Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Database Migration Service melindungi data Anda selama dan setelah migrasi. Fitur keamanan dan enkripsi berikut memastikan keamanan migrasi Anda:
Kunci enkripsi yang dikelola pelanggan (CMEK) mengenkripsi data dalam penyimpanan.
Metode enkripsi, seperti sertifikat SSL/TLS dan Private Service Connect, mengamankan koneksi jaringan antara database sumber dan tujuan.
Praktik Identity and Access Management (IAM) memastikan kontrol akses.
Migrasi homogen dan heterogen memiliki opsi keamanan yang berbeda. Untuk migrasi homogen, database tujuan mendukung CMEK secara native, sedangkan migrasi heterogen memerlukan Database Migration Service untuk mengenkripsi data dalam penyimpanan selama konversi ke database sementara.
Pelajari lebih lanjut di bagian berikut:
Mengamankan migrasi homogen
Pilih skenario migrasi homogen untuk melihat opsi keamanan dan enkripsi
yang didukung migrasi Anda:
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda.
Anda dapat mengupload sertifikat enkripsi Anda sendiri saat membuat profil koneksi
sumber. Untuk informasi selengkapnya, lihat
Membuat profil koneksi sumber.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi.
Untuk mengetahui informasi selengkapnya, lihat
Autentikasi IAM.
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda.
Anda dapat mengupload sertifikat enkripsi Anda sendiri saat membuat profil koneksi sumber.
Untuk informasi selengkapnya, lihat
Membuat profil koneksi sumber.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk mengetahui informasi selengkapnya, lihat
Autentikasi IAM.
PostgreSQL ke AlloyDB untuk PostgreSQL
CMEK
Anda dapat bermigrasi ke tujuan AlloyDB tempat Anda mengonfigurasi CMEK untuk mengamankan data. Untuk informasi selengkapnya, lihat
Tentang CMEK dalam dokumentasi AlloyDB.
Konektivitas jaringan aman
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda.
Anda dapat mengupload sertifikat enkripsi Anda sendiri saat membuat profil koneksi sumber.
Untuk informasi selengkapnya, lihat
Membuat profil koneksi sumber.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk informasi selengkapnya, lihat
Mengelola autentikasi IAM.
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda serta
metode lain yang mengakomodasi perbedaan dalam akses jaringan, seperti daftar IP yang diizinkan atau menggunakan tunnel SSH maju. Untuk informasi selengkapnya, lihat
Membuat profil koneksi.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk mengetahui informasi selengkapnya, lihat
Kontrol akses dengan IAM.
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda serta
metode lain yang mengakomodasi perbedaan dalam akses jaringan, seperti daftar IP yang diizinkan atau menggunakan tunnel SSH maju. Untuk mengetahui informasi selengkapnya, lihat
Membuat profil koneksi.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk mengetahui informasi selengkapnya, lihat
Kontrol akses dengan IAM.
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda serta
metode lain yang mengakomodasi perbedaan dalam akses jaringan, seperti daftar IP yang diizinkan atau menggunakan tunnel SSH maju. Untuk informasi selengkapnya, lihat
Menggunakan sertifikat SSL/TLS untuk mengenkripsi koneksi jaringan.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk mengetahui informasi selengkapnya, lihat
Kontrol akses dengan IAM.
Database Migration Service mendukung konektivitas SSL/TLS untuk migrasi Anda serta
metode lain yang mengakomodasi perbedaan dalam akses jaringan, seperti daftar IP yang diizinkan atau menggunakan tunnel SSH maju. Untuk informasi selengkapnya, lihat
Menggunakan sertifikat SSL/TLS untuk mengenkripsi koneksi jaringan.
