AWS RDS:如何将SELECT PG_BUFFERCACHE授予非aws超级用户

时间:2019-02-25 10:46:53

标签: postgresql amazon-web-services amazon-rds database-permissions

在安装https://www.postgresql.org/docs/9.1/pgbuffercache.html扩展之后,我希望可以从其他非超级用户访问pg_buffercache视图。

GRANT EXECUTE ON FUNCTION pg_buffercache_pages() TO test_monitoring;
GRANT SELECT ON pg_buffercache TO test_monitoring;

不起作用

根据https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.MasterAccounts.html RDS_SUPERUSER角色具有“ EXECUTE PG_BUFFERCACHE_PAGES(),SELECT PG_BUFFERCACHE”的权限

是否可以将相同的角色授予其他角色?

1 个答案:

答案 0 :(得分:2)

您可以为此创建一个函数和一个名为rds_superuser的视图:

CREATE FUNCTION buffercache_for_all()
   RETURNS TABLE (
      bufferid integer,
      relfilenode oid,
      reltablespace oid,
      reldatabase oid,
      relforknumber smallint,
      relblocknumber bigint,
      isdirty boolean,
      usagecount smallint,
      pinning_backends integer
   ) LANGUAGE sql SECURITY DEFINER SET search_path = pg_catalog AS
'SELECT p.bufferid,
       p.relfilenode,
       p.reltablespace,
       p.reldatabase,
       p.relforknumber,
       p.relblocknumber,
       p.isdirty,
       p.usagecount,
       p.pinning_backends
FROM public.pg_buffercache_pages() AS p(
        bufferid integer,
        relfilenode oid,
        reltablespace oid,
        reldatabase oid,
        relforknumber smallint,
        relblocknumber bigint,
        isdirty boolean,
        usagecount smallint,
        pinning_backends integer
     )';

CREATE VIEW buffercache_for_all AS SELECT * FROM buffercache_for_all();

然后将EXECUTE授予该功能,并将SELECT授予该权限,以允许任何人查看该信息。