Use native replication instances
ApsaraDB RDS for MySQL native replication lets you replicate data from a self-managed MySQL database directly into an RDS instance using standard MySQL replication—without additional migration tools or paid data transfer services.
Use cases
-
Cloud migration with minimal downtime: Import a full backup of your self-managed database, then keep the RDS instance in sync via replication until you're ready to cut over your application.
-
Hybrid data synchronization: Keep your on-premises MySQL and cloud RDS instance continuously synchronized, for example during a phased migration or a disaster recovery setup.
-
Multicloud replication: Replicate data from a MySQL database on another cloud provider to an ApsaraDB RDS for MySQL instance.
Prerequisites
Before you begin, ensure that:
-
Database version: MySQL 5.7 (minor version 20240930 or later) or MySQL 8.0 (minor version 20250531 or later)
-
Product series: Basic Edition
-
Billing method: Subscription or pay-as-you-go
-
Region: China (Shanghai), China (Beijing), China (Shenzhen), China (Guangzhou), or China (Chengdu)
Native replication is currently available only in the regions listed above. If you need it in other regions, submit a ticket.
To use a Serverless native replication instance, first create a pay-as-you-go instance, enable native replication, and then change the billing method to Serverless.
Billing
-
New instance with native replication enabled: Standard instance fees apply. No extra charge for the native replication feature itself.
-
Upgrading an existing instance: No extra fees.
-
Importing data via Object Storage Service (OSS): OSS storage fees apply for the duration the backup file is stored in OSS.
Limitations
Functional limitations
-
The instance operates in read-only mode while native replication is active.
-
Major version upgrades are not supported.
-
Replication across major versions is not supported. The self-managed MySQL database and the RDS native replication instance must run the same major version (for example, both MySQL 8.0).
-
Upgrading the product series is not supported (for example, from Basic Edition to High-availability Edition or Cluster Edition).
-
Switching the VPC is not supported.
-
Database and table recovery is not supported.
-
When you upgrade an existing instance to a native replication instance, a transient connection of about 30 seconds may occur. Perform this operation during off-peak hours and make sure your application has a reconnection mechanism.
Permission limitations
Privileged account scope
Some SUPER privileges for native replication are granted to the privileged account of the RDS instance. Only the privileged account can run native replication commands such as CHANGE MASTER TO (MySQL 5.7) or CHANGE REPLICATION SOURCE TO (MySQL 8.0).
Replication permission allowlist
When native replication applies binary log events from an external source, it checks permissions first. Any operation that requires permissions beyond the following list is rejected and breaks the replication:
GRANT SELECT, INSERT, UPDATE, DELETE, CREATE,
DROP, RELOAD, PROCESS, REFERENCES, INDEX,
ALTER, SHOW DATABASES, CREATE TEMPORARY TABLES,
LOCK TABLES, EXECUTE, REPLICATION SLAVE,
REPLICATION CLIENT, CREATE VIEW, SHOW VIEW,
CREATE ROUTINE, ALTER ROUTINE, CREATE USER,
EVENT, TRIGGER ON *.* TO XXX;
System database limitations
All operations on system databases are ignored during replication. System databases include mysql, sys, information_schema, performance_schema, and __recyclebin__.
Operations that indirectly modify system databases—such asCREATE USERandGRANT—are not ignored. These operations must comply with the replication permission allowlist. Statements that exceed the granted permissions, such asGRANT SUPER ON *.* TO xxx;, will break the replication.
GTID limitations
ApsaraDB RDS for MySQL requires Global Transaction Identifier (GTID) mode to be enabled and does not support disabling it. To replicate from an external MySQL database, the source must also have GTID enabled.
Before setting up replication, run the following on the source database to check GTID status:
SHOW VARIABLES LIKE 'gtid_mode';
If GTID is not enabled, run:
SET GLOBAL gtid_mode = ON;
Maintenance behavior
During maintenance operations such as cross-server migration or a minor version upgrade, native replication command permissions and parameter modification permissions are temporarily revoked. The replication process itself is not affected. Permissions are restored automatically after maintenance completes.
Native replication permissions
Privileged accounts on native replication instances have additional permissions not available on standard RDS instances.
Replication commands
| Command (MySQL 5.7) | Command (MySQL 8.0) | Description |
|---|---|---|
CHANGE MASTER TO |
CHANGE REPLICATION SOURCE TO |
Configure the source and start position for replication. See MySQL 5.7 docs. |
START SLAVE |
START REPLICA |
Start the replication process. |
STOP SLAVE |
STOP REPLICA |
Stop the replication process. |
RESET SLAVE |
RESET REPLICA |
Reset the replica state to restart replication from the source. |
Parameter modification
Privileged accounts can also modify the following runtime parameters:
-
`SET GLOBAL read_only = ON/OFF;` — Switch the instance between read-only (ON) and read/write (OFF) mode.
-
`SET SESSION sql_log_bin = ON/OFF;` — Control whether SQL statements in the current session are recorded in the binary log.
