Use native replication instances

Updated at:

ApsaraDB RDS for MySQL native replication lets you replicate data from a self-managed MySQL database directly into an RDS instance using standard MySQL replication—without additional migration tools or paid data transfer services.

Use cases

  • Cloud migration with minimal downtime: Import a full backup of your self-managed database, then keep the RDS instance in sync via replication until you're ready to cut over your application.

  • Hybrid data synchronization: Keep your on-premises MySQL and cloud RDS instance continuously synchronized, for example during a phased migration or a disaster recovery setup.

  • Multicloud replication: Replicate data from a MySQL database on another cloud provider to an ApsaraDB RDS for MySQL instance.

Prerequisites

Before you begin, ensure that:

  • Database version: MySQL 5.7 (minor version 20240930 or later) or MySQL 8.0 (minor version 20250531 or later)

  • Product series: Basic Edition

  • Billing method: Subscription or pay-as-you-go

  • Region: China (Shanghai), China (Beijing), China (Shenzhen), China (Guangzhou), or China (Chengdu)

Native replication is currently available only in the regions listed above. If you need it in other regions, submit a ticket.

To use a Serverless native replication instance, first create a pay-as-you-go instance, enable native replication, and then change the billing method to Serverless.

Billing

  • New instance with native replication enabled: Standard instance fees apply. No extra charge for the native replication feature itself.

  • Upgrading an existing instance: No extra fees.

  • Importing data via Object Storage Service (OSS): OSS storage fees apply for the duration the backup file is stored in OSS.

Limitations

Functional limitations

  • The instance operates in read-only mode while native replication is active.

  • Major version upgrades are not supported.

  • Replication across major versions is not supported. The self-managed MySQL database and the RDS native replication instance must run the same major version (for example, both MySQL 8.0).

  • Upgrading the product series is not supported (for example, from Basic Edition to High-availability Edition or Cluster Edition).

  • Switching the VPC is not supported.

  • Database and table recovery is not supported.

  • When you upgrade an existing instance to a native replication instance, a transient connection of about 30 seconds may occur. Perform this operation during off-peak hours and make sure your application has a reconnection mechanism.

Permission limitations

Privileged account scope

Some SUPER privileges for native replication are granted to the privileged account of the RDS instance. Only the privileged account can run native replication commands such as CHANGE MASTER TO (MySQL 5.7) or CHANGE REPLICATION SOURCE TO (MySQL 8.0).

Replication permission allowlist

When native replication applies binary log events from an external source, it checks permissions first. Any operation that requires permissions beyond the following list is rejected and breaks the replication:

GRANT SELECT, INSERT, UPDATE, DELETE, CREATE,
DROP, RELOAD, PROCESS, REFERENCES, INDEX,
ALTER, SHOW DATABASES, CREATE TEMPORARY TABLES,
LOCK TABLES, EXECUTE, REPLICATION SLAVE,
REPLICATION CLIENT, CREATE VIEW, SHOW VIEW,
CREATE ROUTINE, ALTER ROUTINE, CREATE USER,
EVENT, TRIGGER ON *.* TO XXX;

System database limitations

All operations on system databases are ignored during replication. System databases include mysql, sys, information_schema, performance_schema, and __recyclebin__.

Operations that indirectly modify system databases—such as CREATE USER and GRANT—are not ignored. These operations must comply with the replication permission allowlist. Statements that exceed the granted permissions, such as GRANT SUPER ON *.* TO xxx;, will break the replication.

GTID limitations

ApsaraDB RDS for MySQL requires Global Transaction Identifier (GTID) mode to be enabled and does not support disabling it. To replicate from an external MySQL database, the source must also have GTID enabled.

Before setting up replication, run the following on the source database to check GTID status:

SHOW VARIABLES LIKE 'gtid_mode';

If GTID is not enabled, run:

SET GLOBAL gtid_mode = ON;

Maintenance behavior

During maintenance operations such as cross-server migration or a minor version upgrade, native replication command permissions and parameter modification permissions are temporarily revoked. The replication process itself is not affected. Permissions are restored automatically after maintenance completes.

Native replication permissions

Privileged accounts on native replication instances have additional permissions not available on standard RDS instances.

Replication commands

Command (MySQL 5.7) Command (MySQL 8.0) Description
CHANGE MASTER TO CHANGE REPLICATION SOURCE TO Configure the source and start position for replication. See MySQL 5.7 docs.
START SLAVE START REPLICA Start the replication process.
STOP SLAVE STOP REPLICA Stop the replication process.
RESET SLAVE RESET REPLICA Reset the replica state to restart replication from the source.

Parameter modification

Privileged accounts can also modify the following runtime parameters:

  • `SET GLOBAL read_only = ON/OFF;` — Switch the instance between read-only (ON) and read/write (OFF) mode.

  • `SET SESSION sql_log_bin = ON/OFF;` — Control whether SQL statements in the current session are recorded in the binary log.

