Updated on 2024-04-11 GMT+08:00

Changing a Security Group

Scenarios

This section describes how to change the security group of a primary DB instance or read replica. For primary/standby DB instances, changing the security group of the primary DB instance will cause the security group of the standby DB instance to be changed as well.

Precautions

  • If you need to change the security group of a DB instance with read/write splitting enabled, contact customer service to apply for required permissions.
  • Changing the security group of a DB instance with read/write splitting enabled will also change the security group of its read replicas. The security group of the read replicas cannot be changed independently. Check whether the new security group meets the expectation to prevent impact on existing workloads.
  • You can add or modify rules for the security group associated with your DB instance, or delete the security group.

Managing Security Groups

  1. Log in to the management console.
  2. Click in the upper left corner and select a region and a project.
  3. Click in the upper left corner of the page and choose Databases > Relational Database Service.
  4. On the Instances page, click the DB instance or read replica.
  5. In the Connection Information area on the Basic Information page, click Manage next to the Security Group field.

    • You can select multiple security groups at a time. The security group rules will be applied based on the following sequence: the first security group associated will take precedence over those associated later, then the rule with the highest priority in that security group will be applied first.
    • To create a new security group, click Create Security Group.

    Using multiple security groups may impact the network performance. Selecting more than five security groups is not recommended.

    Figure 1 Managing security groups

  6. Click Yes to submit the modification.