无法通过MSK Connect在RDS上配置Debezium Postgres连接器
问题
在AWS RDS PostgreSQL 11上配置MSK Connect的Debezium Postgres连接器时碰到权限问题:
- 拥有
rds_superuser角色的postgres用户没有REPLICATION权限 - 拿不到受保护的
rdsadmin密码,且postgres用户无法创建REPLICATION角色
连接器配置如下:
connector.class=io.debezium.connector.postgresql.PostgresConnector publication.autocreate.mode=all_tables database.user=postgres database.dbname=postgres topic.creation.default.partitions=1 database.server.id=123456 tasks.max=1 database.history.kafka.bootstrap.servers=b-1.** database.history.kafka.topic=umg-kafka-postgres-history publication.name=umg-publication database.port=5432 plugin.name=pgoutput topic.creation.enabled=true key.converter.schemas.enable=true topic.prefix=pre-prod-rds database.hostname=** database.password=** value.converter.schemas.enable=true topic.creation.default.replication.factor=2 value.converter=org.apache.kafka.connect.json.JsonConverter
MSK Connect报错信息:
[Worker-07e12fb7b8fe79792] [2023-06-13 14:55:22,802] WARN [pre-prod-14|task-0] Unable to use pg_replication_slot_advance() function. The Postgres server is likely on an old RDS version or privileges are not correctly set (io.debezium.connector.postgresql.connection.PostgresReplicationConnection:376) [Worker-07e12fb7b8fe79792] org.postgresql.util.PSQLException: ERROR: must be superuser or replication role to use replication slots
解决方案
1. 给postgres用户添加REPLICATION权限(AWS RDS专属操作)
AWS RDS里rds_superuser本身不带REPLICATION权限,但可以用特殊SQL命令给用户授权:
ALTER USER postgres WITH REPLICATION;
直接用你现有的postgres用户(带rds_superuser角色)登录数据库执行这条命令就行。
2. 检查并调整RDS参数组配置
打开RDS实例的参数组,确认以下参数配置正确:
wal_level设为logical(Debezium逻辑复制必须的)max_replication_slots设为足够的值(至少比你要创建的复制槽数量多,建议设5以上)max_wal_senders设为足够的值(建议5以上)
如果用的是默认参数组,得先创建自定义参数组修改这些配置,然后重启RDS实例生效。
3. 优化Debezium连接器配置(可选)
- 保留
plugin.name=pgoutput,这是PostgreSQL 10+推荐的逻辑复制插件,适配RDS环境 - 如果不需要同步所有表,把
publication.autocreate.mode改成filtered,手动指定要同步的表,减少权限依赖 - 确认
database.server.id是唯一值,别和其他复制源重复
4. 验证权限和复制槽创建
执行以下SQL验证postgres用户的权限:
SELECT rolname, rolreplication FROM pg_roles WHERE rolname='postgres';
如果rolreplication返回t,说明权限生效了。之后可以手动创建复制槽测试:
CREATE_REPLICATION_SLOT umg_slot LOGICAL pgoutput;
能成功创建的话,权限问题就解决了,重启MSK Connect连接器即可。
内容的提问来源于stack exchange,提问作者Niteesh Hegde
相关产品推荐
相关产品推荐

