---
title: "yb-voyager CLI"
url: "https://docs.yugabyte.com/stable/yugabyte-voyager/reference/yb-voyager-cli/"
---

# yb-voyager CLI

YugabyteDB Voyager CLI and SSL connectivity.

yb-voyager command line interface reference

yb-voyager is a command line executable for migrating databases from PostgreSQL to YugabyteDB. Offline migration from MySQL and Oracle is deprecated and will no longer be supported after October 13, 2026. Contact [Yugabyte Support](https://support.yugabyte.com/ "Yugabyte Support") for guidance on migration options.

## Syntax

```sh
yb-voyager [ <migration-step>... ] [ <arguments> ... ]
```

- *migration-step*: See [Commands](#commands "Commands")
- *arguments*: one or more arguments, separated by spaces.

### Command line help

To display the available online help, run:

```sh
yb-voyager --help
```

To display the available online help for any migration step, run:

```sh
yb-voyager [ <migration-step>... ] --help
```

### Version check

To verify the version of yb-voyager installed on your machine, run:

```sh
yb-voyager version
```

## Commands

The list of commands for various phases of migration are as follows:

- [Assess migration](/stable/yugabyte-voyager/reference/assess-migration "Assess migration")
- [Export schema](/stable/yugabyte-voyager/reference/schema-migration/export-schema/ "Export schema")
- [Analyze schema](/stable/yugabyte-voyager/reference/schema-migration/analyze-schema/ "Analyze schema")
- [Detect drift](/stable/yugabyte-voyager/reference/schema-migration/detect-drift/ "Detect drift")
- [Import schema](/stable/yugabyte-voyager/reference/schema-migration/import-schema/ "Import schema")
- [Export data](/stable/yugabyte-voyager/reference/data-migration/export-data/ "Export data")
- [Export data status](/stable/yugabyte-voyager/reference/data-migration/export-data/#export-data-status "Export data status")
- [Get data-migration-report](/stable/yugabyte-voyager/reference/data-migration/export-data/#get-data-migration-report "Get data-migration-report")
- [Export data from target](/stable/yugabyte-voyager/reference/data-migration/export-data/#export-data-from-target "Export data from target")
- [Import data](/stable/yugabyte-voyager/reference/data-migration/import-data/ "Import data")
- [Import data status](/stable/yugabyte-voyager/reference/data-migration/import-data/#import-data-status "Import data status")
- [Import data to source](/stable/yugabyte-voyager/reference/data-migration/import-data/#import-data-to-source "Import data to source")
- [Import data to source-replica](/stable/yugabyte-voyager/reference/data-migration/import-data/#import-data-to-source-replica "Import data to source-replica")
- [Import data file](/stable/yugabyte-voyager/reference/bulk-data-load/import-data-file/ "Import data file")
- [Finalize-schema-post-data-import](/stable/yugabyte-voyager/reference/schema-migration/finalize-schema-post-data-import/ "Finalize-schema-post-data-import")
- [Cutover to target](/stable/yugabyte-voyager/reference/cutover-archive/cutover/#cutover-to-target "Cutover to target")
- [Cutover to source](/stable/yugabyte-voyager/reference/cutover-archive/cutover/#cutover-to-source "Cutover to source")
- [Cutover to source-replica](/stable/yugabyte-voyager/reference/cutover-archive/cutover/#cutover-to-source-replica "Cutover to source-replica")
- [Cutover status](/stable/yugabyte-voyager/reference/cutover-archive/cutover/#cutover-status "Cutover status")
- [Archive changes](/stable/yugabyte-voyager/reference/cutover-archive/archive-changes "Archive changes")
- [End migration](/stable/yugabyte-voyager/reference/end-migration "End migration")
- [Compare performance](/stable/yugabyte-voyager/reference/compare-performance "Compare performance")

## SSL Connectivity

You can instruct yb-voyager to connect to the source or target database over an SSL connection. Connecting securely to PostgreSQL, MySQL, and YugabyteDB requires you to pass a similar set of arguments to yb-voyager. Oracle requires a different set of arguments.

### PostgreSQL/MySQL options

The following table summarizes the arguments and options you can pass to yb-voyager to establish an SSL connection for PostgreSQL or MySQL.

Argument

Description 

--source-ssl-mode Value of this argument determines whether an encrypted connection is established between yb-voyager and the database server; and whether the certificate of the database server is verified from a CA.  
**Options**

- disable: Only try a non-SSL connection.
- allow: First try a non-SSL connection; if that fails, try an SSL connection. (Not supported for MySQL.)
- prefer (default): First try an SSL connection; if that fails, try a non-SSL connection.
- require: Only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified.
- verify-ca: Only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA).
- verify-full: Only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate.