  • `SET SESSION GTID_NEXT = "<gtid_value>";` — Set the GTID value for the next transaction.

Step 1: Enable native replication

Enable native replication on a new instance

When creating a new ApsaraDB RDS for MySQL instance on the Standard Create page, scroll to the bottom, expand More, and turn on the Native Replication switch.

The switch appears only when the instance configuration meets the prerequisites.

image

Enable native replication on an existing instance

Important

Upgrading an existing instance causes a transient connection of about 30 seconds. Perform this operation during off-peak hours and make sure your application has a reconnection mechanism.

  1. Go to the RDS Instances page, select a region, and click the ID of the target instance.

  2. In the left navigation pane, click Native Replication, then click Enable.

  3. Review the information in the dialog box and click OK.

If the official ApsaraDB RDS service account does not yet have permission to access your OSS and to create and attach elastic network interfaces (ENIs), select the corresponding checkboxes in the dialog box to grant these permissions.

Step 2: Configure network connectivity

Before importing data, make sure the self-managed MySQL database can communicate with the RDS instance over the network.

Scenario Configuration Fees
Self-managed MySQL on ECS in the same VPC Network connectivity is available by default. Configure the ECS security group to allow inbound traffic on port 3306 from the RDS instance IP. To get the RDS instance IP, connect to the instance and run SHOW VARIABLES LIKE 'report_host';. None
Cross-VPC or cross-region on Alibaba Cloud Use a VPC peering connection or Cloud Enterprise Network (CEN). VPC peering connection fees apply. CEN instances are free, but data transfer and bandwidth fees may apply.
On-premises data center to cloud Use a VPN Gateway or a leased line to connect your data center to the VPC. Fees vary by method. See the official documentation for details.
Another cloud provider to ApsaraDB RDS Use a VPN or a leased line to establish a cross-cloud network connection. Fees vary by method. See the official documentation for details.
Public network (not recommended) ApsaraDB RDS native replication instances support public network access. This method is not recommended due to security risks. Fees vary by method.

For a complete reference, see Connections and networking.

Step 3: Import full data and set up replication

Import a full backup of your self-managed database into RDS, then set up incremental replication to keep the two databases in sync.

Install Percona XtraBackup and back up the source database

Install Percona XtraBackup on your self-managed database host.

Install on CentOS

For MySQL 5.7:

wget https://downloads.percona.com/downloads/Percona-XtraBackup-2.4/Percona-XtraBackup-2.4.29/binary/redhat/8/x86_64/percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm

For MySQL 8.0:

wget https://downloads.percona.com/downloads/Percona-XtraBackup-8.0/Percona-XtraBackup-8.0.35-31/binary/redhat/8/x86_64/percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm

Install on Ubuntu

For MySQL 5.7:

wget https://downloads.percona.com/downloads/Percona-XtraBackup-2.4/Percona-XtraBackup-2.4.29/binary/redhat/8/x86_64/percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-24-2.4.29-1.el8.x86_64.rpm

For MySQL 8.0:

wget https://downloads.percona.com/downloads/Percona-XtraBackup-8.0/Percona-XtraBackup-8.0.35-31/binary/redhat/8/x86_64/percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm
yum localinstall percona-xtrabackup-80-8.0.35-31.1.el8.x86_64.rpm

XtraBackup on Ubuntu does not include qpress. Install it separately:

sudo apt-get install -y qpress

Create the backup

The following commands are for databases that primarily use the InnoDB engine. If your database contains MyISAM tables, use the innobackupex command instead.

Three compression methods are supported. Choose one:

Method 1: Default qpress compression

xtrabackup --backup \
  --host=127.0.0.1 \
  --port=3306 \
  --user=<user_of_self-managed_MySQL> \
  --password=<password> \
  --stream=xbstream \
  --compress > ./<backup_file_name>.xb

Method 2: QuickLZ compression

Requires XtraBackup version 8.0.34-29 or earlier. See the Percona XtraBackup documentation for details.

xtrabackup --backup \
  --host=127.0.0.1 \
  --port=3306 \
  --user=<user_of_self-managed_MySQL> \
  --password=<password> \
  --stream=xbstream \
  --compress > ./<backup_file_name>_qp.xb

Method 3: Zstandard (zstd) compression

xtrabackup --backup \
  --host=127.0.0.1 \
  --port=3306 \
  --user=<user_of_self-managed_MySQL> \
  --password=<password> \
  --stream=xbstream \
  | zstd -q - > ./<backup_file_name>.xb.zstd

Import the backup and set up replication

Two import methods are available. If you can upload the backup file to OSS, use Method 1. If your environment is constrained and direct streaming is preferable, use Method 2.

Method 1: Import a backup file from OSS

Upload the backup to an OSS bucket

The OSS bucket must be in the same region as the RDS instance.

