Before you configure a data synchronization task, create and authorize database accounts for the source and destination databases. Different databases and synchronization types require different permissions.
Permissions required for the source database account
Database | Required permissions | References |
ApsaraDB for RDS for MySQL | Read permissions on the objects to synchronize. | Create accounts and databases and Modify the permissions of an account. |
self-managed MySQL |
| Create an account for a self-managed MySQL database and configure binary logging. |
PolarDB for MySQL | Read permissions on the objects to synchronize. | |
PolarDB for PostgreSQL (Oracle compatible) | Permissions of a privileged account. | |
PolarDB-X 1.0 | Read permissions on the objects to synchronize. | |
ApsaraDB for RDS for SQL Server | Owner permission on the database that contains the objects to synchronize. Note A privileged account has the required permissions. | |
self-managed SQL Server | The | |
ApsaraDB for RDS for PostgreSQL | A privileged account that owns the selected database. Note If the source database is an ApsaraDB for RDS for PostgreSQL 9.4 instance and you synchronize only DML operations, the account needs only the | |
self-managed PostgreSQL | The | CREATE USER and GRANT syntax. |
ApsaraDB for Redis | Read and write permissions on the objects to synchronize. | |
self-managed Redis | Redis does not use users or permissions. You only need to ensure the database can run the | None |
ApsaraDB for MongoDB |
| |
self-managed MongoDB |
| |
self-managed TiDB | The |
Permissions required for the destination database account
Database | Required permissions | References |
ApsaraDB for RDS for MySQL | Read and write permissions on the destination database. | Create accounts and databases and Modify the permissions of an account. |
self-managed MySQL | The | Create an account for a self-managed MySQL database and configure binary logging. |
PolarDB for MySQL | The | |
PolarDB for PostgreSQL (Oracle compatible) | Permissions of the database owner. | You specify the database owner when you create the database. |
PolarDB-X 1.0 | Write permissions on the database that contains the objects to synchronize. | |
Tair | If you use the instance password, no authorization is required. | None |
If you use a custom account, read and write permissions are required. | ||
self-managed Redis | Redis does not use users or permissions. You only need to provide the correct database password. | None |
ApsaraDB for MongoDB | The | |
self-managed MongoDB | The | |
AnalyticDB for MySQL |
| Version 3.0: Create a database account |
AnalyticDB for PostgreSQL instance | The initial account or an account with |
|
Message Queue for Apache Kafka | Not required. Note If the Kafka instance is a VPC instance, you do not need to configure a Database Account or Database Password. | None |
self-managed Kafka | Not required. Note If authentication is disabled for the Kafka cluster, you do not need to provide credentials. | None |
DataHub | You do not need to configure a Database Account. | None |
Elasticsearch | The username (default: | |
MaxCompute | The | The system automatically grants permissions when you configure the data synchronization task. |
Tablestore | You do not need to configure a Database Account. | None |
Permissions required for the database accounts in two-way data synchronization tasks
In two-way synchronization tasks, DTS creates a database named dts in both the source and destination databases to prevent circular replication. The following table lists the required permissions.
Database | Required permissions | References |
ApsaraDB for RDS for MySQL | Permissions of a privileged account. | |
self-managed MySQL | The SELECT permission on the objects to synchronize The REPLICATION CLIENT, REPLICATION SLAVE, and SHOW VIEW permissions The permissions to create databases and tables, which allow DTS to create a database named | Create an account for a self-managed MySQL database and configure binary logging. |
ApsaraDB for RDS for PostgreSQL | A privileged account that owns the selected database. | |
self-managed PostgreSQL | The | CREATE USER and GRANT syntax. |
PolarDB for MySQL | Permissions of a privileged account. | |
Tair | If you use the instance password, no authorization is required. | None |
If you use a custom account, read and write permissions are required. | ||
self-managed Redis | Redis does not use users or permissions. You only need to ensure the database can run the | None |