IAM
Dengan IAM, Anda dapat mengontrol akses ke resource migrasi. Untuk mengetahui informasi selengkapnya, lihat
Kontrol akses dengan IAM.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-05 UTC."],[],[],null,["# Security and encryption\n\nDatabase Migration Service protects your data during and after migration. The following\nsecurity and encryption features ensure the safety of your migration:\n\n- Customer-managed encryption keys (CMEK) encrypt data at rest.\n- Encryption methods, such as SSL/TLS certificates and Private Service Connect, secure network connections between the source and destination databases.\n- Identity and Access Management (IAM) practices ensure access control.\n\nHomogeneous and heterogeneous migrations have different security options. For\nhomogeneous migrations, destination databases support CMEK natively while\nheterogeneous migrations require Database Migration Service to additionally encrypt\ndata at rest during conversion to a temporary database.\n\nLearn more in the sections that follow:\n\nSecure homogeneous migrations\n-----------------------------\n\nSelect your homogeneous migration scenario to view security and encryption\noptions that your migration supports: \n\n### MySQL to Cloud SQL for MySQL\n\n**CMEK**\n\nYou can migrate to Cloud SQL destinations where you configure CMEK to secure your data.\nFor more information, see\n[Use customer-managed encryption keys (CMEK)](/sql/docs/mysql/configure-cmek)\nin the Cloud SQL documentation.\n\n**Secure network connectivity**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration.\nYou can upload your own encryption certificates when you create the source\nconnection profile. For more information, see\n[Create a source connection profile](/database-migration/docs/mysql/create-source-connection-profile).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources.\nFor more information, see\n[IAM authentication](/sql/docs/mysql/iam-authentication). \n\n### PostgreSQL to Cloud SQL for PostgreSQL\n\n**CMEK**\n\nYou can migrate to Cloud SQL destinations where you configure CMEK to secure your data.\nFor more information, see\n[Use customer-managed encryption keys (CMEK)](/sql/docs/postgres/configure-cmek) in the Cloud SQL documentation.\n\n**Secure network connectivity**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration.\nYou can upload your own encryption certificates when you create the source connection profile.\nFor more information, see\n[Create a source connection profile](/database-migration/docs/postgres/create-source-connection-profile).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information see\n[IAM authentication](/sql/docs/postgres/iam-authentication). \n\n### PostgreSQL to AlloyDB for PostgreSQL\n\n**CMEK**\n\nYou can migrate to AlloyDB destinations where you configure CMEK to secure your data. For more information, see\n[About CMEK](/alloydb/docs/cmek) in the AlloyDB documentation.\n\n**Secure network connectivity**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration.\nYou can upload your own encryption certificates when you create the source connection profile.\nFor more information, see\n[Create a source connection profile](/database-migration/docs/postgresql-to-alloydb/create-source-connection-profile).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[Manage IAM authentication](/alloydb/docs/manage-iam-authn). \n\n### SQL Server to Cloud SQL for SQL Server\n\n**CMEK**\n\nYou can migrate to Cloud SQL destinations where you configure CMEK to secure your data.\nFor more information, see\n[Use customer-managed encryption keys (CMEK)](/sql/docs/sqlserver/configure-cmek)\nin the Cloud SQL documentation.\n\n**Migrate encrypted databases**\n\nDatabase Migration Service supports migrating encrypted columns. For more information, see\n[Use encrypted SQL Server backup files](/database-migration/docs/sqlserver/backup-file-encryption).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[IAM authentication](/sql/docs/sqlserver/iam-authentication)\n\nSecure heterogeneous migrations\n-------------------------------\n\nSelect your heterogeneous migration scenario to view security and encryption options that your migration supports: \n\n### Oracle to Cloud SQL for PostgreSQL\n\n**CMEK**\n\nDatabase Migration Service supports CMEK in the migration job to secure the data at rest.\nFor more information, see\n[Use customer-managed encryption keys (CMEK) for continuous migrations](/database-migration/docs/oracle-to-postgresql/cmek-for-migration-jobs).\n\n**Connectivity encryption**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration as well\nas other methods that accommodate differences in network access, such as IP\nallowlisting or using a forward SSH tunnel. For more information, see\n[Create connection profiles](/database-migration/docs/oracle-to-postgresql/create-connection-profiles).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[Access control with IAM](/database-migration/docs/oracle-to-postgresql/access-control). \n\n### Oracle to AlloyDB for PostgreSQL\n\n**CMEK**\n\nDatabase Migration Service supports CMEK in the migration job to secure the data at rest.\nFor more information, see\n[Use customer-managed encryption keys (CMEK) for continuous migrations](/database-migration/docs/oracle-to-alloydb/cmek-for-migration-jobs).\n\n**Connectivity encryption**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration as well\nas other methods that accommodate differences in network access, such as IP\nallowlisting or using a forward SSH tunnel. For more information, see\n[Create connection profiles](/database-migration/docs/oracle-to-alloydb/create-connection-profiles).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[Access control with IAM](/database-migration/docs/oracle-to-alloydb/access-control). \n\n### SQL Server to Cloud SQL for PostgreSQL\n\n**CMEK**\n\nDatabase Migration Service supports CMEK in the migration job to secure the data at rest.\nFor more information, see\n[Use customer-managed encryption keys (CMEK) for continuous migrations](/database-migration/docs/sqlserver-to-csql-pgsql/cmek-for-migration-jobs).\n\n**Connectivity encryption**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration as well\nas other methods that accommodate differences in network access, such as IP\nallowlisting or using a forward SSH tunnel. For more information, see\n[Use SSL/TLS certificates to encrypt network connections](/database-migration/docs/sqlserver-to-csql-pgsql/encrypt-connections-with-certificates).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[Access control with IAM](/database-migration/docs/sqlserver-to-csql-pgsql/access-control). \n\n### SQL Server to AlloyDB for PostgreSQL\n\n**CMEK**\n\nDatabase Migration Service supports CMEK in the migration job to secure the data at rest.\nFor more information, see\n[Use customer-managed encryption keys (CMEK) for continuous migrations](/database-migration/docs/sqlserver-to-alloydb/cmek-for-migration-jobs).\n\n**Connectivity encryption**\n\nDatabase Migration Service supports SSL/TLS connectivity for your migration as well\nas other methods that accommodate differences in network access, such as IP\nallowlisting or using a forward SSH tunnel. For more information, see\n[Use SSL/TLS certificates to encrypt network connections](/database-migration/docs/sqlserver-to-alloydb/encrypt-connections-with-certificates).\n\n**IAM**\n\nWith IAM, you can control access to your migration resources. For more information, see\n[Access control with IAM](/database-migration/docs/sqlserver-to-alloydb/access-control)."]]