OceanBase logo

OceanBase

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Resources

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS

OceanBase Cloud

OceanBase Database

Tools

Connectors and Middleware

QUICK START

OceanBase Cloud

OceanBase Database

BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Company

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

International - English
中国站 - 简体中文
日本 - 日本語
Sign In
Start on Cloud

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS
OceanBase CloudOceanBase Database
ToolsConnectors and Middleware
QUICK START
OceanBase CloudOceanBase Database
BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

Start on Cloud
编组
All Products
    • Databases
    • iconOceanBase Database
    • iconOceanBase Cloud
    • iconOceanBase Tugraph
    • iconInteractive Tutorials
    • iconOceanBase Best Practices
    • Tools
    • iconOceanBase Cloud Platform
    • iconOceanBase Migration Service
    • iconOceanBase Developer Center
    • iconOceanBase Migration Assessment
    • iconOceanBase Admin Tool
    • iconOceanBase Loader and Dumper
    • iconOceanBase Deployer
    • iconKubernetes operator for OceanBase
    • iconOceanBase Diagnostic Tool
    • iconOceanBase Binlog Service
    • Connectors and Middleware
    • iconOceanBase Database Proxy
    • iconEmbedded SQL in C for OceanBase
    • iconOceanBase Call Interface
    • iconOceanBase Connector/C
    • iconOceanBase Connector/J
    • iconOceanBase Connector/ODBC
    • iconOceanBase Connector/NET
icon

