OceanBase logo

OceanBase

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Resources

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS

OceanBase Cloud

OceanBase Database

Tools

Connectors and Middleware

QUICK START

OceanBase Cloud

OceanBase Database

BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Company

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

International - English
中国站 - 简体中文
日本 - 日本語
Sign In
Start on Cloud

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS
OceanBase CloudOceanBase Database
ToolsConnectors and Middleware
QUICK START
OceanBase CloudOceanBase Database
BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

Start on Cloud
编组
All Products
    • Databases
    • iconOceanBase Database
    • iconOceanBase Cloud
    • iconOceanBase Tugraph
    • iconInteractive Tutorials
    • iconOceanBase Best Practices
    • Tools
    • iconOceanBase Cloud Platform
    • iconOceanBase Migration Service
    • iconOceanBase Developer Center
    • iconOceanBase Migration Assessment
    • iconOceanBase Admin Tool
    • iconOceanBase Loader and Dumper
    • iconOceanBase Deployer
    • iconKubernetes operator for OceanBase
    • iconOceanBase Diagnostic Tool
    • iconOceanBase Binlog Service
    • Connectors and Middleware
    • iconOceanBase Database Proxy
    • iconEmbedded SQL in C for OceanBase
    • iconOceanBase Call Interface
    • iconOceanBase Connector/C
    • iconOceanBase Connector/J
    • iconOceanBase Connector/ODBC
    • iconOceanBase Connector/NET
icon

