Connect to Oracle AI Database@Google Cloud - Autonomous Database
Learn to create a connection to Oracle AI Database@Google Cloud - Autonomous Database in OCI GoldenGate.
Before you begin
Ensure that you:
-
Review how OCI GoldenGate connects to your sources and targets.
-
Depending on your Oracle GoldenGate version:
-
For Autonomous AI Database, Unlock the GGADMIN user.
-
Configure the required policies to enable secure Vault and Secrets access, such as use secrets, use vaults, and read secret-bundles. For more information, see Minimum recommended policies.
Create the connection
To create the connection:
-
From the OCI GoldenGate Overview page, select Connections.
You can also select Create Connection under the Get started section and skip to step 3.
-
On the Connections page, select Create Connection.
-
On the Create Connection page, complete the fields as follows:
-
For Name, enter a name for the connection.
-
(Optional) For Description, enter a description that helps you distinguish this connection from others.
-
(For GoldenGate on Multicloud only) Select your Subscription, and then complete the following fields.
-
From the Compartment dropdown, select the compartment in which the Resource Anchor resides.
-
Select the Multicloud partner region.
-
Select your Partner availability zone. The available options populate based on the selected Multicloud partner region.
-
-
For Compartment, select the compartment in which to create the connection.
-
For Type, select Oracle AI Database@Google Cloud - Autonomous Database from the dropdown.
-
Enter the Database connection string. If a connection string is not provided, you must provide a Database wallet or Wallet secret.
-
For Database username, enter the username to connect to the database with.
-
Select the Database user password secret. If located in a different compartment, use the dropdown to change compartments.
Note:
-
Secrets are credentials such as passwords, certificates, SSH keys, or authentication tokens that you use with OCI services. To create a secret, see Creating a secret. Ensure that you:
-
Select Manual secret generation.
-
Paste the credentials into Secret contents.
-
-
If you prefer not to use password secrets, ensure that you deselect Use secrets in vault in the Security section under Advanced Options, located at the bottom of this form.
-
When you need to update the Secret content, ensure that you:
-
Create a new Secret version using the Plain-Text template and provide the updated content. For more information, see Updating a Secret’s Content.
-
Refresh the connection to clear cached Secret content.
-
-
-
Expand Show advanced options. You can configure the following options:
-
Security
-
Deselect Use vault secrets you prefer not to use password secrets for this connection. If not selected:
-
Select Use Oracle-managed encryption key to leave all encryption key management to Oracle.
-
Select Use customer-managed encryption key to select a specific encryption key stored in your OCI Vault to encrypt your connection credentials.
-
-
-
Network connectivity
Select a Traffic routing method:
-
Shared endpoint, to share an endpoint with the assigned deployment. You must allow connectivity from the deployment's ingress IP.
-
Dedicated endpoint, for network traffic through a dedicated endpoint in the assigned subnet in your VCN. You must allow connectivity from this connection's ingress IPs.
Note: If a dedicated connection remains unassigned for seven days, then the service converts it to a shared connection.
Then, select a Session mode:
-
Direct, for RAC databases with SCAN listeners that return FQDNs, and for all other Oracle Database technologies.
-
Redirect, for RAC databases with SCAN listeners that return IP addresses only.
Note: In RAC deployments, SCAN listeners redirects a connection to a specific database node identified by either IP address or FQDN. It’s recommended to configure RAC with FQDN-based SCAN listeners.
For Dedicated endpoints, select the subnet through which to route network traffic.
-
-
-
Security attributes: Add security attributes to control access to this connection using Zero Trust Packet Routing (ZPR).
-
Tags: Add tags to organize your resources.
-
-
-
Select Create.
After the connection is created, it appears in the Connections list. Ensure that you assign the connection to a deployment to use it as a source or target in a replication.
Next steps
Known issues
Redirect session mode with SCAN listener connection doesn’t support TCPS and TLS
OCI GoldenGate doesn’t support connections that use Redirect session mode with Oracle Single Client Access Name (SCAN) using TCPS and TLS. TCP is supported.
Workaround: Configure a connection using the Direct session mode to an individual Real Application Cluster (RAC) node.