. Go to the details page of the RAM role.

      1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

        "> with the Alibaba Cloud root account that owns the destination database.

      2. In the left-side navigation pane, choose Identities > Role.

        Important

        Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

        error occurs.

      3. On the Role page, find and click the target RAM role.

      OPIC">

    2. On the Permissions tab, click Grant Permission.

      g">Permissions tab, click Grant Permission.

    3. In the Grant Permission panel, set Policy Type to System Policy.

      ission panel, set Policy Type to System Policy.

    4. In the Policy Name field, enter AliyunDTSRolePolicy.

      /b> field, enter AliyunDTSRolePolicy.

    5. Click OK.

      You can click the refresh icon image on the right side of the Permissions tab to confirm that the permission has been granted.

      side of the Permissions tab to confirm that the permission has been granted.

  3. Modify the trust policy of the RAM role.

    From the page that indicates the permission is granted

    1. Click the Trust Policy tab.

      Click Edit Trust Policy.

      >

      Click Edit Trust Policy.

    2. On the Trust Policy tab, click Edit Trust Policy.

      >Trust Policy tab, click Edit Trust Policy.

    3. On the JSON tab, replace the existing code in the policy editor with the following code.

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::<Alibaba Cloud account ID>:root"
                      ],
                      "Service": [
                          "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }

      /div>

    4. Replace the two <Alibaba Cloud account ID> placeholders in the code with the ID of the Alibaba Cloud account that is used to create the DTS task.

      Example (click to expand)

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::164682176356****:root"
                      ],
                      "Service": [
                          "164682176356****@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }
    5. Click OK, save the trust policy.

      If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID that created the DTS task, but you configured the destination database's account ID)。

      Note

      For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

    From the RAM role list

    1. Go to the details page of the RAM role.

      1. Sign in to the RAM console with the Alibaba Cloud root account that owns the destination database.

        "> with the Alibaba Cloud root account that owns the destination database.

      2. In the left-side navigation pane, choose Identities > Role.

        Important

        Do not choose Identities > Users. Otherwise, DTS cannot access the database instance and an error occurs.

        error occurs.

      3. On the Role page, find and click the target RAM role.

    2. Click the Trust Policy tab.

      Click Edit Trust Policy.

      >

      Click Edit Trust Policy.

    3. On the Trust Policy tab, click Edit Trust Policy.

      >Trust Policy tab, click Edit Trust Policy.

    4. On the JSON tab, replace the existing code in the policy editor with the following code.

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::<Alibaba Cloud account ID>:root"
                      ],
                      "Service": [
                          "<Alibaba Cloud account ID>@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }

      /div>

    5. Replace the two <Alibaba Cloud account ID> placeholders in the code with the ID of the Alibaba Cloud account that is used to create the DTS task.

      Example (click to expand)

      {
          "Statement": [
              {
                  "Action": "sts:AssumeRole",
                  "Effect": "Allow",
                  "Principal": {
                      "RAM": [
                          "acs:ram::164682176356****:root"
                      ],
                      "Service": [
                          "164682176356****@dts.aliyuncs.com"
                      ]
                  }
              }
          ],
          "Version": "1"
      }
    6. Click OK, save the trust policy.

      If, after saving the trust policy, the "<Alibaba Cloud account ID>@dts.aliyuncs.com" part of the code changes to "dts.aliyuncs.com" automatically, this indicates that <Alibaba Cloud account ID>is configured incorrectly (it must be the Alibaba Cloud account ID that created the DTS task, but you configured the destination database's account ID)。

      Note

      For the Alibaba Cloud account used to log on to the RAM console and replaced in the trust policy, see Accounts

Next steps

After completing RAM authorization, you can create a cross-account task. For details, see Configure a cross-account task.

FAQ

Can cross-account RAM authorization be reused across database types?

Yes. Cross-account RAM authorization depends only on the account ID and role name, and is independent of the database type. Authorization configured for one database type can be reused directly for other database types that support cross-account access.