OceanBase Migration Service

V4.0.2Enterprise Edition

  • OMS Documentation
  • What's new
  • OMS Introduction
    • What is OMS?
    • Terms
    • OMS HA
    • Architecture
      • Overview
      • Hierarchical functional system
      • Basic components
    • Limits
  • Quick Start
    • Data migration process
    • Data synchronization process
  • Deploy OMS
    • Deployment types
    • System and network requirements
    • Memory and disk requirements
    • Environment preparations
    • Deploy OMS on a single node
    • Deploy OMS on multiple nodes in a single region
    • Deploy OMS on multiple nodes in multiple regions
    • Integrate the OIDC protocol to OMS to implement SSO
    • Scale-out OMS
    • Check the deployment
    • Deploy a time-series database (Optional)
  • OMS console
    • Log on to the OMS console
    • Overview
    • User center
      • Configure user information
      • Change your logon password
      • Log off
  • Data migration
    • Data migration overview
    • Migrate data from a MySQL database to a MySQL tenant of OceanBase Database
    • Migrate data from a MySQL tenant of OceanBase Database to a MySQL database
    • Migrate data from an Oracle database to a MySQL tenant of OceanBase Database
    • Migrate data from an Oracle tenant of OceanBase Database to an Oracle database
    • Migrate data from an Oracle database to an Oracle tenant of OceanBase Database
    • Migrate data from a DB2 LUW database to an Oracle tenant of OceanBase Database
    • Migrate data from an Oracle tenant of OceanBase Database to a DB2 LUW database
    • Migrate data from a DB2 LUW database to a MySQL tenant of OceanBase Database
    • Migrate data from a MySQL tenant of OceanBase Database to a DB2 LUW database
    • Migrate data within OceanBase Database
    • Active-active disaster recovery between OceanBase databases
    • Migrate data from a TiDB database to a MySQL tenant of OceanBase Database
    • Migrate data from a PostgreSQL database to a MySQL tenant of OceanBase Database
    • Manage data migration projects
      • View details of a data migration project
      • Change the name of a data migration project
      • View and modify migration objects
      • Use tags to manage data migration projects
      • Download and import the settings of migration objects
      • Start and pause a data migration project
      • Release and delete a data migration project
    • Features
      • DML filtering
      • Synchronize DDL operations
      • Configure matching rules for migration objects
      • Wildcard rules
      • Rename a database table
      • Use SQL conditions to filter data
      • Create and update a heartbeat table
      • Schema migration mechanisms
      • Schema migration operations
      • Set an incremental synchronization timestamp
    • Supported DDL operations and limits for synchronization
      • DDL synchronization from a MySQL database to a MySQL tenant of OceanBase Database
        • Overview of DDL synchronization from a MySQL database to a MySQL tenant of OceanBase Database
        • CREATE TABLE
          • Create a table
          • Create a column
          • Create an index or a constraint
          • Create partitions
        • Data type conversion
        • ALTER TABLE
          • Modify a table
          • Operations on columns
          • Operations on constraints and indexes
          • Operations on partitions
        • TRUNCATE TABLE
        • RENAME TABLE
        • DROP TABLE
        • CREATE INDEX
        • DROP INDEX
        • DDL incompatibilities between a MySQL database and a MySQL tenant of OceanBase Database
          • Overview
          • Incompatibilities of the CREATE TABLE statement
            • Incompatibilities of CREATE TABLE
            • Column types that are supported to create indexes or constraints
          • Incompatibilities of the ALTER TABLE statement
            • Incompatibilities of ALTER TABLE
            • Change the type of a constrained column
            • Change the type of an unconstrained column
            • Change the length of a constrained column
            • Change the length of an unconstrained column
            • Delete a constrained column
          • Incompatibilities of DROP INDEX operations
      • Synchronize DDL operations from a MySQL tenant of OceanBase Database to a MySQL database
      • DDL operations for synchronizing data from an Oracle database to an Oracle tenant of OceanBase Database
        • Overview
        • CREATE TABLE
          • Overview
          • Create a relational table
            • Create a relational table
            • Define columns of a relational table
          • Virtual columns
          • Regular columns
          • Create partitions
            • Overview
            • Partitioning
            • Subpartitioning
            • Composite partitioning
            • User-defined partitioning
            • Subpartition templates
          • Constraints
            • Overview
            • Inline constraints
            • Out-of-line constraints
        • CREATE INDEX
          • Overview
          • Normal indexes
        • ALTER TABLE
          • Modify tables
          • Modify, drop, and add table attributes
          • Column attribute management
            • Modify, drop, and add column attributes
            • Rename a column
            • Add columns and column attributes
            • Modify column attributes
            • Drop columns
          • Modify, drop, and add constraints
          • Partition management
            • Modify, drop, and add partitions
            • Drop partitions
            • Drop subpartitions
            • Add partitions and subpartitions
            • Modify partitions
            • Truncate partitions
        • DROP TABLE
        • COMMENT
        • RENAME OBJECT
        • TRUNCATE TABLE
        • DROP INDEX
        • DDL incompatibilities between an Oracle database and an Oracle tenant of OceanBase Database
          • Overview
          • Incompatibilities of CREATE TABLE
          • Incompatibilities in table modification operations
            • Incompatibilities of ALTER TABLE
            • Change the type of a constrained column
            • Change the type of an unconstrained column
            • Change the length of a constrained column
            • Change the length of an unconstrained column
      • Synchronize DDL operations from an Oracle tenant of OceanBase Database to an Oracle database
      • Synchronize DDL operations from an Oracle tenant of OceanBase Database to a DB2 LUW database
      • Synchronize DDL operations from a DB2 LUW database to a MySQL tenant of OceanBase Database
      • Synchronize DDL operations from a MySQL tenant of OceanBase Database to a DB2 LUW database
      • DDL synchronization between MySQL tenants of OceanBase Database
      • DDL synchronization between Oracle tenants of OceanBase Database
  • Data synchronization
    • Overview
    • Synchronize data from OceanBase Database to a Kafka instance
    • Synchronize data from an OceanBase database to a RocketMQ instance
    • Synchronize data from OceanBase Database to a DataHub instance
    • Synchronize data from an ODP logical table to a physical table in a MySQL tenant of OceanBase Database