--source-ssl-cert  
\--source-ssl-key These two arguments specify names of the files containing SSL certificate and key, respectively. The `<cert, key>` pair forms the identity of the client. Note: If using [accelerated data export](/stable/yugabyte-voyager/migrate/migrate-steps/#accelerate-data-export-for-mysql-and-oracle "accelerated data export"), ensure that the keys are in the PKCS8 standard PEM format. 

--source-ssl-root-cert Specifies the path to a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. 

--source-ssl-crl Specifies the path to a file containing the SSL certificate revocation list (CRL). Certificates listed in this file, if it exists, will be rejected while attempting to authenticate the server's certificate. If using [accelerated data export](/stable/yugabyte-voyager/migrate/migrate-steps/#accelerate-data-export-for-mysql-and-oracle "accelerated data export"), this is not supported.

### Oracle options

The following table summarizes the arguments and options you can pass to yb-voyager to establish an SSL connection for Oracle:

| Argument           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
|--------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| --oracle-tns-alias | A TNS (Transparent Network Substrate) alias that is configured to establish a secure connection with the server is passed to yb-voyager. When you pass [--oracle-tns-alias](/stable/yugabyte-voyager/reference/schema-migration/export-schema/#arguments "--oracle-tns-alias"), you cannot use any other arguments to connect to your Oracle instance including [--source-db-schema](/stable/yugabyte-voyager/reference/schema-migration/export-schema/#arguments "--source-db-schema") and [--oracle-db-sid](/stable/yugabyte-voyager/reference/schema-migration/export-schema/#arguments "--oracle-db-sid"). Note: By default, the expectation is that the wallet files (.sso, .pk12, and so on) are in the TNS\_ADMIN directory (the one containing tnsnames.ora). If the wallet files are in a different directory, ensure that you update the wallet location in the `sqlnet.ora` file. If using [accelerated data export](/stable/yugabyte-voyager/migrate/migrate-steps/#accelerate-data-export-for-mysql-and-oracle "accelerated data export"), to specify a different wallet location, also create a `ojdbc.properties` file in the TNS\_ADMIN directory, and add the following: `oracle.net.wallet_location=(SOURCE=(METHOD=FILE)(METHOD_DATA=(DIRECTORY=/path/to/wallet)))`. |

### YugabyteDB options

The following table summarizes the arguments and options you can pass to yb-voyager to establish an SSL connection for YugabyteDB.

Argument

Description 

--target-ssl-mode Value of this argument determines whether an encrypted connection is established between yb-voyager and the database server; and whether the certificate of the database server is verified from a CA.  
**Options**

- disable: Only try a non-SSL connection.
- allow: First try a non-SSL connection; if that fails, try an SSL connection. (Not supported for MySQL.)
- prefer (default): First try an SSL connection; if that fails, try a non-SSL connection.
- require: Only try an SSL connection. If a root CA file is present, verify the certificate in the same way as if verify-ca was specified.
- verify-ca: Only try an SSL connection, and verify that the server certificate is issued by a trusted certificate authority (CA).
- verify-full: Only try an SSL connection, verify that the server certificate is issued by a trusted CA and that the requested server host name matches that in the certificate.

Only certain modes are supported by [export-data-from-target](/stable/yugabyte-voyager/reference/data-migration/export-data/#export-data-from-target "export-data-from-target"). 

--target-ssl-cert  
\--target-ssl-key These two arguments specify names of the files containing SSL certificate and key, respectively. The `<cert, key>` pair forms the identity of the client. These arguments are not supported by `export-data-from-target` when using the [YugabyteDB gRPC Connector](/stable/additional-features/change-data-capture/using-yugabytedb-grpc-replication/debezium-connector-yugabytedb/ "YugabyteDB gRPC Connector"). 

--target-ssl-root-cert Specifies the path to a file containing SSL certificate authority (CA) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. For `export data from target` with the [YugabyteDB gRPC Connector](/stable/additional-features/change-data-capture/using-yugabytedb-grpc-replication/debezium-connector-yugabytedb/ "YugabyteDB gRPC Connector"), this flag secures the internal RPC ports (7100/9100) independently of `--target-ssl-mode`, which controls only the YSQL (5433) connection. See [SSL mode options](/stable/yugabyte-voyager/reference/data-migration/export-data/#ssl-mode-options "SSL mode options"). 

--target-ssl-crl Specifies the path to a file containing the SSL certificate revocation list (CRL). Certificates listed in this file, if it exists, will be rejected while attempting to authenticate the server's certificate. This flag is not supported by `export-data-from-target`.