-
`SET SESSION GTID_NEXT = "<gtid_value>";` — Set the GTID value for the next transaction.
Step 1: Enable native replication
Enable native replication on a new instance
When creating a new ApsaraDB RDS for MySQL instance on the Standard Create page, scroll to the bottom, expand More, and turn on the Native Replication switch.
The switch appears only when the instance configuration meets the prerequisites.
Enable native replication on an existing instance
Upgrading an existing instance causes a transient connection of about 30 seconds. Perform this operation during off-peak hours and make sure your application has a reconnection mechanism.
-
Go to the RDS Instances page, select a region, and click the ID of the target instance.
-
In the left navigation pane, click Native Replication, then click Enable.
-
Review the information in the dialog box and click OK.
If the official ApsaraDB RDS service account does not yet have permission to access your OSS and to create and attach elastic network interfaces (ENIs), select the corresponding checkboxes in the dialog box to grant these permissions.
Step 2: Configure network connectivity
Before importing data, make sure the self-managed MySQL database can communicate with the RDS instance over the network.
| Scenario | Configuration | Fees |
|---|---|---|
| Self-managed MySQL on ECS in the same VPC | Network connectivity is available by default. Configure the ECS security group to allow inbound traffic on port 3306 from the RDS instance IP. To get the RDS instance IP, connect to the instance and run SHOW VARIABLES LIKE 'report_host';. |
None |
| Cross-VPC or cross-region on Alibaba Cloud | Use a VPC peering connection or Cloud Enterprise Network (CEN). | VPC peering connection fees apply. CEN instances are free, but data transfer and bandwidth fees may apply. |
| On-premises data center to cloud | Use a VPN Gateway or a leased line to connect your data center to the VPC. | Fees vary by method. See the official documentation for details. |
| Another cloud provider to ApsaraDB RDS | Use a VPN or a leased line to establish a cross-cloud network connection. | Fees vary by method. See the official documentation for details. |
| Public network (not recommended) | ApsaraDB RDS native replication instances support public network access. This method is not recommended due to security risks. | Fees vary by method. |
For a complete reference, see Connections and networking.
Step 3: Import full data and set up replication
Import a full backup of your self-managed database into RDS, then set up incremental replication to keep the two databases in sync.
Install Percona XtraBackup and back up the source database
Install Percona XtraBackup on your self-managed database host.
Install on CentOS
For MySQL 5.7:
wget https://downloads.percona.com/downloads/Percona-XtraBackup-2.4/Percona-XtraBackup-2.4.29/binary/redhat/8/x86_64/percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
For MySQL 8.0:
wget https://downloads.percona.com/downloads/Percona-XtraBackup-8.0/Percona-XtraBackup-8.0.35-31/binary/redhat/8/x86_64/percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
Install on Ubuntu
For MySQL 5.7:
wget https://downloads.percona.com/downloads/Percona-XtraBackup-2.4/Percona-XtraBackup-2.4.29/binary/redhat/8/x86_64/percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
For MySQL 8.0:
wget https://downloads.percona.com/downloads/Percona-XtraBackup-8.0/Percona-XtraBackup-8.0.35-31/binary/redhat/8/x86_64/percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
XtraBackup on Ubuntu does not include qpress. Install it separately:
sudo apt-get install -y qpress
Create the backup
The following commands are for databases that primarily use the InnoDB engine. If your database contains MyISAM tables, use the innobackupex command instead.
Three compression methods are supported. Choose one:
Method 1: Default qpress compression
xtrabackup --backup \
--host=127.0.0.1 \
--port=3306 \
--user=<user_of_self-managed_MySQL> \
--password=<password> \
--stream=xbstream \
--compress > ./<backup_file_name>.xb
Method 2: QuickLZ compression
Requires XtraBackup version 8.0.34-29 or earlier. See the Percona XtraBackup documentation for details.
xtrabackup --backup \
--host=127.0.0.1 \
--port=3306 \
--user=<user_of_self-managed_MySQL> \
--password=<password> \
--stream=xbstream \
--compress > ./<backup_file_name>_qp.xb
Method 3: Zstandard (zstd) compression
xtrabackup --backup \
--host=127.0.0.1 \
--port=3306 \
--user=<user_of_self-managed_MySQL> \
--password=<password> \
--stream=xbstream \
| zstd -q - > ./<backup_file_name>.xb.zstd
Import the backup and set up replication
Two import methods are available. If you can upload the backup file to OSS, use Method 1. If your environment is constrained and direct streaming is preferable, use Method 2.
Method 1: Import a backup file from OSS
Upload the backup to an OSS bucket
The OSS bucket must be in the same region as the RDS instance.
Install ossutil:
yum install -y unzip
sudo -v ; curl https://gosspublic.alicdn.com/ossutil/install.sh | sudo bash
ossutil config
Upload the backup file:
ossutil -e <OSS_Endpoint> -i <your_AccessKeyId> -k <your_AccessKeySecret> cp <backup_file_name> oss://<bucket_name>/
Import the backup into RDS
-
Go to the RDS Instances page, select a region, and click the instance ID.
