Re: pg_basebackup issue

From: Adrian Klaver <adrian(dot)klaver(at)aklaver(dot)com>
To: chiru r <chirupg(at)gmail(dot)com>, "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>
Cc: John R Pierce <pierce(at)hogranch(dot)com>, Forums postgresql <pgsql-general(at)postgresql(dot)org>
Subject: Re: pg_basebackup issue
Date: 2017-04-23 04:10:12
Message-ID: 9308725f-2646-9554-d007-b0d642dec4b0@aklaver.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On 04/22/2017 08:04 PM, chiru r wrote:
> Use case: Want to control database privileges/default roles by creating
> roles instead of granting directly to users.
> So that we can manage database access control easily.

Which you can do. However, pg_basebackup is a cluster wide command not
tied a particular database, so database privileges do not apply. You can
still manage it by restricting the roles able to connect to
'replication' in pg_hba.conf and creating roles that match that have
only the replication attribute. It is why the replication attribute was
added to role creation.

>
> Thanks,
> Chiru
>
> On Sat, Apr 22, 2017 at 10:03 PM, David G. Johnston
> <david(dot)g(dot)johnston(at)gmail(dot)com <mailto:david(dot)g(dot)johnston(at)gmail(dot)com>> wrote:
>
> On Saturday, April 22, 2017, chiru r <chirupg(at)gmail(dot)com
> <mailto:chirupg(at)gmail(dot)com>> wrote:
>
> Thank you Adrian.
>
> It seems the code is allowing only who has Superuser/Replication
> role directly.
>
> Is there any possibility in future releases they allow both case
> A & B Users able to use pg_basebackup.
>
>
> It does not seem wise to introduce inheritance of such
> powerful capabilities when for many years now we have not done so.
> It seems like reality could be better documented but the present
> behavior should stay. I also find the original choice to be quite
> sane regardless.
>
> David J.
>
>

--
Adrian Klaver
adrian(dot)klaver(at)aklaver(dot)com

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Ron Ben 2017-04-23 10:31:29 Re: Not sure this should be asked here but...
Previous Message chiru r 2017-04-23 03:04:17 Re: pg_basebackup issue