    • Synchronize data from an ODP logical table to a DataHub instance
    • Synchronize data from an IDB logical table to a physical table in a MySQL tenant of OceanBase Database
    • Synchronize data from an IDB logical table to a DataHub instance
    • Synchronize data from a MySQL database to a DataHub instance
    • Synchronize data from an Oracle database to a DataHub instance
    • Manage data synchronization projects
      • View details of a data synchronization project
      • Change the name of a data synchronization project
      • View and modify synchronization objects
      • Use tags to manage data synchronization projects
      • Download and import the settings of synchronization objects
      • Start and pause a data synchronization project
      • Release and delete a data synchronization project
    • Features
      • DML filtering
      • Synchronize DDL operations
      • Rename databases and tables
      • Rename a topic
      • Use SQL conditions to filter data
      • Column filtering
      • Data formats
  • Create and manage data sources
    • Create data sources
      • Create an OceanBase data source
        • Create a physical OceanBase data source
        • Create a DBP data source
        • Create an IDB data source
      • Create a MySQL data source
      • Create an Oracle data source
      • Create a TiDB data source
      • Create a Kafka data source
      • Create a RocketMQ data source
      • Create a DataHub data source
      • Create a DB2 LUW data source
      • Create a PostgreSQL data source
    • Manage data sources
      • View data source information
      • Copy a data source
      • Edit a data source
      • Delete a data source
    • Create a database user
    • User privileges
    • Enable binlogs for the MySQL database
    • Minimum privileges required when an Oracle database serves as the source
  • OPS & Monitoring
    • O&M overview
    • Go to the overview page
    • Server
      • View server information
      • Update the quota
      • View server logs
    • Components
      • Store
        • Create a store
        • View details of a store
        • Update the configurations of a store
        • Start and pause a store
        • Delete a store
      • Incr-Sync
        • View details of an Incr-Sync component
        • Start and pause an Incr-Sync component
        • Migrate an Incr-Sync component
        • Update the configurations of an Incr-Sync component
        • Batch O&M
        • Delete an Incr-Sync component
      • Full-Import
        • View details of a Full-Import component
        • Pause a Full-Import component
        • Rerun and resume a Full-Import component
        • Update the configurations of a Full-Import component
        • Delete a Full-Import component
      • Full-Verification
        • View details of a Full-Verification component
        • Pause a Full-Verification component
        • Rerun and resume a Full-Verification component
        • Update the configurations of a Full-Verification component
        • Delete a Full-Verification component
    • O&M tickets
      • View details of an O&M ticket
      • Skip a ticket or sub-ticket
      • Retry a ticket or sub-ticket
  • System management
    • Permission Management
      • Overview
      • Manage users
      • Manage departments
    • Alert center
      • View project alerts
      • View system alerts
      • Manage alert settings
    • Associate with OCP
    • System parameters
      • Modify system parameters
      • Modify HA configurations
      • oblogproxy parameters
    • Operation audit
  • OMS O&M
    • Manage OMS services
    • OMS logs
    • Component O&M
      • O&M operations for the Supervisor component
      • CLI-based O&M for the Connector component
      • O&M operations for the Store component
    • Component tuning
      • Incr-Sync/Full-Import tuning
      • Oracle store tuning
    • Component parameters
      • Coordinator
      • Condition
      • Source Plugin
        • Overview
        • StoreSource
        • DataFlowSource
        • LogProxySource
        • KafkaSource (TiDB)
      • Sink Plugin
        • Overview
        • JDBC-Sink
        • KafkaSink
        • DatahubSink
        • RocketMQSink
      • Store parameters
        • Parameters of an Oracle store
        • Parameters of a DB2 store
        • Parameters of a MySQL store
        • Parameters of an OceanBase store
      • Parameters of the CM component
      • Parameters of the Supervisor component
    • Set throttling
  • Reference Guide
    • API Reference
      • Obtain the status of a migration project
      • Obtain the status of a synchronization project
    • OMS error codes
    • Alert Reference
      • oms_host_down
      • oms_host_down_migrate_resource
      • oms_host_threshold
      • oms_migration_failed
      • oms_migration_delay
      • oms_sync_failed
      • oms_sync_status_inconsistent
      • oms_sync_delay
  • Upgrade Guide
    • Overview
    • Upgrade OMS in single-node deployment mode
    • Upgrade OMS in multi-node deployment mode
    • FAQ
  • FAQ
    • General O&M
      • How do I modify the resource quotas of an OMS container?
      • How do I troubleshoot the OMS server down issue?
      • Deploy InfluxDB for OMS
      • Increase the disk space of the OMS host
    • Project diagnostics
      • How do I troubleshoot common problems with Oracle Store?
      • How do I perform performance tuning for Oracle Store?
      • What do I do when Oracle Store reports an error at the isUpdatePK stack?
      • What do I do when a store does not have data of the timestamp requested by the downstream?
      • What do I do when OceanBase Store failed to access an OceanBase cluster through RPC?
      • How do I use LogMiner to pull data from an Oracle database?
    • OPS & monitoring
      • What are the alert rules?
    • Data synchronization
      • FAQ about synchronization to a message queue
        • What are the strategies for ensuring the message order in incremental data synchronization to Kafka
    • Data migration
      • User privileges
        • What privileges do I need to grant to a user during data migration to or from an Oracle database?
      • Full migration
        • How do I query the ID of a checker?
        • How do I query log files of the Checker component of OMS?
        • How do I query the verification result files of the Checker component of OMS?
        • What do I do if the destination table does not exist?
        • What can I do when the full migration failed due to LOB fields?
        • What do I do if garbled characters cannot be written into OceanBase Database V3.1.2?
      • Incremental synchronization
        • How do I skip DDL statements?
        • How do I update whitelists and blacklists?
        • What are the application scope and limits of ETL?
    • Installation and deployment
      • How do I upgrade Store?
  • Release Note
    • V4.0
      • OMS V4.0.2
      • OMS V4.0.1
    • V3.4
      • OMS V3.4.0
    • V3.3
      • OMS V3.3.1
      • OMS V3.3.0
    • V3.2
      • OMS V3.2.2
      • OMS V3.2.1
    • V3.1
      • OMS V3.1.0
    • V2.1
      • OMS V2.1.2
      • OMS V2.1.0

