Skip to content

Conversation

@shiyuhang0
Copy link
Member

First-time contributors' checklist

What is changed, added or deleted? (Required)

Which TiDB version(s) do your changes apply to? (Required)

Tips for choosing the affected version(s):

By default, CHOOSE MASTER ONLY so your changes will be applied to the next TiDB major or minor releases. If your PR involves a product feature behavior change or a compatibility change, CHOOSE THE AFFECTED RELEASE BRANCH(ES) AND MASTER.

For details, see tips for choosing the affected versions.

  • master (the latest development version)
  • v9.0 (TiDB 9.0 versions)
  • v8.5 (TiDB 8.5 versions)
  • v8.1 (TiDB 8.1 versions)
  • v7.5 (TiDB 7.5 versions)
  • v7.1 (TiDB 7.1 versions)
  • v6.5 (TiDB 6.5 versions)
  • v6.1 (TiDB 6.1 versions)
  • v5.4 (TiDB 5.4 versions)

What is the related PR or file link(s)?

  • This PR is translated from:
  • Other reference link(s):

Do your changes match any of the following descriptions?

  • Delete files
  • Change aliases
  • Need modification after applied to another branch
  • Might cause conflicts after applied to another branch

@ti-chi-bot ti-chi-bot bot added missing-translation-status This PR does not have translation status info. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Dec 16, 2025
@gemini-code-assist
Copy link

Summary of Changes

Hello @shiyuhang0, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces a suite of new documentation focused on establishing secure and efficient Private Link connections for TiDB Cloud's dataflow services. These guides provide detailed, step-by-step instructions for connecting TiDB Cloud to various external data sources, including AWS RDS, Alibaba Cloud RDS, AWS Confluent Dedicated clusters, and self-hosted Kafka clusters on AWS, all leveraging cloud-native private link services. The aim is to facilitate private, direct, and secure data transmission, improving both security posture and network performance for users integrating TiDB Cloud with their existing cloud infrastructure.

Highlights

  • New Private Link Connection Documentation: Introduced a comprehensive set of documentation for establishing Private Link connections from TiDB Cloud to various external data sources.
  • Support for AWS RDS and Alibaba Cloud RDS: Added detailed guides for setting up secure Private Link connections to both AWS RDS and Alibaba Cloud RDS instances.
  • Integration with AWS Confluent and Self-Hosted Kafka: Provided new documentation for connecting TiDB Cloud to AWS Confluent Dedicated clusters and self-hosted Kafka clusters on AWS via Private Link.
  • Overview and Management of Private Link Connections: Included an overview document explaining the Private Link Connection for Dataflow feature, its types, domain attachment, and general management steps via Console and CLI.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds several new documentation pages related to setting up Private Link connections for TiDB Cloud Dataflow services. The new documents cover connections to Alibaba Cloud RDS, AWS Confluent, AWS RDS, and self-hosted Kafka on AWS, along with a general overview page. My review focuses on improving clarity, correcting grammatical errors and typos, and ensuring consistency with the repository's style guide. I've provided suggestions to improve sentence structure, use consistent terminology, and fix formatting for better readability.

@gemini-code-assist
Copy link

Warning

Gemini encountered an error creating the review. You can try again by commenting /gemini review.

shiyuhang0 and others added 3 commits December 17, 2025 10:40
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@shiyuhang0 shiyuhang0 force-pushed the private-link-connection branch from 726c985 to ca176a2 Compare December 17, 2025 03:01
@hfxsd hfxsd self-assigned this Dec 17, 2025
@hfxsd hfxsd added translation/no-need No need to translate this PR. area/tidb-cloud This PR relates to the area of TiDB Cloud. and removed missing-translation-status This PR does not have translation status info. labels Dec 17, 2025
@shiyuhang0 shiyuhang0 changed the title Private link connection [wip] Private link connection Dec 17, 2025
@ti-chi-bot ti-chi-bot bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Dec 17, 2025
@ti-chi-bot
Copy link

ti-chi-bot bot commented Dec 17, 2025

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please ask for approval from hfxsd. For more information see the Code Review Process.
Please ensure that each of them provides their approval before proceeding.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

