RE: GRANT CONNECT ON DATABASE

Поиск
Список
Период
Сортировка
От M Sarwar
Тема RE: GRANT CONNECT ON DATABASE
Дата
Msg-id DM4PR19MB597871C16367EC841DDC943FD3C62@DM4PR19MB5978.namprd19.prod.outlook.com
обсуждение исходный текст
Ответ на Re: GRANT CONNECT ON DATABASE  (Edwin UY <edwin.uy@gmail.com>)
Ответы Re: GRANT CONNECT ON DATABASE
Список pgsql-admin
We are using aws - rds.
All the discussions with respect to this thread are applicable to aws rds.
Thanks,
Sarwar




Sent from my Galaxy



-------- Original message --------
From: Edwin UY <edwin.uy@gmail.com>
Date: 6/10/24 8:18 AM (GMT-05:00)
To: Norbert Poellmann <np@ibu.de>
Cc: pgsql-admin@lists.postgresql.org
Subject: Re: GRANT CONNECT ON DATABASE

Don't think I can do this as this is AWS RDS?

On Mon, Jun 10, 2024 at 10:59 PM Norbert Poellmann <np@ibu.de> wrote:
On Mon, Jun 10, 2024 at 12:09:14PM +1200, Edwin UY wrote:
> Hi,
>
> A role was created as below:
> CREATE ROLE [blah] WITH NOLOGIN NOSUPERUSER INHERIT NOCREATEDB NOCREATEROLE
> NOREPLICATION VALID UNTIL 'infinity';
>
> Doesn't the following SQLs supposed to give the role login access?
>
> ALTER ROLE [blah] WITH ENCRYPTED PASSWORD 'blahpassword' ;
> GRANT CONNECT ON DATABASE [blahdb] TO [blahuser] ;
>
> We're trying to take the minimalist approach for a user access to have
> access to only the tables he has created and only to a specific database
> and schema.

Hi,

I would suggest, additionally, the strictest doorman for your database
is a record in ${data_directory}/pg_hba.conf, example:

# TYPE  DATABASE        USER            ADDRESS                 METHOD
hostssl   blahdb       blahuser       1.2.3.4/32            scram-sha-256

changes followed by a server reload.

cheers
Norbert Poellmann

>
> Regards,
> Ed

В списке pgsql-admin по дате отправления:

Предыдущее
От: Edwin UY
Дата:
Сообщение: Re: GRANT CONNECT ON DATABASE
Следующее
От: Edwin UY
Дата:
Сообщение: Re: GRANT CONNECT ON DATABASE