Download PDF

OMS Documentation What's new What is OMS? Terms OMS HA Overview Hierarchical functional system Basic components Limits Data migration process Data synchronization process Deployment types System and network requirements Memory and disk requirements Environment preparations Deploy OMS on a single node Deploy OMS on multiple nodes in a single region Deploy OMS on multiple nodes in multiple regions Integrate the OIDC protocol to OMS to implement SSO Scale-out OMS Check the deployment Deploy a time-series database (Optional) Log on to the OMS console Overview Configure user information Change your logon password Log off Data migration overview Migrate data from a MySQL database to a MySQL tenant of OceanBase Database Migrate data from a MySQL tenant of OceanBase Database to a MySQL database Migrate data from an Oracle database to a MySQL tenant of OceanBase Database Migrate data from an Oracle tenant of OceanBase Database to an Oracle database Migrate data from an Oracle database to an Oracle tenant of OceanBase Database Migrate data from a DB2 LUW database to an Oracle tenant of OceanBase Database Migrate data from an Oracle tenant of OceanBase Database to a DB2 LUW database Migrate data from a DB2 LUW database to a MySQL tenant of OceanBase Database Migrate data from a MySQL tenant of OceanBase Database to a DB2 LUW database Migrate data within OceanBase Database Active-active disaster recovery between OceanBase databases Migrate data from a TiDB database to a MySQL tenant of OceanBase Database Migrate data from a PostgreSQL database to a MySQL tenant of OceanBase Database View details of a data migration project Change the name of a data migration project View and modify migration objects Use tags to manage data migration projects Download and import the settings of migration objects Start and pause a data migration project Release and delete a data migration project DML filtering Synchronize DDL operations Configure matching rules for migration objects Wildcard rules Rename a database table Use SQL conditions to filter data Create and update a heartbeat table Schema migration mechanisms Schema migration operations Set an incremental synchronization timestamp Synchronize DDL operations from a MySQL tenant of OceanBase Database to a MySQL database Synchronize DDL operations from an Oracle tenant of OceanBase Database to an Oracle database Synchronize DDL operations from an Oracle tenant of OceanBase Database to a DB2 LUW database Synchronize DDL operations from a DB2 LUW database to a MySQL tenant of OceanBase Database Synchronize DDL operations from a MySQL tenant of OceanBase Database to a DB2 LUW database DDL synchronization between MySQL tenants of OceanBase Database DDL synchronization between Oracle tenants of OceanBase Database Overview Synchronize data from OceanBase Database to a Kafka instance Synchronize data from an OceanBase database to a RocketMQ instance Synchronize data from OceanBase Database to a DataHub instance Synchronize data from an ODP logical table to a physical table in a MySQL tenant of OceanBase Database Synchronize data from an ODP logical table to a DataHub instance Synchronize data from an IDB logical table to a physical table in a MySQL tenant of OceanBase Database Synchronize data from an IDB logical table to a DataHub instance Synchronize data from a MySQL database to a DataHub instance Synchronize data from an Oracle database to a DataHub instance View details of a data synchronization project Change the name of a data synchronization project View and modify synchronization objects Use tags to manage data synchronization projects Download and import the settings of synchronization objects Start and pause a data synchronization project Release and delete a data synchronization project DML filtering Synchronize DDL operations Rename databases and tables Rename a topic Use SQL conditions to filter data Column filtering Data formats Create a MySQL data source Create an Oracle data source Create a TiDB data source Create a Kafka data source Create a RocketMQ data source Create a DataHub data source Create a DB2 LUW data source Create a PostgreSQL data source View data source informationCopy a data source Edit a data source
OceanBase logo

The Unified Distributed Database for the AI Era.

Follow Us
Products
OceanBase CloudOceanBase EnterpriseOceanBase Community EditionOceanBase seekdb
Resources
DocsBlogLive DemosTraining & Certification
Company
About OceanBaseTrust CenterLegalPartnerContact Us
Follow Us

© OceanBase 2026. All rights reserved

Cloud Service AgreementPrivacy PolicySecurity
Contact Us
Document Feedback
  1. Documentation Center
  2. OceanBase Migration Service
  3. V4.0.2
iconOceanBase Migration Service
V 4.0.2Enterprise Edition
Enterprise Edition
  • V 4.3.2
  • V 4.3.1
  • V 4.3.0
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.0.2
  • V 3.4.0
Community Edition
  • V 4.2.13
  • V 4.2.12
  • V 4.2.11
  • V 4.2.10
  • V 4.2.9
  • V 4.2.8
  • V 4.2.7
  • V 4.2.6
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.2.1
  • V 4.2.0
  • V 4.0.0
  • V 3.3.1