OceanBase Migration Service

V4.2.4Enterprise Edition

  • OMS Documentation
  • OMS Introduction
    • What is OMS?
    • Terms
    • OMS HA
    • Principles of Store
    • Principles of Full-Import and Incr-Sync
    • Data verification principles
    • Architecture
      • Overview
      • Hierarchical functional system
      • Basic components
    • OMS Oracle full data migration design and impact
    • Limitations
  • Quick Start
    • Data migration process
    • Data synchronization process
  • Deploy OMS
    • Deployment types
    • System and network requirements
    • Memory and disk requirements
    • Environment preparations
    • Deploy OMS on a single node
    • Deploy OMS on multiple nodes in a single region
    • Deploy OMS on multiple nodes in multiple regions
    • Integrate the OIDC protocol to OMS to implement SSO
    • Scale out
    • Check the deployment
    • Deploy a time-series database (Optional)
  • OMS console
    • Log in to the OMS console
    • Overview
    • User center
      • Configure user information
      • Change your login password
      • Log out
  • Data migration
    • Overview
    • Migrate data from a MySQL database to a MySQL-compatible tenant of OceanBase Database
    • Migrate data from a MySQL-compatible tenant of OceanBase Database to a MySQL database
    • Migrate data from an Oracle database to a MySQL-compatible tenant of OceanBase Database
    • Migrate data from an Oracle-compatible tenant of OceanBase Database to an Oracle database
    • Migrate data from an Oracle database to an Oracle-compatible tenant of OceanBase Database
    • Migrate data from a DB2 LUW database to an Oracle-compatible OceanBase database
    • Migrate data from an Oracle-compatible tenant of OceanBase Database to a DB2 LUW database
    • Migrate data from a DB2 LUW database to a MySQL-compatible tenant of OceanBase Database
    • Migrate data from a MySQL-compatible tenant of OceanBase Database to a DB2 LUW database
    • Migrate data within OceanBase Database
    • Create an active-active disaster recovery task in OceanBase Database
    • Migrate data from a TiDB database to a MySQL-compatible tenant of OceanBase Database
    • Migrate data from a PostgreSQL database to a MySQL-compatible tenant of OceanBase Database
    • Migrate data from a PolarDB-X 1.0 database to a MySQL-compatible tenant of OceanBase Database
    • Migrate incremental data from an Oracle-compatible tenant of OceanBase Database to a MySQL database
    • Manage data migration tasks
      • View details of a data migration task
      • Rename a data migration task
      • View and modify migration objects
      • Use tags to Manage data migration tasks
      • Perform batch operations on data migration tasks
      • Download and import settings of migration objects
      • View and modify the parameter configurations of a data migration task
      • Start and pause a data migration task
      • Release and delete a data migration task
    • Supported DDL operations and limits for synchronization
      • Synchronize DDL operations from a MySQL database to a MySQL-compatible tenant of OceanBase Database
        • Overview
        • CREATE TABLE
          • Create a table
          • Create a column
          • Create an index or a constraint
          • Create partitions
        • Data type conversion
        • ALTER TABLE
          • Modify a table
          • Operations on columns
          • Operations on constraints and indexes
          • Operations on partitions
        • TRUNCATE TABLE
        • RENAME TABLE
        • DROP TABLE
        • CREATE INDEX
        • DROP INDEX
        • DDL incompatibilities between a MySQL database and a MySQL-compatible tenant of OceanBase Database
          • Overview
          • Incompatibilities of the CREATE TABLE statement
            • Incompatibilities of CREATE TABLE
            • Column types that are supported to create indexes or constraints
          • Incompatibilities of the ALTER TABLE statement
            • Incompatibilities of ALTER TABLE
            • Change the type of a constrained column
            • Change the type of an unconstrained column
            • Change the length of a constrained column
            • Change the length of an unconstrained column
            • Delete a constrained column
          • Incompatibilities of DROP INDEX operations
      • Synchronize DDL operations from a MySQL-compatible tenant of OceanBase Database to a MySQL database
      • DDL operations for synchronizing data from an Oracle database to an Oracle-compatible tenant of OceanBase Database
        • Overview of DDL synchronization from Oracle to an Oracle-compatible tenant of OceanBase Database
        • CREATE TABLE
          • Overview
          • Create a relational table
            • Create a relational table
            • Define columns of a relational table
          • Virtual columns
          • Regular columns
          • Create partitions
            • Overview
            • Partitioning
            • Subpartitioning
            • Composite partitioning
            • User-defined partitioning
            • Subpartition templates
          • Constraints
            • Overview
            • Inline constraints
            • Out-of-line constraints
        • CREATE INDEX
          • Overview
          • Normal indexes
        • ALTER TABLE
          • Modify tables
          • Modify, drop, and add table attributes
          • Column attribute management
            • Modify, drop, and add column attributes
            • Rename a column
            • Add columns and column attributes
            • Modify column attributes
            • Drop columns
          • Modify, drop, and add constraints
          • Partition management
            • Modify, drop, and add partitions
            • Drop partitions
            • Drop subpartitions
            • Add partitions and subpartitions
            • Modify partitions
            • Truncate partitions
        • DROP TABLE
        • RENAME OBJECT
        • TRUNCATE TABLE
        • DROP INDEX
        • DDL incompatibilities between an Oracle database and an Oracle-compatible tenant of OceanBase Database
          • Overview
          • Incompatibilities of CREATE TABLE
          • Incompatibilities in table modification operations
            • Incompatibilities of ALTER TABLE
            • Change the type of a constrained column
            • Change the type of an unconstrained column
            • Change the length of a constrained column
            • Change the length of an unconstrained column
      • DDL synchronization from an Oracle-compatible tenant of OceanBase Database to an Oracle database
      • Synchronize DDL operations from a DB2 LUW database to an Oracle-compatible tenant of OceanBase Database
      • Synchronize DDL operations from an Oracle-compatible tenant of OceanBase Database to a DB2 LUW database
      • Synchronize DDL operations from a DB2 LUW database to a MySQL-compatible tenant of OceanBase Database
      • Synchronize DDL operations from a MySQL-compatible tenant of OceanBase Database to a DB2 LUW database
      • DDL synchronization between MySQL-compatible tenants of OceanBase Database
      • DDL synchronization between Oracle-compatible tenants of OceanBase Database
  • Data synchronization
    • Overview
    • Synchronize data from OceanBase Database to a Kafka instance
    • Synchronize data from OceanBase Database to a RocketMQ instance
    • Synchronize data from OceanBase Database to a DataHub instance
    • Synchronize data from an ODP logical table to a physical table in a MySQL-compatible tenant of OceanBase Database
    • Synchronize data from an ODP logical table to a DataHub instance
    • Synchronize data from an IDB logical table to a physical table in a MySQL-compatible tenant of OceanBase Database
    • Synchronize data from an IDB logical table to a DataHub instance
    • Synchronize data from a MySQL database to a DataHub instance
    • Synchronize data from an Oracle database to a DataHub instance
    • Manage data synchronization tasks
      • View details of a data synchronization task
      • Change the name of a data synchronization task
      • View and modify synchronization objects
      • Use tags to Manage data synchronization tasks