-
In the left navigation pane, click Native Replication.
-
Click Import Full Data, configure the parameters, and click OK.
| Category | Parameter | Description |
|---|---|---|
| Backup upload method (required) | MySQL version | Displayed automatically as 5.7 or 8.0. No configuration needed. |
| Import method | Select Import from OSS. | |
| OSS bucket | Select the OSS bucket that contains your backup file. | |
| OSS file name | Select the backup file. If the file is in a subdirectory, enter the full path. Supported formats: .xb (xbstream), _qp.xb (QuickLZ), .xb.zst (zstd). |
|
| Automatic replication setup (optional) | Auto replication building | Turn on to automatically set up replication from the source database after the import. If you leave this off, set up replication manually after importing. |
| Source IP address | IP address of the source self-managed database. | |
| Source port | Port of the source self-managed database. | |
| Source account | Account on the source database. Must have REPLICATION CLIENT and REPLICATION SLAVE permissions. |
|
| Account password | Password for the source account. |
Method 2: Stream the backup directly to RDS
Install the backup-helper tool and start the backup stream
# Install the backup-helper tool
wget -O backup-helper https://mysql-backup-helper.oss-cn-beijing.aliyuncs.com/v1.0.0-alpha/backup-helper && chmod +x backup-helper
# Start the backup stream (requires MySQL and the matching XtraBackup version to be installed)
./backup-helper --backup --mode=stream --host=<MySQL_IP> --port=<MySQL_port> --user=<MySQL_account> --password=<MySQL_password>
Import the stream into RDS
-
Log on to the ApsaraDB RDS console, select a region, and click the instance ID.
-
In the left navigation pane, click Native Replication.
-
Click Import Full Data, configure the parameters, and click OK.
| Category | Parameter | Description |
|---|---|---|
| Backup upload method (required) | MySQL version | Displayed automatically as 5.7 or 8.0. No configuration needed. |
| Import method | Select Direct Stream Backup. | |
| Source backup IP address | IP address used for the backup stream. | |
| Source backup port | Port used for the backup stream. Default: 9999. | |
| Automatic replication setup (optional) | Auto replication building | Turn on to automatically set up replication from the source database after the import. If you leave this off, set up replication manually after importing. |
| Source IP address | IP address of the source self-managed database. | |
| Source port | Port of the source self-managed database. | |
| Source account | Account on the source database. Must have REPLICATION CLIENT and REPLICATION SLAVE permissions. |
|
| Account password | Password for the source account. |
Set up replication manually (if needed)
If you did not enable Auto replication building during import, or if the automatic setup failed and cannot recover, set up the replication link manually.
-
Create a privileged account on the RDS instance.
-
On the source self-managed database, create a replication account and grant the required permissions:
-- Create a replication account. For production, restrict the allowed IP address instead of using '%'. -- Replace 'Test123!' with a strong password. CREATE USER 'replica'@'%' IDENTIFIED BY 'Test123!'; -- Grant replication permissions GRANT REPLICATION SLAVE, REPLICATION CLIENT ON *.* TO 'replica'@'%'; -- Apply the changes FLUSH PRIVILEGES; -
Log on to the RDS instance using the privileged account and run the following commands: MySQL 5.7
-- Configure the replication source CHANGE MASTER TO MASTER_HOST='<source_IP>', MASTER_PORT='<source_port>', MASTER_USER='<replication_account>', MASTER_PASSWORD='<replication_account_password>', MASTER_AUTO_POSITION=1; -- Start replication START SLAVE; -- Check replication status SHOW SLAVE STATUS;MySQL 8.0
-- Configure the replication source CHANGE REPLICATION SOURCE TO SOURCE_HOST='<source_IP>', SOURCE_PORT='<source_port>', SOURCE_USER='<replication_account>', SOURCE_PASSWORD='<replication_account_password>', SOURCE_AUTO_POSITION=1; -- Start replication START REPLICA; -- Check replication status SHOW REPLICA STATUS;
Verify replication status
On the Native Replication page of the RDS instance, check the replication status. When it shows Running, the replication link is active and data is being synchronized.
Disable native replication
When you're ready to cut over your application—or if you no longer need the replication—disable native replication to switch the instance back to read/write mode.
-
Go to the RDS Instances page, select a region, and click the instance ID.
-
In the left navigation pane, click Native Replication, then click Disable.
-
Click OK.
After you click OK, the replication link from the source database is terminated. The RDS instance reverts to a standard ApsaraDB RDS for MySQL instance and switches from read-only to read/write mode, allowing write operations.
API reference
| Operation | API | Notes |
|---|---|---|
| Create an instance with native replication | CreateDBInstance | Set ExternalReplication to ON. The basic instance configuration must meet the prerequisites. |
| Set up a native replication link for an existing instance | ImportUserBackupFile | — |