github-actions bot pushed a commit to hfxsd/pingcap-docsite-preview that referenced this pull request Dec 17, 2025
@shiyuhang0 shiyuhang0 force-pushed the private-link-connection branch from 6798c24 to 94b06af Compare December 17, 2025 04:33
@shiyuhang0 shiyuhang0 force-pushed the private-link-connection branch from 94b06af to a5d2ad4 Compare December 17, 2025 04:35
@shiyuhang0 shiyuhang0 force-pushed the private-link-connection branch from 7c91d4c to 4c5a5fa Compare December 23, 2025 08:53
hfxsd and others added 7 commits December 23, 2025 17:21
Improved instructions and terminology in the AliCloud RDS and AWS Confluent private link connection guides. Clarified prerequisites, step-by-step procedures, and updated language for consistency and accuracy.
Improved clarity, consistency, and accuracy in the documentation for connecting TiDB Cloud to Alibaba Cloud RDS, AWS Confluent, and AWS RDS via private link connections. Updates include more precise terminology, step-by-step instructions, and enhanced formatting for prerequisites and procedures. Added links to relevant cloud consoles and guides, and standardized naming conventions for private link connections.
Standardized terminology for Alibaba Cloud (formerly AliCloud) and improved prerequisite instructions in both Alibaba Cloud and AWS Kafka connection guides. Clarified placeholder usage for 'unique_name' and updated references to endpoint services for consistency and accuracy.
@shiyuhang0 shiyuhang0 force-pushed the private-link-connection branch from 7b2267c to d097da9 Compare December 24, 2025 05:34
shiyuhang0 and others added 2 commits December 25, 2025 11:13
Co-authored-by: xixirangrang <hfxsd@hotmail.com>
Adds beta status notes and clarifies documentation for Private Link Connections for Dataflow in TiDB Cloud. Improves instructions for AWS and Alibaba Cloud endpoint service setup, domain attachment, and management via console and CLI. Updates TOC to indicate beta status and enhances overall guidance for users.
github-actions bot pushed a commit to hfxsd/pingcap-docsite-preview that referenced this pull request Dec 26, 2025
Improved clarity and consistency in instructions for connecting to Confluent Cloud Dedicated clusters on AWS using private link connections. Updated phrasing for better readability, clarified steps for both console and CLI usage, and fixed internal documentation links.

# Connect to AWS Self-Hosted Kafka via Private Link Connection

The document describes how to connect to a self-hosted Kafka cluster in AWS, using AWS Endpoint Service private link connection.
Copy link
Collaborator

@qiancai qiancai Dec 26, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
The document describes how to connect to a self-hosted Kafka cluster in AWS, using AWS Endpoint Service private link connection.
This document describes how to connect a {{{ .essential }}} cluster to a self-hosted Kafka cluster in AWS using AWS Endpoint Service [private link connection](/tidb-cloud/serverless-private-link-connection.md).

Comment on lines +12 to +15
1. The private link connection connects to your endpoint service with bootstrap port, it returns broker addresses with different ports.
2. The private link connection connects to your endpoint service with broker addresses and ports.
3. Endpoint service forwards requests to your load balancers.
4. Load balancers forward requests to different Kafka brokers based on the port mapping.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. The private link connection connects to your endpoint service with bootstrap port, it returns broker addresses with different ports.
2. The private link connection connects to your endpoint service with broker addresses and ports.
3. Endpoint service forwards requests to your load balancers.
4. Load balancers forward requests to different Kafka brokers based on the port mapping.
1. The private link connection connects to your AWS Endpoint Service using the bootstrap broker address, which returns the addresses and ports of all Kafka brokers.
2. TiDB Cloud uses the returned broker addresses and ports to establish connections through the private link connection.
3. The AWS Endpoint Service forwards requests to your load balancers.
4. Load balancers route requests to the corresponding Kafka brokers based on port mapping.