      • Perform batch operations on data synchronization tasks
      • Download and import the settings of synchronization objects
      • View and modify the parameter configurations of a data synchronization task
      • Start and pause a data synchronization task
      • Release and delete a data synchronization task
  • Create and manage data sources
    • Create data sources
      • Create an OceanBase data source
        • Create a physical OceanBase data source
        • Create an ODP data source
        • Create an IDB data source
        • Create a public cloud OceanBase data source
      • Create a MySQL data source
      • Create an Oracle data source
      • Create a TiDB data source
      • Create a Kafka data source
      • Create a RocketMQ data source
      • Create a DataHub data source
      • Create a DB2 LUW data source
      • Create a PostgreSQL data source
      • Create a PolarDB-X 1.0 data source
    • Manage data sources
      • View data source information
      • Copy a data source
      • Edit a data source
      • Delete a data source
    • Create a database user
    • User privileges
    • Enable binlogs for the MySQL database
    • Minimum privileges required when an Oracle database serves as the source
  • OPS & Monitoring
    • O&M overview
    • Go to the overview page
    • Server
      • View server information
      • Update the quota
      • View server logs
    • Components
      • Store
        • Create a store
        • View details of a store
        • Update the configurations of a store
        • Start and pause a store
        • Delete a store
      • Incr-Sync
        • View details of an Incr-Sync component
        • Start and pause an Incr-Sync component
        • Migrate an Incr-Sync component
        • Update the configurations of an Incr-Sync component
        • Batch O&M
        • Delete an Incr-Sync component
      • Full-Import
        • View details of a Full-Import component
        • Pause a Full-Import component
        • Rerun and resume a Full-Import component
        • Update the configurations of a Full-Import component
        • Delete a Full-Import component
      • Full-Verification
        • View details of a Full-Verification component
        • Pause a Full-Verification component
        • Rerun and resume a Full-Verification component
        • Update the configurations of a Full-Verification component
        • Delete a Full-Verification component
    • O&M Task
      • View O&M tasks
      • Skip a task or subtask
      • Retry a task or subtask
    • Parameter Template
      • Overview
      • Task Template
        • Create a task template
        • View and edit task templates
        • Copy and export a task template
        • Delete a task template
      • Component Template
        • Create a component template
        • View and edit component templates
        • Copy and export a component template
        • Delete a component template
      • Component parameters
        • Store parameters
        • Incr-Sync parameters
        • Full-Import parameters
        • Full-Verification parameters
        • CM parameters
        • Supervisor parameters
  • System management
    • Permission Management
      • Overview
      • Manage users
      • Manage departments
    • Alert center
      • View task alerts
      • View system alerts
      • Manage alert settings
    • Associate with OCP
    • System parameters
      • Modify system parameters
      • Modify HA configurations
      • oblogproxy parameters
    • Operation audit
  • Troubleshooting Guide
    • Manage OMS services
    • OMS logs
    • Component O&M
      • O&M operations for the Supervisor component
      • CLI-based O&M for the Connector component
      • O&M operations for the Store component
    • Component tuning
      • Incr-Sync/Full-Import tuning
      • Oracle store tuning
    • Set throttling
    • Store performance diagnostics
  • Reference Guide
    • Features
      • Configure DDL/DML synchronization
      • Supported DDL operations for synchronization
      • Rename a migration or synchronization object
      • Use SQL conditions to filter data
      • Set an incremental synchronization timestamp
      • Configure matching rules
      • Wildcard patterns supported for matching rules
      • Hidden column mechanisms
      • Instructions on schema migration
      • Create and update a heartbeat table
      • Change the topic
      • Column filtering
      • Data formats
    • API Reference
      • Overview
      • CreateProject
      • StartProject
      • StopProject
      • ResumeProject
      • ReleaseProject
      • DeleteProject
      • ListProjects
      • DescribeProject
      • DescribeProjectSteps
      • DescribeProjectStepMetric
      • DescribeProjectProgress
      • DescribeProjectComponents
      • ListProjectFullVerifyResult
      • StartProjectsByLabel
      • StopProjectsByLabel
      • CreateMysqlDataSource
      • CreateOceanBaseDataSource
      • CreateOceanBaseODPDataSource
      • CreatePolarDBDataSource
      • ListDataSource
      • CreateLabel
      • ListAllLabels
      • DeleteDataSource
      • CreateProjectModifyRecords
      • ListProjectModifyRecords
      • StopProjectModifyRecords
      • RetryProjectModifyRecords
      • CancelProjectModifyRecord
      • SubmitPreCheck
      • GetPreCheckResult
      • UpdateProjectConfig
    • Alert Reference
      • oms_host_down
      • oms_host_down_migrate_resource
      • oms_host_threshold
      • oms_migration_failed
      • oms_migration_delay
      • oms_sync_failed
      • oms_sync_status_inconsistent
      • oms_sync_delay
    • OMS error codes
    • SQL statements for querying table objects
    • Create a trigger
    • Change the log level for a PostgreSQL instance
    • Online DDL tools
    • Oracle supplemental logging
  • Upgrade Guide
    • Overview
    • Upgrade OMS in single-node deployment mode
    • Upgrade OMS in multi-node deployment mode
    • FAQ
  • FAQ
    • General O&M
      • How do I modify the resource quotas of an OMS container?
      • How do I troubleshoot the OMS server down issue?
      • Deploy InfluxDB for OMS
      • Increase the disk space of the OMS host
    • Task diagnostics
      • How do I troubleshoot common problems with Oracle Store?
      • How do I perform performance tuning for Oracle Store?
      • What do I do when Oracle Store reports an error at the isUpdatePK stack?
      • What do I do when a store does not have data of the timestamp requested by the downstream?
      • What do I do when OceanBase Store failed to access an OceanBase cluster through RPC?
      • How do I use LogMiner to pull data from an Oracle database?
    • OPS & monitoring
      • What are the alert rules?
    • Data synchronization
      • FAQ about synchronization to a message queue
        • What are the strategies for ensuring the message order in incremental data synchronization to Kafka
    • Data migration
      • User privileges
        • What privileges do I need to grant to a user during data migration to or from an Oracle database?
      • Full migration
        • How do I query the ID of a checker?
        • How do I query log files of the Checker component of OMS?
        • How do I query the verification result files of the Checker component of OMS?
        • What do I do if the destination table does not exist?
        • What can I do when the full migration failed due to LOB fields?
        • What do I do if garbled characters cannot be written into OceanBase Database V3.1.2?
      • Incremental synchronization
        • How do I skip DDL statements?
        • How do I migrate an Oracle database object whose name exceeds 30 bytes in length?
        • How do I update whitelists and blacklists?
        • What are the application scope and limits of ETL?
    • Installation and deployment
      • How do I upgrade Store?
  • Release Note
    • V4.2
      • OMS V4.2.4
      • OMS V4.2.3
      • OMS V4.2.2
      • OMS V4.2.1
      • OMS V4.2.0
    • V4.1
      • OMS V4.1.0
    • V4.0
      • OMS V4.0.2
      • OMS V4.0.1
    • V3.4
      • OMS V3.4.0
    • V3.3
      • OMS V3.3.1
      • OMS V3.3.0
    • V3.2
      • OMS V3.2.2
      • OMS V3.2.1
    • V3.1
      • OMS V3.1.0
    • V2.1
      • OMS V2.1.2
      • OMS V2.1.0

