Hi all,
Sorry for the late reply.
The v1 patch was mainly intended to discuss whether `RELOAD` belongs
under `ALTER SYSTEM`, so I did not cover the privilege design in detail.
I had in mind a separate ACL for `ALTER SYSTEM` operations, allowing
privileges to be granted per operation. If we add more operations,
predefined roles may be too broad to allow fine-grained control.
> I'm pretty down on this proposal even without the privilege question.
> "There's more than one way to do it" isn't a great thing for
> security-relevant operations, and this surely is one.
>
> Also, I don't like the loss of an explainable scope for what
> ALTER SYSTEM does.
I agree with Tom's concerns about adding a second interface and blurring
the scope of the command. I also agree with Andreas about the maintenance
cost. `pg_reload_conf()` already provides the reload operation, and the
`ALTER SYSTEM` documentation explains how to request a reload.
> This lack of intellectual consistency would get ten times worse
> if we followed through on the idea of overloading ALTER SYSTEM
> with unrelated actions like log rotation and promotion.
Agreed. Log rotation and promotion were simply the first operations that
came to mind as possible fits for a broader command family. Adding just
those two would not give ALTER SYSTEM a coherent scope. Oracle has a much
broader ALTER SYSTEM command family, though. If PostgreSQL developed a
similarly broad family of instance-level operations, could that give the
command a clearer scope? But still, it would increase the overlap with
existing functions that concerns Tom, as well as the maintenance cost
Andreas noted.
Thanks everyone for the reviews.
Best regards,
Yuhang Qiu