## Prerequisites

- Ensure that you have the following permissions to set up a Kafka cluster in your own AWS account.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Ensure that you have the following permissions to set up a Kafka cluster in your own AWS account.
- Ensure that you have the following permissions to set up a Kafka cluster in your AWS account:

- Manage subnets
- Connect to EC2 nodes to configure Kafka nodes

- Ensure that you have the following authorization to set up a load balancer and endpoint service in your own AWS account.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Ensure that you have the following authorization to set up a load balancer and endpoint service in your own AWS account.
- Ensure that you have the following permissions to set up a load balancer and endpoint service in your AWS account:

- Manage load balancer
- Manage endpoint services

- {{{ .essential }}} information: confirm that your {{{ .essential }}} is active in AWS. Retrieve and save the following details for later use:
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- {{{ .essential }}} information: confirm that your {{{ .essential }}} is active in AWS. Retrieve and save the following details for later use:
- Ensure that your {{{ .essential }}} is active in AWS. Retrieve and save the following details for later use:

Comment on lines +39 to +41
1. In the [TiDB Cloud console](https://tidbcloud.com), navigate to the cluster overview page of the TiDB cluster, and then click **Settings** > **Networking** in the left navigation pane.
2. On the **Private Link Connection For Dataflow**, click **Create Private Link Connection**.
3. You can find the AWS account ID and available zones information.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
1. In the [TiDB Cloud console](https://tidbcloud.com), navigate to the cluster overview page of the TiDB cluster, and then click **Settings** > **Networking** in the left navigation pane.
2. On the **Private Link Connection For Dataflow**, click **Create Private Link Connection**.
3. You can find the AWS account ID and available zones information.
1. In the [TiDB Cloud console](https://tidbcloud.com), navigate to the cluster overview page of your TiDB cluster, and then click **Settings** > **Networking** in the left navigation pane.
2. In the **Private Link Connection For Dataflow** section, click **Create Private Link Connection**.
3. In the displayed dialog, you can find the AWS account ID and available zones.

- Account ID
- Availability Zones (AZ)

To view the the AWS account ID and available zones, do the following:
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
To view the the AWS account ID and available zones, do the following:
To view the AWS account ID and available zones, do the following:

- {{{ .essential }}} information: confirm that your {{{ .essential }}} is active in AWS. Retrieve and save the following details for later use:

- Account ID
- Availability Zones (AZ)
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Availability Zones (AZ)
- Availability Zones (AZs)

Comment on lines +21 to +24
- Manage EC2 nodes
- Manage VPC
- Manage subnets
- Connect to EC2 nodes to configure Kafka nodes
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
- Manage EC2 nodes
- Manage VPC
- Manage subnets
- Connect to EC2 nodes to configure Kafka nodes
- Manage EC2 instances
- Manage VPCs
- Manage subnets
- Connect to EC2 instances to configure Kafka nodes

Improved wording, consistency, and clarity in instructions for creating, attaching, and detaching private link connections in TiDB Cloud. Updated references to AWS and Alibaba Cloud consoles, refined step descriptions, and standardized terminology for better user guidance.
@ti-chi-bot
Copy link

ti-chi-bot bot commented Dec 26, 2025

@shiyuhang0: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
pull-verify ffc965d link true /test pull-verify

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

- [Connect via Private Endpoint with Alibaba Cloud](/tidb-cloud/set-up-private-endpoint-connections-on-alibaba-cloud.md)
- [Configure Firewall Rules for Public Endpoints](/tidb-cloud/configure-serverless-firewall-rules-for-public-endpoints.md)
- [TLS Connections to TiDB Cloud](/tidb-cloud/secure-connections-to-serverless-clusters.md)
- Private Link Connection ![BETA](/media/tidb-cloud/blank_transparent_placeholder.png)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

need beta?


> **Note:**
>
> The Private Link Connections for Dataflow feature is in beta. It might be changed without prior notice. If you find a bug, you can report an [issue](https://github.com/pingcap/tidb/issues) on GitHub.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

不要这个提醒


- Region match: the instance must reside in the same Alibaba Cloud region as your {{{ .essential }}} cluster.
- AZ (Availability Zone) availability: the availability zones must overlap with those of your {{{ .essential }}} cluster.
- Network accessibility: the instance must be accessible within the VPC, with an appropriately configured IP allowlist.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

这啥意思?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/tidb-cloud This PR relates to the area of TiDB Cloud. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. translation/no-need No need to translate this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants