Skip to content

From Aiven

Tested with: Aiven preset: offline fixtures only (URL detection, TLS, checklist) · zb migrate 0.1

Aiven services move to the matching Databasezy engine. PostgreSQL and MySQL can use continuous sync.

Aiven migration at a glance, from the migration source catalogue
Status Coming soon · phase 2
Target engines PostgreSQL , MySQL , Valkey , ClickHouse
How we read it Connection string
Continuous sync Yes, for PostgreSQL and MySQL
Provider preset aiven
  • A Databasezy instance of the matching engine, or use --create.
  • The service URI, and the egress addresses on the service’s allowed IP addresses.

Copy the Service URI from the service’s overview page in the Aiven console. Do not use a connection-pool URI: pools listen on another port and cannot serve pg_dump snapshots or replication. Add the egress addresses to Allowed IP addresses.

  • Download the Aiven CA certificate if the preflight cannot verify the source TLS chain.

The preset keeps sslmode=require (PostgreSQL) or adds ssl-mode=REQUIRED (MySQL). If preflight cannot verify the source’s TLS chain, download the project CA certificate from the Aiven console.

  1. Open the target PostgreSQL instance (create one first if you need to) and choose the Migrate in tab.
  2. Under Source, pick Connection string and paste the URL. The host is recognised as Aiven; you can also pick it from the provider list.
  3. Choose Copy and sync to keep the target current until cutover, or Copy for a one-off copy.
  4. Run Preflight and work through the checklist. Blocking items must be fixed before the copy starts.
  5. Start the copy and follow Copy and Verify. Mismatches are listed per table or collection.
  6. When the sync lag is low, stop writes and choose Cut over. The Report step keeps the timings and verification results.

For PostgreSQL sync, Aiven enables wal_level=logical and avnadmin has REPLICATION. avnadmin is not a superuser, so the migration publishes an explicit list of the copied tables (never FOR ALL TABLES); that works for tables avnadmin owns. Change the owner of other tables first (ALTER TABLE ... OWNER TO avnadmin), or run the migration as their owner. MySQL sync needs gtid_mode=ON and a user with REPLICATION SLAVE.

Aiven for Valkey targets Valkey with a key copy. Aiven for ClickHouse targets the ClickHouse engine, which is coming soon.

Verification compares what the engine exposes: row counts per table for SQL engines, document counts per collection for document engines, key counts for key-value engines. Mismatches are listed in zb migrate status <mig_id> and the Verify step. Run your application’s tests against the new instance before you switch traffic.

With copy and sync, the target keeps receiving changes after the copy. When zb migrate status reports ready_for_cutover (two lag samples in a row under 5 seconds):

  1. Stop writes to the source: maintenance mode, scale writers to zero, or revoke the application user.
  2. Run zb migrate cutover <mig_id> (or Cut over in the portal). The agent drains the last changes, copies sequence values (PostgreSQL), verifies again and stops replication. If the target cannot catch up in time, the cutover is abandoned and sync keeps running; nothing changes on either side.
  3. Point the application at the Databasezy connection string and resume writes. zb migrate status shows the measured downtime.

Schema changes are not replicated, so freeze migrations between the copy and cutover. Details: what happens at cutover.

Sync applies to PostgreSQL and MySQL targets only; other engines from this source are copy only.

A migration never deletes anything on the source. Until you decommission it, rolling back means pointing the application back at the source.

  • Before cutover: cancel with zb migrate cancel <mig_id>. The publication, replication slot or replication channel the migration created is removed.
  • After cutover: writes made on Databasezy are not on the source. For PostgreSQL, start the migration with --reverse-sync so the old database keeps receiving them after cutover and stays a valid fallback. Without it, copy the new data back with a migration in the other direction before you switch.

Some tables are owned by another role. Transfer ownership to avnadmin or run the migration as the owner.

Check that the source accepts connections from the egress addresses preflight prints, that the host is the public one and that the password has not been rotated. zb migrate --dry-run shows the exact URL that will be used after any rewrites.

Each item has a machine code and a fix. Nothing is written to the target until every blocking item is resolved; warnings do not block.

The source uses an extension Databasezy does not ship. Drop it on the source if it is unused, or exclude the objects that depend on it with --exclude.

Sync is blocked with pg.wal_level or pg.replica_identity

Section titled “Sync is blocked with pg.wal_level or pg.replica_identity”

Logical replication needs wal_level=logical on the source and a primary key (or REPLICA IDENTITY FULL) on every published table. Preflight lists the tables.

Sync is blocked on binlog or GTID settings

Section titled “Sync is blocked on binlog or GTID settings”

Continuous sync needs binlog_format=ROW, gtid_mode=ON, enforce_gtid_consistency=ON and a user with REPLICATION SLAVE and REPLICATION CLIENT. Preflight names whichever is missing.

For anything else, zb migrate status <mig_id> shows the failing step and its message. How migrations work describes every step.