Feature Recommendations for Logical Subscriptions

From: YeXiu <1518981153(at)qq(dot)com>
To: pgsql-hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Feature Recommendations for Logical Subscriptions
Date: 2025-04-08 02:04:08
Message-ID: tencent_DCDF626FCD4A556C51BE270FDC3047540208@qq.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Business Scenario:
The BI department requires real-time data from the operational database. In our current approach (on platform 14), we create a separate database within our department's real-time backup instance, set up a logical replication account, replicate required tables to this isolated database via logical replication, and then create a dedicated account with column-level permissions on specific tables for the BI department.

Recommendations:

1、Column Filtering Functionality‌: During implementation, some tables may contain sensitive data or long fields (e.g., text columns), while other fields in these tables still need to be replicated to another database or instance. Manually specifying individual columns becomes cumbersome, especially for tables with many fields, and complicates future field additions. We recommend adding a ‌column filtering feature‌ to logical replication to streamline this process.

2、Logical Replication Account Permissions‌:
Logical replication permissions should be decoupled from general database access permissions.
Proposed workflow:
Create a dedicated account with ‌logical replication privileges only‌.
Create a logical replication slot and grant this account access ‌only to the authorized replication slot‌.
This account would have no direct access to the database itself but could subscribe to and consume data from the permitted replication slot.
This approach allows securely providing the account to the BI department. They can subscribe to the replication slot and perform downstream processing independently, without risking exposure of unauthorized data.

YeXiu
1518981153(at)qq(dot)com

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Jacob Champion 2025-04-08 02:10:10 Re: [PoC] Federated Authn/z with OAUTHBEARER
Previous Message Hayato Kuroda (Fujitsu) 2025-04-08 02:00:35 RE: Fix 035_standby_logical_decoding.pl race conditions