From: Stephen Frost <sfrost@snowman.net>
To: Greg Smith <greg@2ndquadrant.com>
Cc: KaiGai Kohei <kaigai@ak.jp.nec.com>,
SELinux <selinux@tycho.nsa.gov>,
Robert Haas <robertmhaas@gmail.com>
Subject: Re: Report of PGcon2010
Date: Fri, 11 Jun 2010 11:41:17 -0400 [thread overview]
Message-ID: <20100611154117.GS21875@tamriel.snowman.net> (raw)
In-Reply-To: <4C125496.1060107@2ndquadrant.com>
[-- Attachment #1: Type: text/plain, Size: 1409 bytes --]
Greg, all,
* Greg Smith (greg@2ndquadrant.com) wrote:
> This pushes off the problem of how to keep labels consistent in the face
> of things like table changes to being a database superuser only task,
> not one you can delegate to other users.
As an additional side-note that might be relevant to this community,
I've been talking to some of the other PG developers (Tom Lane, Robert
Haas, etc) about adding more granularity to the PG role options to
eliminate the need to have an actual PG "super-user". There are still
some specific tasks which require super-user (in particular, the
"replication" user must be a super-user, the user which can issue
pg_start_backup/pg_stop_backup commands, etc), but if we make those into
separately tracked options, we could provide a system with no user
having the actual "super-user" bit set which would still be very usable.
I'm hoping to target that for 9.1, but I certainly can't make any
promises. One thing to note in all of this, as has likely been said
here already, right now this is just about all spare-time work by the PG
individuals and companies who are interested in it. Organizations
interested in this speaking up that they'd like to use it, or even
better sponsor work on it, in whatever way they can, would certainly
increase the availability of PG community resources for this project and
things like RLS being added to PG.
Thanks!
Stephen
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 197 bytes --]
next prev parent reply other threads:[~2010-06-11 15:41 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-06-11 5:48 Report of PGcon2010 KaiGai Kohei
[not found] ` <4C125496.1060107@2ndquadrant.com>
2010-06-11 15:41 ` Stephen Frost [this message]
2010-06-11 16:08 ` Xavier Toth
2010-06-11 16:12 ` Stephen Frost
2010-06-14 4:39 ` KaiGai Kohei
2010-06-14 4:17 ` KaiGai Kohei
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100611154117.GS21875@tamriel.snowman.net \
--to=sfrost@snowman.net \
--cc=greg@2ndquadrant.com \
--cc=kaigai@ak.jp.nec.com \
--cc=robertmhaas@gmail.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.