TiDB Cloud CLI Regions, Security, and Limitations
This reference describes current regions, authentication, platform, and preview boundaries for TiDB Cloud CLI. For file system regions and limitations, see TiDB Cloud Filesystem Regions and Limitations.
Supported regions
When using TiDB Cloud CLI, you need to configure a default region for CLI operations.
The following table lists the supported regions for TiDB Cloud CLI and shows which TiDB Cloud CLI services are available in each region.
If your configured region supports TiDB Cloud Starter but not TiDB Cloud Filesystem, you can manage Starter instances in that region. File system commands fail with an unsupported endpoint error.
Supported file system regions are built into each ti release. To use a file system in a region added after your installed version was released, upgrade ti. You cannot enable an unsupported region by specifying a service URL.
Credential requirements
TiDB Cloud API calls use Digest authentication. SQL HTTPS execution uses generated SQL username/password Basic authentication over TLS. These credentials are not interchangeable.
Security best practices
- Create TiDB Cloud API keys with only the access required for the workflow. Do not reuse a personal administrator key in unattended automation.
- Inject automation credentials from a CI secret store or runtime secret manager. Do not place credentials in source control, container images, shell scripts, or command-line arguments that can appear in process listings and shell history.
- Do not copy the complete
~/.ti/directory into an agent sandbox. For an existing file system, pass onlyTI_FS_TOKENandTI_REGION_CODE; useTI_FS_FILE_SYSTEM_IDonly as an optional assertion. - Use
--read-onlyfor SQL inspection by untrusted or exploratory agents. Use--adminonly for DDL or privilege management, and use--read-writeonly when data changes are intended. - Use
--dry-runbefore destructive control-plane operations. Keep~/.ti/credentials, resource credentials, and DB SQL credentials owner-readable only. - Review local operation logs before sharing diagnostics. The logs exclude SQL text, paths, payloads, and credential values, but command names, flag names, profile and region metadata, status codes, and operational timing can still be sensitive.
For file system tokens, mounts, Vault, and AI provider security, see Authorization, Manage File System Tokens, and Configure AI Providers for a File System.
Product limitations
- The TiDB Cloud CLI is in preview, and command contracts can change.
- Database management targets TiDB Cloud Starter instances, not other TiDB Cloud database plans.
- SQL execution accepts one statement per invocation.
- Read-write is the default SQL role; use explicit role flags in security-sensitive automation.
- Telemetry management commands are intentionally not implemented. Control telemetry through
~/.ti/.preferencesorTI_TELEMETRY; serverless-function deployment, Homebrew, and Scoop distribution are not implemented.