Download PDF

OMS Documentation What is OMS? Terms OMS HA Principles of Store Principles of Full-Import and Incr-Sync Data verification principles Overview Hierarchical functional system Basic components OMS Oracle full data migration design and impact Limitations Data migration process Data synchronization process Deployment types System and network requirements Memory and disk requirements Environment preparations Deploy OMS on a single node Deploy OMS on multiple nodes in a single region Deploy OMS on multiple nodes in multiple regions Integrate the OIDC protocol to OMS to implement SSO Scale out Check the deployment Deploy a time-series database (Optional) Log in to the OMS console Overview Configure user information Change your login password Log out Overview Migrate data from a MySQL database to a MySQL-compatible tenant of OceanBase Database Migrate data from a MySQL-compatible tenant of OceanBase Database to a MySQL database Migrate data from an Oracle database to a MySQL-compatible tenant of OceanBase Database Migrate data from an Oracle-compatible tenant of OceanBase Database to an Oracle database Migrate data from an Oracle database to an Oracle-compatible tenant of OceanBase Database Migrate data from a DB2 LUW database to an Oracle-compatible OceanBase database Migrate data from an Oracle-compatible tenant of OceanBase Database to a DB2 LUW database Migrate data from a DB2 LUW database to a MySQL-compatible tenant of OceanBase Database Migrate data from a MySQL-compatible tenant of OceanBase Database to a DB2 LUW database Migrate data within OceanBase Database Create an active-active disaster recovery task in OceanBase Database Migrate data from a TiDB database to a MySQL-compatible tenant of OceanBase Database Migrate data from a PostgreSQL database to a MySQL-compatible tenant of OceanBase Database Migrate data from a PolarDB-X 1.0 database to a MySQL-compatible tenant of OceanBase Database Migrate incremental data from an Oracle-compatible tenant of OceanBase Database to a MySQL database View details of a data migration task Rename a data migration task View and modify migration objects Use tags to Manage data migration tasks Perform batch operations on data migration tasks Download and import settings of migration objects View and modify the parameter configurations of a data migration task Start and pause a data migration task Release and delete a data migration task Synchronize DDL operations from a MySQL-compatible tenant of OceanBase Database to a MySQL database DDL synchronization from an Oracle-compatible tenant of OceanBase Database to an Oracle database Synchronize DDL operations from a DB2 LUW database to an Oracle-compatible tenant of OceanBase Database Synchronize DDL operations from an Oracle-compatible tenant of OceanBase Database to a DB2 LUW database Synchronize DDL operations from a DB2 LUW database to a MySQL-compatible tenant of OceanBase Database Synchronize DDL operations from a MySQL-compatible tenant of OceanBase Database to a DB2 LUW database DDL synchronization between MySQL-compatible tenants of OceanBase Database DDL synchronization between Oracle-compatible tenants of OceanBase Database Overview Synchronize data from OceanBase Database to a Kafka instance Synchronize data from OceanBase Database to a RocketMQ instance Synchronize data from OceanBase Database to a DataHub instance Synchronize data from an ODP logical table to a physical table in a MySQL-compatible tenant of OceanBase Database Synchronize data from an ODP logical table to a DataHub instance Synchronize data from an IDB logical table to a physical table in a MySQL-compatible tenant of OceanBase Database Synchronize data from an IDB logical table to a DataHub instance Synchronize data from a MySQL database to a DataHub instance Synchronize data from an Oracle database to a DataHub instance View details of a data synchronization task Change the name of a data synchronization task View and modify synchronization objects Use tags to Manage data synchronization tasks Perform batch operations on data synchronization tasks Download and import the settings of synchronization objects View and modify the parameter configurations of a data synchronization task Start and pause a data synchronization task Release and delete a data synchronization task Create a MySQL data source Create an Oracle data source Create a TiDB data source Create a Kafka data source Create a RocketMQ data source Create a DataHub data source Create a DB2 LUW data source Create a PostgreSQL data source Create a PolarDB-X 1.0 data source View data source information Copy a data source Edit a data source Delete a data source Create a database user User privileges Enable binlogs for the MySQL database Minimum privileges required when an Oracle database serves as the source O&M overview
OceanBase logo

The Unified Distributed Database for the AI Era.

Follow Us
Products
OceanBase CloudOceanBase EnterpriseOceanBase Community EditionOceanBase seekdb
Resources
DocsBlogLive DemosTraining & Certification
Company
About OceanBaseTrust CenterLegalPartnerContact Us
Follow Us

© OceanBase 2026. All rights reserved

Cloud Service AgreementPrivacy PolicySecurity
Contact Us
Document Feedback
  1. Documentation Center
  2. OceanBase Migration Service
  3. V4.2.4
iconOceanBase Migration Service
V 4.2.4Enterprise Edition
Enterprise Edition
  • V 4.3.2
  • V 4.3.1
  • V 4.3.0
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.0.2
  • V 3.4.0
Community Edition
  • V 4.2.13
  • V 4.2.12
  • V 4.2.11
  • V 4.2.10
  • V 4.2.9
  • V 4.2.8
  • V 4.2.7
  • V 4.2.6
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.2.1
  • V 4.2.0
  • V 4.0.0
  • V 3.3.1

User privileges

Last Updated:2026-04-14 07:36:49  Updated
share
What is on this page
Privileges required when a MySQL database is the source
Permissions required for a MySQL database as the destination
User privileges required when OceanBase Database is used as the source in MySQL compatible mode
User privileges required when OceanBase Database is used in MySQL compatible mode as the destination
Privileges required when an Oracle database serves as the source or target
Granting DBA privileges to a user in an Oracle database of a version earlier than 12c
Granting non-DBA privileges to a user in an Oracle database of a version earlier than 12c
Granting DBA privileges to a user in Oracle Database 12c and later
Granting privileges to non-DBA users in Oracle Database 12c and later
Privileges required for OceanBase Database in Oracle compatible mode as the source
Privileges for OceanBase Database in Oracle compatible mode as the destination
Privileges for OceanBase Database in Oracle compatible mode V2.2.5 or V2.2.3
Privileges for OceanBase Database in Oracle compatible mode V2.2.7 and later
Privileges required for DB2 LUW databases as source and target databases
Privileges required when a PostgreSQL database serves as the source
User privileges required for TiDB as the source database
DataHub as the destination
Permissions when Kafka is the target
Permissions required when RocketMQ is the destination

folded

share

Before you migrate a database by using OceanBase Migration Service (OMS), make sure that a database user is created for migration or synchronization in each data source. The user must have the required privileges in the source and destination data sources.

Privileges required when a MySQL database is the source

  • The database user must have read privileges on the database to be migrated. For MySQL V8.0, you must also grant the SHOW VIEW privilege.

    GRANT SELECT ON <database_name>.* TO '<user_name>';
    
  • When you synchronize incremental data from a MySQL database, the database user must have the REPLICATION CLIENT, REPLICATION SLAVE, and SELECT *.* privileges.

    GRANT REPLICATION CLIENT, REPLICATION SLAVE ON *.* TO '<user_name>' [WITH GRANT OPTION];
    GRANT SELECT ON *.* TO '<user_name>';
    

    Note

    • If the database user does not have read privileges on all tables in the source database, the task may fail.

    • WITH GRANT OPTION is an optional parameter.

    If you select Allow OMS to automatically write heartbeat data to this instance during incremental synchronization to address high latency in scenarios where there is no business write to the source database when you add a MySQL data source, OMS will create and update the drc.heartbeat table in the corresponding MySQL database. In this case, the MySQL database user must have the privileges to create and write to tables. For more information, see Create and update a heartbeat table.

  • When you migrate data from a MySQL database to a MySQL compatible mode of OceanBase Database, if there is reverse incremental data, the migration user must have the CREATE, SELECT, INSERT, UPDATE, and DELETE privileges on the test database in the source database.

    GRANT CREATE,SELECT,INSERT,UPDATE,DELETE ON test.* TO '<user_name>';
    

Permissions required for a MySQL database as the destination

  • The database user must have the CREATE, CREATE VIEW, INSERT, UPDATE, and DELETE permissions on the destination database.

    GRANT <privilege_type> ON <database_name>.<table_name> TO '<user_name>'@'<host_name>' [WITH GRANT OPTION];
    
    Parameter Description
    privilege_type The operation permissions to grant to the account, such as CREATE, INSERT, and UPDATE. If you want to grant all permissions to the account, set this parameter to ALL.
    database_name The name of the database. If you want to grant all database operation permissions to the account, set this parameter to a star (*).
    table_name The name of the table. If you want to grant all table operation permissions to the account, set this parameter to a star (*).
    user_name The account to be authorized.
    host_name The host that allows the account to log in. If the account is allowed to log in from any host, set this parameter to a percent sign (%).
    WITH GRANT OPTION The permission to use the GRANT command. This parameter is optional.
  • The database user must have the TRIGGER permission.

    This permission is used to check whether a trigger exists in the destination database. If a trigger exists, it may cause data inconsistency.

    GRANT TRIGGER ON *.* TO '<user_name>';
    

    or

    GRANT TRIGGER ON <database_name>.* TO '<user_name>';
    

User privileges required when OceanBase Database is used as the source in MySQL compatible mode

When OceanBase Database is used as the source in MySQL compatible mode, the migration/synchronization user must have the following privileges:

  • When the destination is a message queue such as Kafka, DataHub, or RocketMQ, the user must have the SELECT privilege on the source database to be synchronized.

    When the destination is a database such as MySQL or OceanBase Database in MySQL compatible mode, the user must have the SELECT privilege on the source database to be migrated and the oceanbase database.

    GRANT SELECT ON <database_name>.* TO '<user_name>';
    GRANT SELECT ON oceanbase.* TO '<user_name>';
    

    Notice

    You must grant the SELECT privilege on the oceanbase database to the user only in OceanBase Database V4.0.0 and later.

  • In incremental data synchronization, you must read incremental log data and database object structure information. Therefore, you must create a user in the sys tenant of the source database and grant the SELECT ON *.* privilege to the user.

    GRANT SELECT ON <database_name>.* TO <drc_user>;
    
  • When you migrate data between OceanBase Database instances in MySQL compatible mode, if there is a reverse incremental, the migration user must have the CREATE, SELECT, INSERT, UPDATE, and DELETE privileges on the test database of the source database.

    GRANT CREATE,SELECT,INSERT,UPDATE,DELETE ON test.* TO '<user_name>';
    

User privileges required when OceanBase Database is used in MySQL compatible mode as the destination

When OceanBase Database is used in MySQL compatible mode as the destination, the migration user must have the following privileges:

  • The CREATE, CREATE VIEW, SELECT, INSERT, UPDATE, ALTER, INDEX, and DELETE privileges on the destination database.

