AWS Security ChangesHomeSearch

AWS dms: Clarify explicit vs include wildcard behavior in selection rules

Service: dms · 2026-09-27 · Documentation low

File: dms/latest/userguide/sc-selection-rules.md

Summary

Clarifies that wildcard characters are treated literally under rule-action explicit, adds examples for selecting all objects in SQL Server databases and Oracle schemas, and adds an Important note warning not to use "schema-name": "%" with explicit.

Security assessment

Purely functional documentation about object selection rule semantics and wildcard matching; it affects which tables/schemas are migrated but describes no vulnerability, credential handling, or auth change.

Evidence

+Do not use `"schema-name": "%"` with `"rule-action": "explicit"`. Under `explicit`, `%` is treated as a literal character, so the rule matches only a schema named literally `%` rather than every schema. Wildcards such as `%` work only with `include` and `exclude`.

Diff

diff --git a/dms/latest/userguide/sc-selection-rules.md b/dms/latest/userguide/sc-selection-rules.md
index 425cd9833..bd94d232f 100644
--- a//dms/latest/userguide/sc-selection-rules.md
+++ b//dms/latest/userguide/sc-selection-rules.md
@@ -143 +143 @@ Value | Behavior | When to use it
-`"explicit"` | Selects exactly the named object. Every locator value, including `schema-name`, `database-name`, and any leaf key such as `table-name` or `scalar-function-name`, is matched as a literal string. Wildcard characters such as `%`, `_`, `[`, and `]` have no special meaning under `explicit`. | Use when you know the exact name of every object you want to act on.  
+`"explicit"` | Selects exactly the named object. Every locator value, including `schema-name`, `database-name`, and any leaf key such as `table-name` or `scalar-function-name`, is matched as a literal string. Wildcard characters such as `%`, `_`, `[`, and `]` have no special meaning under `explicit`. To match objects by a wildcard pattern, use `include` instead. | Use when you know the exact name of every object you want to act on.  
@@ -445,0 +446,59 @@ Select all objects in an Oracle schema by omitting the object-level key. Oracle
+Select all objects in a Microsoft SQL Server database by omitting `schema-name` from the object locator. The rule then widens to the whole database, and the locator contains only `server-name` and `database-name`. Selecting an entire database is supported for Microsoft SQL Server and SAP ASE (Sybase ASE) sources, which have a `database-name` level in the object locator.
+    
+    
+    {
+      "rules": [
+        {
+          "rule-type": "selection",
+          "rule-id": "1",
+          "rule-name": "rule_name",
+          "rule-action": "explicit",
+          "object-locator": {
+            "server-name": "source_server",
+            "database-name": "database_name"
+          }
+        }
+      ]
+    }
+
+Use `"rule-action": "include"` with `"schema-name": "%"` to match every schema in a Microsoft SQL Server database. Microsoft SQL Server requires `database-name` in the object locator.
+    
+    
+    {
+      "rules": [
+        {
+          "rule-type": "selection",
+          "rule-id": "1",
+          "rule-name": "rule_name",
+          "rule-action": "include",
+          "object-locator": {
+            "server-name": "source_server",
+            "database-name": "database_name",
+            "schema-name": "%"
+          }
+        }
+      ]
+    }
+
+###### Important
+
+Do not use `"schema-name": "%"` with `"rule-action": "explicit"`. Under `explicit`, `%` is treated as a literal character, so the rule matches only a schema named literally `%` rather than every schema. Wildcards such as `%` work only with `include` and `exclude`.
+
+Use `"rule-action": "include"` with `"schema-name": "%"` to match every schema (Oracle user). Oracle has no `database-name` level; the schema is the top container under `server-name`, so the object locator contains only `server-name` and `schema-name`.
+    
+    
+    {
+      "rules": [
+        {
+          "rule-type": "selection",
+          "rule-id": "1",
+          "rule-name": "rule_name",
+          "rule-action": "include",
+          "object-locator": {
+            "server-name": "source_server",
+            "schema-name": "%"
+          }
+        }
+      ]
+    }
+