User privileges

Last Updated:2026-04-14 07:36:47  Updated
share
What is on this page
User privileges required when a MySQL database serves as the source database
User privileges required when a MySQL database serves as the destination database
User privileges required when a MySQL tenant of OceanBase Database serves as the source database
User privileges required when a MySQL tenant of OceanBase Database serves as the destination database
User privileges required when an Oracle database serves as the source or destination database
Privileges required for DBA users in Oracle databases earlier than 12c
Privileges required for non-DBA users in Oracle databases earlier than 12c
Privileges required for DBA users in Oracle Database 12c and later versions
Privileges required for non-DBA users in Oracle Database 12c and later versions
User privileges required when an Oracle tenant of OceanBase Database serves as the source database
User privileges required when an Oracle tenant of OceanBase Database serves as the destination database
User privileges required for an Oracle tenant of OceanBase Database V2.2.5 or V2.2.3
User privileges required for an Oracle tenant of OceanBase Database V2.2.7 or later versions
User privileges required when a DB2 LUW database serves as the source or destination database
User privileges required when a PostgreSQL database serves as the source database
User privileges required when a DataHub instance serves as the destination database
User privileges required when a Kafka database serves as the destination database
User privileges required when a RocketMQ database serves as the destination database

folded

share

Before you migrate data between databases by using OceanBase Migration Service (OMS), ensure that you have created a database user for each data source as the migration or synchronization user. These users must have the required privileges on the source and destination data sources.

User privileges required when a MySQL database serves as the source database

  • The database user must have the read privilege on the database from which data is migrated.

    GRANT SELECT ON <database_name>.* TO '<user_name>';
    
  • The database user must have the REPLICATION CLIENT and REPLICATION SLAVE privileges to perform incremental synchronization on a MySQL database.

    GRANT REPLICATION CLIENT, REPLICATION SLAVE ON *.* TO <user_name> WITH GRANT OPTION;
    

    If you select Allow OMS to automatically write heartbeat data into this instance during incremental synchronization to resolve the problem of high latency when no business data is written into the source database when you add a MySQL data source, OMS will create and update the drc.heartbeat table in the corresponding MySQL database. In that case, the MySQL database user must have the privileges to create and write the table. For more information about how to create a data source, see Create a MySQL data source.

    • Grant a database user the privilege to create the drc.heartbeat table:

      GRANT CREATE ON drc.heartbeat TO '<user_name>';
      
    • Grant a database user the privilege to write the drc.heartbeat table:

      GRANT INSERT, UPDATE, DELETE ON drc.heartbeat TO '<user_name>';
      
  • The database user must have the SELECT *.* privilege to synchronously pull incremental logs.

    GRANT SELECT ON *.* TO '<user_name>';
    

User privileges required when a MySQL database serves as the destination database

Run the following command to grant privileges to the user in the MySQL database:

GRANT <privilege_type> ON <database_name>.<table_name> TO '<user_name>'@'<host_name>' [WITH GRANT OPTION];
Parameter Description
privilege_type Grant SELECT, INSERT, UPDATE, and other operation privileges to the account. To grant all privileges to the account, set this parameter to ALL.
database_name The name of the database. To grant operation privileges on all databases to the account, set this parameter to an asterisk (*).
table_name The name of the table. To grant operation privileges on all tables to the account, set this parameter to an asterisk (*).
user_name The account to which privileges are granted.
host_name The host from which the account is allowed to log on to the database. To allow the account to log on to the database from any host, set this parameter to a percent sign (%).
WITH GRANT OPTION Grant the account the privilege to use the GRANT command. This parameter is optional.

User privileges required when a MySQL tenant of OceanBase Database serves as the source database

To synchronize data from a MySQL tenant of OceanBase Databases to a Kafka, RocketMQ, or DataHub instance, the migration user of the source database must have the following privileges:

  • SELECT privilege on the source business database.

  • SELECT privilege on the OceanBase and MySQL databases of the source tenant.

  • To synchronize incremental data, you need to create a user under the sys tenant of OceanBase Community Edition and grant the SELECT ON *.* privilege to the user.

    The username and password must be the same as those in the config.yaml file.

When you synchronize data from logical tables to physical tables in a MySQL tenant of OceanBase Database, the data source account is not used in the source tables. By default, the drc_user (password: drc_password) in the config.yaml file is used.

  • If you need incremental synchronization, you must create the drc account in the sys tenant and grant the SELECT privilege to the account. At the same time, you must create the same account in the business tenant to be synchronized and grant the SELECT privilege to the account.

  • If you need full synchronization, you must create the drc_user account under the business tenant to be synchronized and grant the SELECT privilege to the account.

User privileges required when a MySQL tenant of OceanBase Database serves as the destination database

To migrate data from a MySQL database to a MySQL tenant of OceanBase Database, the migration user in the MySQL tenant of OceanBase Database must have the following privileges:

  • SELECT, INSERT, UPDATE, and DELETE privileges on the business database.