    GRANT CREATE,CREATE VIEW,SELECT,INSERT,UPDATE,ALTER,INDEX,DELETE ON <database_name>.* TO '<user_name>';
    
  • The SELECT privilege on the entire tenant.

    GRANT SELECT ON *.* TO '<user_name>';
    
  • OceanBase Database V4.2.4 to V4.3.0 or V4.3.3 and later in MySQL compatible mode as the destination:

    • The migration user must have the trigger privilege to check whether triggers exist on the destination. If triggers exist, data inconsistency may occur.

    • If you select schema migration when you create a data migration task and the database tables contain foreign key constraints, the migration user must also have the REFERENCES privilege on the database where the tables referenced by the foreign key constraints are located.

    You can grant the trigger and REFERENCES privileges on the corresponding database or the global trigger and REFERENCES privileges.

    • Grant the trigger and REFERENCES privileges on the corresponding database:

      GRANT TRIGGER,REFERENCES ON <database_name>.* TO '<user_name>';
      
    • Grant the global trigger and REFERENCES privileges:

      GRANT TRIGGER,REFERENCES ON *.* TO '<user_name>';
      

Privileges required when an Oracle database serves as the source or target

The privileges required for forward migration when an Oracle database serves as the source and for reverse migration when it serves as the target are the same. After you create a user, the privileges required for different versions of an Oracle database and the user roles are described as follows.

Note

  • For an ADG standby database, the privileges might not take effect after they are granted. In this case, you need to run the ALTER SYSTEM FLUSH SHARED_POOL; command on the standby database to refresh the Shared Pool.

  • This topic provides the privileges required for migration, including SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY.
    When an Oracle database serves as the source, you can specify the privileges for the migration user to enhance security. For more information, see Minimum privileges required when an Oracle database serves as the source.

Granting DBA privileges to a user in an Oracle database of a version earlier than 12c

If your environment allows you to grant the DBA role to a migration user and the Oracle database version is earlier than 12c, you can execute the following statement to grant the DBA privileges to the migration user:

GRANT DBA TO <user_name>;

Granting non-DBA privileges to a user in an Oracle database of a version earlier than 12c

If your environment is cautious about granting privileges to a migration user and the Oracle database version is earlier than 12c, perform the following steps:

  1. Grant the CONNECT privilege.

    GRANT CONNECT TO <user_name>;
    
  2. Grant the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges to the migration user.

    GRANT CREATE SESSION, ALTER SESSION,
    SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <user_name>;
    
  3. Grant the LOGMINER privilege to the migration user.

    GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <user_name>;
    
  4. Grant the CREATE TABLE and UNLIMITED TABLESPACE privileges to the migration user.

    GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <user_name>;
    
  5. If the schema name to be migrated is the same as the user_name, execute the following statement:

    GRANT CREATE SEQUENCE, CREATE VIEW TO <user_name>;
    

    If the schema name to be migrated is different from the user_name, execute the following statement:

    GRANT CREATE ANY TABLE, CREATE ANY INDEX, DROP ANY TABLE, ALTER ANY TABLE, COMMENT ANY TABLE,
    DROP ANY INDEX, ALTER ANY INDEX, CREATE ANY SEQUENCE, ALTER ANY SEQUENCE, DROP ANY SEQUENCE,
    CREATE ANY VIEW, DROP ANY VIEW, INSERT ANY TABLE, DELETE ANY TABLE, UPDATE ANY TABLE TO <user_name>;
    

    You can also execute the following statement:

    GRANT CREATE ANY TABLE, CREATE ANY INDEX, DROP ANY TABLE, ALTER ANY TABLE, COMMENT ANY TABLE,
    DROP ANY INDEX, ALTER ANY INDEX, CREATE ANY SEQUENCE, ALTER ANY SEQUENCE, DROP ANY SEQUENCE,
    CREATE ANY VIEW, DROP ANY VIEW TO <user_name>;
    # Grant the DELETE, INSERT, and UPDATE privileges on the tables to be migrated to the migration user.
    GRANT DELETE, INSERT, UPDATE ON <database name>.<table name> TO <user_name>;
    

Granting DBA privileges to a user in Oracle Database 12c and later

If your environment allows you to grant the Database Administrator (DBA) role to a migration user and your Oracle database is of version 12c or later, you need to determine whether to use a pluggable database (PDB) of 12c, 18c, or 19c.

  • Non-PDB

    1. Execute the following statement to grant the DBA privilege to the migration user.

      GRANT DBA TO <user_name>;
      
    2. Execute the following statement to grant the migration user the SELECT privilege on the SYS.USER$ table.

      GRANT SELECT ON SYS.USER$ TO <user_name>;
      
  • PDB

    If you migrate an Oracle database of version 12c, 18c, or 19c to OceanBase Database and the source database is a PDB, the account used to pull the PDB must be a common user.

    1. Execute the following statement to switch to the root container.

      ALTER SESSION SET CONTAINER=CDB$ROOT;
      

      A common user can connect to the root container (named CDB$ROOT) and any PDB to which it has access and perform operations.

