Re: Is there something like a limited superuser to give to a db-assistant? - Mailing list pgsql-general

From Michael Paquier
Subject Re: Is there something like a limited superuser to give to a db-assistant?
Date
Msg-id CAB7nPqSLpLGXrmWHi+qw2K-kXTcpCQQUhg0n+5ZQvPzHtOH+1g@mail.gmail.com
Whole thread Raw
In response to Is there something like a limited superuser to give to a db-assistant?  (Andreas <maps.on@gmx.net>)
List pgsql-general
On Fri, Oct 25, 2013 at 10:53 AM, Andreas <maps.on@gmx.net> wrote:
> Hi,
>
> how can I give a db-assistant the rights to create and drop schemas, tables,
> views ... BUT keep him out of certain existing schemas and tables?
Depending on what you want to do, you will have to use a combination
GRANT and REVOKE to authorize and to restrict access to multiple
database objects:
http://www.postgresql.org/docs/9.3/static/sql-grant.html
http://www.postgresql.org/docs/9.3/static/sql-revoke.html

> Our DB got a wee bit komplex with about 400 schemas and 5000 tables.
> So it would get rather ugly having to alter the rights for every db-object
> one by one manually.
So... First grant the access to all the objects for this new user, and
then use revoke on each object individually you want to restrict for
him. It would be better to do that at the schema level perhaps...
However the risk here is to forget to restrict the access to some
objects... So for safety you should do it the other way around.
Regards,
--
Michael


pgsql-general by date:

Previous
From: "Tomas Vondra"
Date:
Subject: Re: Is there something like a limited superuser to give to a db-assistant?
Next
From: "Tomas Vondra"
Date:
Subject: Re: Need help how to manage a couple of daily DB copies.