  • The SELECT privilege on the OceanBase databases and MySQL databases.

User privileges required when an Oracle database serves as the source or destination database

The user privileges required for forward migration when an Oracle database serves as the source are the same as those required for reverse migration when an Oracle database serves as the destination. This section describes the privileges required for different roles in different versions of Oracle databases.

Note

The user privileges described in this topic are not the minimum privileges. You must grant the following privileges to users: SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY.
When an Oracle database serves as the source database, you can grant the minimum privileges to the migration user to improve security. For more information, see Minimum privileges required when an Oracle database serves as the source.

Privileges required for DBA users in Oracle databases earlier than 12c

If the environment allows you to assign the database administrator (DBA) role to the migration user and the Oracle database version is earlier than 12c, execute the following statement to grant the DBA privileges to the migration user.

GRANT DBA TO <user_name>;

Privileges required for non-DBA users in Oracle databases earlier than 12c

If the environment allows you to grant only the required privileges to the migration user and the Oracle database version is earlier than 12c, perform the following operations:

  1. Grant the CONNECT privilege.

    GRANT CONNECT TO <user_name>;
    
  2. Grant the migration user with the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges.

    GRANT CREATE SESSION, ALTER SESSION,
    SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <user_name>;
    
  3. Grant the LOGMINER privilege to the migration user.

    GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <user_name>;
    
  4. Grant the CREATE TABLE and UNLIMITED TABLESPACE privileges to the migration user.

    GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <user_name>;
    
  5. If the name of the schema to be migrated is the same as user_name, execute the following statement:

    GRANT CREATE SEQUENCE,CREATE VIEW TO <user_name>;
    

    If the name of the schema to be migrated is different from user_name, execute the following statement:

    GRANT CREATE ANY TABLE,CREATE ANY INDEX,DROP ANY TABLE,ALTER ANY TABLE,COMMENT ANY TABLE,
    DROP ANY INDEX,ALTER ANY INDEX,CREATE ANY SEQUENCE,ALTER ANY SEQUENCE,DROP ANY SEQUENCE,
    CREATE ANY VIEW,DROP ANY VIEW,INSERT ANY TABLE,DELETE ANY TABLE,UPDATE ANY TABLE TO <user_name>;
    

    You can also execute the following statement:

    GRANT CREATE ANY TABLE,CREATE ANY INDEX,DROP ANY TABLE,ALTER ANY TABLE,COMMENT ANY TABLE,
    DROP ANY INDEX,ALTER ANY INDEX,CREATE ANY SEQUENCE,ALTER ANY SEQUENCE,DROP ANY SEQUENCE,
    CREATE ANY VIEW,DROP ANY VIEW TO <user_name>;
    # Specify the table in the Oracle database to which data is to be migrated.
    GRANT DELETE, INSERT, UPDATE ON <database name>.<table name> TO <user_name>;
    

Privileges required for DBA users in Oracle Database 12c and later versions

If the environment allows you to assign the DBA role to the migration user and the version of the Oracle database is 12c or later, determine whether to use the pluggable database (PDB) of Oracle Database 12c, 18c, or 19c.

  • Non-PDB

    1. Execute the following statement to grant DBA privileges to the migration user:

      GRANT DBA TO <user_name>;
      
    2. Execute the following statement to grant the read privilege on the SYS.USER$ table to the migration user:

      GRANT SELECT ON SYS.USER$ TO <user_name>;
      
  • PDB

    If you migrate data from a PDB of Oracle Database 12c, 18c, or 19c to an Oracle tenant of OceanBase Database, a common user account is required for pulling data from the PDB.

    1. Execute the following statement to switch to the CDB$ROOT container:

      ALTER SESSION SET CONTAINER=CDB$ROOT;
      

      All common users can connect to the root container named CDB$ROOT and any accessible PDB and then perform related operations.

    2. Execute the following statement to grant DBA privileges to the migration user:

      GRANT DBA TO C##XXX CONTAINER=ALL;
      
    3. Execute the following statement to grant the read privilege on the SYS.USER$ table to the migration user:

      GRANT SELECT ON SYS.USER$ TO C##XXX CONTAINER=ALL;
      

Privileges required for non-DBA users in Oracle Database 12c and later versions

If the environment allows you to grant only the required privileges to the migration user and the version of the Oracle database is 12c or later, perform the following operations:

  • Non-PDB

    1. Grant the CONNECT privilege.

      GRANT CONNECT TO <user_name>;
      
    2. Execute the following statement to grant the read privilege on the SYS.USER$ table to the migration user:

      GRANT SELECT ON SYS.USER$ TO <user_name>;
      