    2. Execute the following statement to grant the DBA privilege to the migration user.

      GRANT DBA TO C##XXX CONTAINER=ALL;
      
    3. Execute the following statement to grant the migration user the SELECT privilege on the SYS.USER$ table.

      GRANT SELECT ON SYS.USER$ TO C##XXX CONTAINER=ALL;
      

Granting privileges to non-DBA users in Oracle Database 12c and later

If your environment grants privileges to migration users cautiously and your Oracle database is of version 12c or later, perform the following steps:

  • Non-PDB

    1. Grant the CONNECT privilege.

      GRANT CONNECT TO <user_name>;
      
    2. Execute the following statement to grant the migration user the SELECT privilege on the SYS.USER$ table.

      GRANT SELECT ON SYS.USER$ TO <user_name>;
      
    3. Grant the migration user the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges.

      GRANT CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <user_name>;
      
    4. Grant the migration user the LOGMINER privilege.

      GRANT LOGMINING TO <user_name>;
      GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <user_name>;
      
    5. Grant the migration user the CREATE TABLE and UNLIMITED TABLESPACE privileges.

      GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <user_name>;
      
    6. If the name of the schema to be migrated is the same as user_name, execute the following statement:

      GRANT CREATE SEQUENCE, CREATE VIEW TO <user_name>;
      

      If the name of the schema to be migrated is different from user_name, execute the following statement:

      GRANT CREATE ANY TABLE, CREATE ANY INDEX, DROP ANY TABLE, ALTER ANY TABLE, COMMENT ANY TABLE,
      DROP ANY INDEX, ALTER ANY INDEX, CREATE ANY SEQUENCE, ALTER ANY SEQUENCE, DROP ANY SEQUENCE,
      CREATE ANY VIEW, DROP ANY VIEW, INSERT ANY TABLE, DELETE ANY TABLE, UPDATE ANY TABLE TO <user_name>;
      
  • PDB

    If you migrate an Oracle database of version 12c, 18c, or 19c to an Oracle tenant of OceanBase Database, the account to be pulled from the source database must be a common user.

    1. Grant the CONNECT privilege.

      GRANT CONNECT TO <C##XXX> CONTAINER=ALL;
      
    2. Execute the following statement to grant the migration user the SELECT privilege on the SYS.USER$ table.

      GRANT SELECT ON SYS.USER$ TO <C##XXX> CONTAINER=ALL;
      
    3. Grant the migration user the CREATE SESSION, ALTER SESSION, SELECT ANY TRANSACTION, SELECT ANY TABLE, and SELECT ANY DICTIONARY privileges.

      GRANT CREATE SESSION, ALTER SESSION,
      SELECT ANY TRANSACTION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO <C##XXX> CONTAINER=ALL;
      
    4. Grant the migration user the LOGMINER privilege.

      GRANT LOGMINING TO <C##XXX> CONTAINER=ALL;
      GRANT EXECUTE ON SYS.DBMS_LOGMNR TO <C##XXX> CONTAINER=ALL;
      
    5. Grant the migration user the CREATE TABLE and UNLIMITED TABLESPACE privileges.

      GRANT CREATE TABLE, UNLIMITED TABLESPACE TO <C##XXX> CONTAINER=ALL;
      
    6. If the name of the schema to be migrated is the same as C##XXX, execute the following statement:

      GRANT CREATE SEQUENCE, CREATE VIEW TO <C##XXX> CONTAINER=ALL;
      

      If the name of the schema to be migrated is different from C##XXX, execute the following statement:

      GRANT CREATE ANY TABLE, CREATE ANY INDEX, DROP ANY TABLE, ALTER ANY TABLE, COMMENT ANY TABLE, 
      DROP ANY INDEX, ALTER ANY INDEX, CREATE ANY SEQUENCE, ALTER ANY SEQUENCE, DROP ANY SEQUENCE,
      CREATE ANY VIEW, DROP ANY VIEW, INSERT ANY TABLE, DELETE ANY TABLE, UPDATE ANY TABLE TO <C##XXX> CONTAINER=ALL;
      

Privileges required for OceanBase Database in Oracle compatible mode as the source

When OceanBase Database in Oracle compatible mode is used as the source, the migration/synchronization user needs the following privileges:

  • For OceanBase Database in Oracle compatible mode V2.2.70 and earlier, the source migration user needs the GRANT SELECT ON *.* TO '<user_name>'; privilege.

  • For OceanBase Database in Oracle compatible mode V2.2.70 and later, the source migration user needs the GRANT DBA TO '<user_name>'; privilege.

    • For OceanBase Database in Oracle compatible mode V4.0.0 and later, the source migration user also needs the SELECT privilege on DBA_OB_ARCHIVELOG.

      GRANT SELECT ON DBA_OB_ARCHIVELOG TO '<user_name>';
      
    • For OceanBase Database in Oracle compatible mode V4.2.0 and later, the source migration user also needs the SELECT privilege on DBA_OB_TABLE_LOCATIONS.

      GRANT SELECT ON DBA_OB_TABLE_LOCATIONS TO '<user_name>';
      

Privileges for OceanBase Database in Oracle compatible mode as the destination

The privileges vary depending on the version of OceanBase Database in Oracle compatible mode as the destination.

Privileges for OceanBase Database in Oracle compatible mode V2.2.5 or V2.2.3

You can grant privileges to the migration user in the following two ways:

  • Method 1

    • Execute the following statement to grant all privileges to the migration user. This method is simple but grants extensive privileges.