Install ossutil:

yum install -y unzip
sudo -v ; curl https://gosspublic.alicdn.com/ossutil/install.sh | sudo bash
ossutil config

Upload the backup file:

ossutil -e <OSS_Endpoint> -i <your_AccessKeyId> -k <your_AccessKeySecret> cp <backup_file_name> oss://<bucket_name>/

Import the backup into RDS

  1. Go to the RDS Instances page, select a region, and click the instance ID.

  2. In the left navigation pane, click Native Replication.

  3. Click Import Full Data, configure the parameters, and click OK.

Category Parameter Description
Backup upload method (required) MySQL version Displayed automatically as 5.7 or 8.0. No configuration needed.
Import method Select Import from OSS.
OSS bucket Select the OSS bucket that contains your backup file.
OSS file name Select the backup file. If the file is in a subdirectory, enter the full path. Supported formats: .xb (xbstream), _qp.xb (QuickLZ), .xb.zst (zstd).
Automatic replication setup (optional) Auto replication building Turn on to automatically set up replication from the source database after the import. If you leave this off, set up replication manually after importing.
Source IP address IP address of the source self-managed database.
Source port Port of the source self-managed database.
Source account Account on the source database. Must have REPLICATION CLIENT and REPLICATION SLAVE permissions.
Account password Password for the source account.

Method 2: Stream the backup directly to RDS

Install the backup-helper tool and start the backup stream

# Install the backup-helper tool
wget -O backup-helper https://mysql-backup-helper.oss-cn-beijing.aliyuncs.com/v1.0.0-alpha/backup-helper && chmod +x backup-helper

# Start the backup stream (requires MySQL and the matching XtraBackup version to be installed)
./backup-helper --backup --mode=stream --host=<MySQL_IP> --port=<MySQL_port> --user=<MySQL_account> --password=<MySQL_password>

Import the stream into RDS

  1. Log on to the ApsaraDB RDS console, select a region, and click the instance ID.

  2. In the left navigation pane, click Native Replication.

  3. Click Import Full Data, configure the parameters, and click OK.

Category Parameter Description
Backup upload method (required) MySQL version Displayed automatically as 5.7 or 8.0. No configuration needed.
Import method Select Direct Stream Backup.
Source backup IP address IP address used for the backup stream.
Source backup port Port used for the backup stream. Default: 9999.
Automatic replication setup (optional) Auto replication building Turn on to automatically set up replication from the source database after the import. If you leave this off, set up replication manually after importing.
Source IP address IP address of the source self-managed database.
Source port Port of the source self-managed database.
Source account Account on the source database. Must have REPLICATION CLIENT and REPLICATION SLAVE permissions.
Account password Password for the source account.

Set up replication manually (if needed)

If you did not enable Auto replication building during import, or if the automatic setup failed and cannot recover, set up the replication link manually.

  1. Create a privileged account on the RDS instance.

  2. On the source self-managed database, create a replication account and grant the required permissions:

    -- Create a replication account. For production, restrict the allowed IP address instead of using '%'.
    -- Replace 'Test123!' with a strong password.
    CREATE USER 'replica'@'%' IDENTIFIED BY 'Test123!';
    
    -- Grant replication permissions
    GRANT REPLICATION SLAVE, REPLICATION CLIENT ON *.* TO 'replica'@'%';
    
    -- Apply the changes
    FLUSH PRIVILEGES;
  3. Log on to the RDS instance using the privileged account and run the following commands: MySQL 5.7

    -- Configure the replication source
    CHANGE MASTER TO
      MASTER_HOST='<source_IP>',
      MASTER_PORT='<source_port>',
      MASTER_USER='<replication_account>',
      MASTER_PASSWORD='<replication_account_password>',
      MASTER_AUTO_POSITION=1;
    
    -- Start replication
    START SLAVE;
    
    -- Check replication status
    SHOW SLAVE STATUS;

    MySQL 8.0

    -- Configure the replication source
    CHANGE REPLICATION SOURCE TO
      SOURCE_HOST='<source_IP>',
      SOURCE_PORT='<source_port>',
      SOURCE_USER='<replication_account>',
      SOURCE_PASSWORD='<replication_account_password>',
      SOURCE_AUTO_POSITION=1;
    
    -- Start replication
    START REPLICA;
    
    -- Check replication status
    SHOW REPLICA STATUS;

Verify replication status

On the Native Replication page of the RDS instance, check the replication status. When it shows Running, the replication link is active and data is being synchronized.

image

Disable native replication

When you're ready to cut over your application—or if you no longer need the replication—disable native replication to switch the instance back to read/write mode.

  1. Go to the RDS Instances page, select a region, and click the instance ID.

  2. In the left navigation pane, click Native Replication, then click Disable.

  3. Click OK.

Important

After you click OK, the replication link from the source database is terminated. The RDS instance reverts to a standard ApsaraDB RDS for MySQL instance and switches from read-only to read/write mode, allowing write operations.

API reference

Operation API Notes
Create an instance with native replication CreateDBInstance Set ExternalReplication to ON. The basic instance configuration must meet the prerequisites.
Set up a native replication link for an existing instance ImportUserBackupFile —

What's next