    3. Grant the migration user with the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges.

      GRANT CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <user_name>;
      
    4. Grant the LOGMINER privilege to the migration user.

      GRANT LOGMINING TO <user_name>;
      GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <user_name>;
      
    5. Grant the CREATE TABLE and UNLIMITED TABLESPACE privileges to the migration user.

      GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <user_name>;
      
    6. If the name of the schema to be migrated is the same as user_name, execute the following statement:

      GRANT CREATE SEQUENCE,CREATE VIEW TO <user_name>;
      

      If the name of the schema to be migrated is different from user_name, execute the following statement:

      GRANT CREATE ANY TABLE,CREATE ANY INDEX,DROP ANY TABLE,ALTER ANY TABLE,COMMENT ANY TABLE,
      DROP ANY INDEX,ALTER ANY INDEX,CREATE ANY SEQUENCE,ALTER ANY SEQUENCE,DROP ANY SEQUENCE,
      CREATE ANY VIEW,DROP ANY VIEW,INSERT ANY TABLE,DELETE ANY TABLE,UPDATE ANY TABLE TO <user_name>;
      
  • PDB

    If you migrate data from a PDB of Oracle Database 12c, 18c, or 19c to an Oracle tenant of OceanBase Database, a common user account is required for pulling data from the PDB.

    1. Grant the CONNECT privilege.

      GRANT CONNECT TO <C##XXX> CONTAINER=ALL;
      
    2. Execute the following statement to grant the read privilege on the SYS.USER$ table to the migration user:

      GRANT SELECT ON SYS.USER$ TO <C##XXX> CONTAINER=ALL;
      
    3. Grant the migration user with the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges.

      GRANT CREATE SESSION, ALTER SESSION,
      SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <C##XXX> CONTAINER=ALL;
      
    4. Grant the LOGMINER privilege to the migration user.

      GRANT LOGMINING TO <C##XXX> CONTAINER=ALL;
      GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <C##XXX> CONTAINER=ALL;
      
    5. Grant the CREATE TABLE and UNLIMITED TABLESPACE privileges to the migration user.

      GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <C##XXX> CONTAINER=ALL;
      
    6. If the name of the schema to be migrated is the same as C##XXX, execute the following statement:

      GRANT CREATE SEQUENCE,CREATE VIEW TO <C##XXX> CONTAINER=ALL;
      

      If the name of the schema to be migrated is different from C##XXX, execute the following statement:

      GRANT CREATE ANY TABLE,CREATE ANY INDEX,DROP ANY TABLE,ALTER ANY TABLE,COMMENT ANY TABLE,
      DROP ANY INDEX,ALTER ANY INDEX,CREATE ANY SEQUENCE,ALTER ANY SEQUENCE,DROP ANY SEQUENCE,
      CREATE ANY VIEW,DROP ANY VIEW,INSERT ANY TABLE,DELETE ANY TABLE,UPDATE ANY TABLE TO <C##XXX> CONTAINER=ALL;
      

User privileges required when an Oracle tenant of OceanBase Database serves as the source database

To synchronize data from an Oracle tenant of OceanBase Database to a Kafka, RocketMQ, or DataHub instance:

  • For OceanBase Database earlier than V2.2.70, the migration user of the source must have the GRANT SELECT ON *.* TO <user_name>; privilege.

  • For OceanBase Database V2.2.70 and later, the migration user of the source must have the GRANT DBA TO <user_name>; privilege.

User privileges required when an Oracle tenant of OceanBase Database serves as the destination database

When an Oracle tenant of OceanBase Database serves as the destination, the required user privileges vary with the version of OceanBase Database.

User privileges required for an Oracle tenant of OceanBase Database V2.2.5 or V2.2.3

You can grant privileges to the migration user by using one of the following two methods:

  • Method 1

    • Execute the following statement to grant all privileges to the migration user. This method is simple but high-level privileges are granted.

      GRANT ALL PRIVILEGES ON *.* TO <user_name>;
      
  • Method 2

    1. Grant the SELECT privilege on system views in the sys tenant to the migration user.

      GRANT SELECT ON SYS.* TO <user_name>;
      
    2. Grant all kinds of privileges on business tables to the migration user. If multiple business databases exist, grant the privileges separately.

      GRANT SELECT,UPDATE,DELETE ON <db_name>.* TO <user_name>;
      GRANT CREATE,INDEX,ALTER ON <db_name>.* TO <user_name>;
      

User privileges required for an Oracle tenant of OceanBase Database V2.2.7 or later versions

You can grant privileges to the migration user by using one of the following two methods:

  • Method 1

    Execute the following statement to grant DBA privileges to the migration user. This method is simple but high-level privileges are granted.