      GRANT ALL PRIVILEGES ON *.* TO '<user_name>';
      
  • Method 2

    1. Grant the SELECT privilege on system views in the SYS schema to the migration user.

      GRANT SELECT ON SYS.* TO '<user_name>';
      
    2. Grant various privileges on business database tables to the migration user. If there are multiple business databases, grant privileges to each database separately.

      GRANT SELECT, UPDATE, DELETE ON <db_name>.* TO '<user_name>';
      GRANT CREATE, INDEX, ALTER ON <db_name>.* TO '<user_name>';
      

Privileges for OceanBase Database in Oracle compatible mode V2.2.7 and later

You can grant privileges to the migration user in the following two ways:

  • Method 1

    Execute the following statement. This method is simple but grants extensive privileges.

    GRANT DBA TO '<user_name>';
    
  • Method 2

    Grant various privileges on business database tables to the migration user. If there are multiple business databases, grant privileges to each database separately.

    GRANT CONNECT TO '<user_name>';
    GRANT CREATE SESSION, ALTER SESSION, SELECT ANY TABLE, SELECT ANY DICTIONARY TO '<user_name>';
    GRANT CREATE ANY TABLE, CREATE ANY INDEX, CREATE ANY VIEW, INSERT ANY TABLE, UPDATE ANY TABLE, ALTER ANY TABLE, DELETE ANY TABLE TO '<user_name>';
    

Privileges required for DB2 LUW databases as source and target databases

When you use DB2 LUW databases as source and target databases, the migration user must have the administrator (DBADM) privilege.

  1. Connect to the target database.

    db2 CONNECT TO <database_name>
    
  2. Grant the database administrator privilege to the migration user.

    db2 GRANT DBADM ON DATABASE TO USER <user_name>;
    

Privileges required when a PostgreSQL database serves as the source

When you migrate the schema of a PostgreSQL database to a MySQL compatible mode of OceanBase Database, you must grant the SELECT privilege on tables and views to the migration user.

When you incrementally synchronize data from a PostgreSQL database to a MySQL compatible mode of OceanBase Database, you must grant the following privileges to the migration user:

  • If the whitelist of the tables to be migrated contains wildcards, you must use a superuser. Otherwise, an error will be returned when you create a publication. If the whitelist does not contain wildcards, you can use a non-superuser.

  • You must have the REPLICATION and LOGIN roles and the CREATE PUBLICATION privilege.

    • CREATE USER <user_name> REPLICATION LOGIN ENCRYPTED PASSWORD '<password>';

    • GRANT CREATE ON DATABASE <database_name> TO <user_name>;

  • You must be the owner of the tables to be migrated.

    // Create a replication group.
    CREATE ROLE <replication_group>;  
    // Add the original owner of the tables to be migrated to the replication group.
    GRANT <replication_group> TO <original_owner>; 
    // Add the migration user to the replication group.
    GRANT <replication_group> TO <replication_user>; 
    // Change the owner of the tables to be migrated to the new replication group.
    ALTER TABLE <table_name> OWNER TO <replication_group>; 
    
  • If you select Allow OMS to automatically write heartbeat data to this instance to resolve high latency in scenarios where no business data is written to the source when you add a PostgreSQL data source, OMS will create and update the oms_postgres_heartbeat table in the corresponding PostgreSQL database. In this case, the PostgreSQL database user must have the privileges to create and write to tables. For more information, see Create and update a heartbeat table.

User privileges required for TiDB as the source database

The migration user must have the full SELECT privilege on the TiDB database.

GRANT SELECT ON *.* TO '<user_name>';

DataHub as the destination

DataHub authenticates based on the endpoint, access key, and secret key. For more information, see DataHub permission control.

The DataHub user must have the GetProject, CreateTopic, ListTopic, GetTopic, ListShard, PutRecords, GetRecords, and GetCursor permissions.

Permissions when Kafka is the target

If Kafka has authentication, see Create a Kafka data source.

When Kafka is the target, the synchronization user must have the following permissions:

  • Create and view Topics.

  • View Topic Partition information.

  • Write Records.

  • Read Records.

Permissions required when RocketMQ is the destination

When RocketMQ is the destination, the user must have the following permissions:

  • Create and view Topics

  • View Topic MessageQueue information

  • Write Records

  • Read Records

Previous topic

Create a database user
Last

Next topic

Enable binlogs for the MySQL database
Next
What is on this page
Privileges required when a MySQL database is the source
Permissions required for a MySQL database as the destination
User privileges required when OceanBase Database is used as the source in MySQL compatible mode
User privileges required when OceanBase Database is used in MySQL compatible mode as the destination
Privileges required when an Oracle database serves as the source or target
Granting DBA privileges to a user in an Oracle database of a version earlier than 12c
Granting non-DBA privileges to a user in an Oracle database of a version earlier than 12c
Granting DBA privileges to a user in Oracle Database 12c and later
Granting privileges to non-DBA users in Oracle Database 12c and later
Privileges required for OceanBase Database in Oracle compatible mode as the source
Privileges for OceanBase Database in Oracle compatible mode as the destination
Privileges for OceanBase Database in Oracle compatible mode V2.2.5 or V2.2.3
Privileges for OceanBase Database in Oracle compatible mode V2.2.7 and later
Privileges required for DB2 LUW databases as source and target databases
Privileges required when a PostgreSQL database serves as the source
User privileges required for TiDB as the source database
DataHub as the destination
Permissions when Kafka is the target
Permissions required when RocketMQ is the destination