    GRANT DBA TO <user_name>;
    
  • Method 2

    Grant all kinds of privileges on business tables to the migration user. If multiple business databases exist, grant the privileges separately.

    GRANT CONNECT TO <user_name>;
    GRANT CREATE SESSION, ALTER SESSION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <user_name>;
    GRANT CREATE ANY TABLE,INSERT ANY TABLE,UPDATE ANY TABLE,DELETE ANY TABLE TO <user_name>;
    

User privileges required when a DB2 LUW database serves as the source or destination database

The migration user must have the sysadm privilege when a DB2 LUW database serves as the source or destination.

User privileges required when a PostgreSQL database serves as the source database

During schema migration from a PostgreSQL database to a MySQL tenant of OceanBase Database, you must grant the SELECT privilege on tables and views to the migration user.

During incremental synchronization from a PostgreSQL database to a MySQL tenant of OceanBase Database, the privileges required for the migration user are as follows:

  • If the specified whitelist of tables to migrate contains wildcard characters, the migration user must be granted the superuser privilege. Otherwise, publication creation will fail and an error indicating no privilege will be returned. If no wildcard character is contained, the superuser privilege is not required.

  • The migration user must be granted the REPLICATION and LOGIN roles and the CREATE PUBLICATION privilege.

    • CREATE USER <user_name> REPLICATION LOGIN ENCRYPTED PASSWORD '<password>';

    • GRANT CREATE ON DATABASE <database_name> TO <user_name>;

  • The migration user must be the owner of the tables to migrate.

    // Create a role named replication_group.
    CREATE ROLE <replication_group>;  
    // Add the original owner of the tables to migrate to the replication_group role.
    GRANT <replication_group> TO <original_owner>;
    // Add the migration account to replication_group.
    GRANT <replication_group> TO <replication_user>;
    // Change the owner of the tables to migrate to the replication_group role.
    ALTER TABLE <table_name> OWNER TO <replication_group>;
    

If you select Allow OMS to automatically write heartbeat data into this instance during incremental synchronization. This resolves the problem of high latency when no business data is written in the source database when you add a PostgreSQL data source, OMS will create and update the oms_postgres_heartbeat table in the corresponding PostgreSQL database. In that case, the PostgreSQL database user must have the privileges to create and write the table. For more information about how to create a data source, see Create a PostgreSQL data source.

  • Grant a database user the privilege to create the drc.heartbeat table:

    GRANT CREATE ON SCHEMA public TO '<user_name>';
    
  • Grant a database user the privilege to write the drc.heartbeat table:

    GRANT INSERT, UPDATE, DELETE ON oms_postgres_heartbeat TO '<user_name>';
    

User privileges required when a DataHub instance serves as the destination database

DataHub performs authentication based on the endpoint, access key, or secret key.

A DataHub user must have the following privileges: GetProject, CreateTopic, ListTopic, GetTopic, ListShard, PutRecords, GetRecords, and GetCursor.

User privileges required when a Kafka database serves as the destination database

If the Kafka database requires authentication, see Create a Kafka data source.

To synchronize data to a Kafka database, the user must have privileges to perform the following operations:

  • Create and view topics.

  • View topic partition information.

  • Write records.

  • Read records.

User privileges required when a RocketMQ database serves as the destination database

To synchronize data to a RocketMQ database, the user must have privileges to perform the following operations:

  • Create and view topics.

  • View the information about the topic message queue.

  • Write records.

  • Read records.

Previous topic

Create a database user
Last

Next topic

Enable binlogs for the MySQL database
Next
What is on this page
User privileges required when a MySQL database serves as the source database
User privileges required when a MySQL database serves as the destination database
User privileges required when a MySQL tenant of OceanBase Database serves as the source database
User privileges required when a MySQL tenant of OceanBase Database serves as the destination database
User privileges required when an Oracle database serves as the source or destination database
Privileges required for DBA users in Oracle databases earlier than 12c
Privileges required for non-DBA users in Oracle databases earlier than 12c
Privileges required for DBA users in Oracle Database 12c and later versions
Privileges required for non-DBA users in Oracle Database 12c and later versions
User privileges required when an Oracle tenant of OceanBase Database serves as the source database
User privileges required when an Oracle tenant of OceanBase Database serves as the destination database
User privileges required for an Oracle tenant of OceanBase Database V2.2.5 or V2.2.3
User privileges required for an Oracle tenant of OceanBase Database V2.2.7 or later versions
User privileges required when a DB2 LUW database serves as the source or destination database
User privileges required when a PostgreSQL database serves as the source database
User privileges required when a DataHub instance serves as the destination database
User privileges required when a Kafka database serves as the destination database
User privileges required when a RocketMQ database serves as the destination database