PGD predefined roles
====================

PGD predefined roles are created when the BDR extension is installed.
After BDR extension is dropped from a database, the roles continue to
exist. You need to drop them manually if dropping is required. This
practice allows PGD to be used in multiple databases on the same
PostgreSQL instance without problem.

bdr_superuser
^^^^^^^^^^^^^

-  ALL PRIVILEGES ON ALL TABLES IN SCHEMA BDR

-  ALL PRIVILEGES ON ALL ROUTINES IN SCHEMA BDR

bdr_read_all_stats
^^^^^^^^^^^^^^^^^^

SELECT privilege on:

-  :ref:`bdr.conflict_history_summary <bdr.conflict_history_summary>`  

-  :ref:`bdr.ddl_epoch <bdr.ddl_epoch>`  

-  :ref:`bdr.ddl_replication <bdr.ddl_replication>`  

-  :ref:`bdr.global_consensus_journal_details <bdr.global_consensus_journal_details>`  

-  :ref:`bdr.global_lock <bdr.global_lock>`  

-  :ref:`bdr.global_locks <bdr.global_locks>`  

-  :ref:`bdr.local_consensus_state <bdr.local_consensus_state>`  

-  :ref:`bdr.local_node_summary <bdr.local_node_summary>`  

-  :ref:`bdr.node_config <bdr.node_config>`  

-  :ref:`bdr.node_catchup_info <bdr.node_catchup_info>`  

-  :ref:`bdr.node_conflict_resolvers <bdr.node_conflict_resolvers>`  

-  :ref:`bdr.node_group_config <bdr.node_group_config>`  

-  :ref:`bdr.node_local_info <bdr.node_local_info>`  

-  :ref:`bdr.node_peer_progress <bdr.node_peer_progress>`  

-  :ref:`bdr.node_slots <bdr.node_slots>`  

-  :ref:`bdr.node_summary <bdr.node_summary>`  

-  :ref:`bdr.replication_sets <bdr.replication_sets>`  

-  :ref:`bdr.sequences <bdr.sequences>`  

-  :ref:`bdr.stat_relation <bdr.stat_relation>`  

-  :ref:`bdr.stat_subscription <bdr.stat_subscription>`  

-  :ref:`bdr.subscription <bdr.subscription>`  

-  :ref:`bdr.subscription_summary <bdr.subscription_summary>`  

-  :ref:`bdr.tables <bdr.tables>`  

EXECUTE privilege on:

-  :ref:`bdr.bdr_version <bdr.bdr_version>`  

-  :ref:`bdr.bdr_version_num <bdr.bdr_version_num>`  

-  :ref:`bdr.decode_message_payload <bdr.decode_message_payload>`  

-  :ref:`bdr.get_global_locks <bdr.get_global_locks>`  

-  :ref:`bdr.get_raft_status <bdr.get_raft_status>`  

-  :ref:`bdr.get_relation_stats <bdr.get_relation_stats>`  

-  :ref:`bdr.get_slot_flush_timestamp <bdr.get_slot_flush_timestamp>`  

-  ``bdr.get_sub_progress_timestamp``

-  :ref:`bdr.get_subscription_stats <bdr.get_subscription_stats>`  

-  :ref:`bdr.peer_state_name <bdr.peer_state_name>`  

-  :ref:`bdr.show_subscription_status <bdr.show_subscription_status>`  

bdr_monitor
^^^^^^^^^^^

All privileges from ``bdr_read_all_stats`` .

Also, EXECUTE privilege on:

-  :ref:`bdr.monitor_group_versions <bdr.monitor_group_versions>`  

-  :ref:`bdr.monitor_group_raft <bdr.monitor_group_raft>`  

-  :ref:`bdr.monitor_local_replslots <bdr.monitor_local_replslots>`  

bdr_application
^^^^^^^^^^^^^^^

EXECUTE privilege on:

-  All functions for column_timestamps datatypes

-  All functions for CRDT datatypes

-  :ref:`bdr.alter_sequence_set_kind <bdr.alter_sequence_set_kind>`  

-  :ref:`bdr.create_conflict_trigger <bdr.create_conflict_trigger>`  

-  :ref:`bdr.create_transform_trigger <bdr.create_transform_trigger>`  

-  :ref:`bdr.drop_trigger <bdr.drop_trigger>`  

-  ``bdr.get_configured_camo_partner``

-  :ref:`bdr.global_lock_table <bdr.global_lock_table>`  

-  ``bdr.is_camo_partner_connected``

-  ``bdr.is_camo_partner_ready``

-  ``bdr.logical_transaction_status``

-  ``bdr.ri_fkey_trigger``

-  :ref:`bdr.seq_nextval <bdr.seq_nextval>`  

-  ``bdr.seq_currval``

-  ``bdr.seq_lastval``

-  :ref:`bdr.trigger_get_committs <bdr.trigger_get_committs>`  

-  :ref:`bdr.trigger_get_conflict_type <bdr.trigger_get_conflict_type>`  

-  :ref:`bdr.trigger_get_origin_node_id <bdr.trigger_get_origin_node_id>`  

-  :ref:`bdr.trigger_get_row <bdr.trigger_get_row>`  

-  :ref:`bdr.trigger_get_type <bdr.trigger_get_type>`  

-  :ref:`bdr.trigger_get_xid <bdr.trigger_get_xid>`  

-  ``bdr.wait_for_camo_partner_queue``

-  :ref:`bdr.wait_slot_confirm_lsn <bdr.wait_slot_confirm_lsn>`  

Many of these functions require additional privileges before you can use
them. For example, you must be the table owner to successfully execute
``bdr.alter_sequence_set_kind`` . These additional rules are described
with each specific function.

bdr_read_all_conflicts
^^^^^^^^^^^^^^^^^^^^^^

PGD logs conflicts into the :ref:`bdr.conflict_history <bdr.conflict_history>` 

table. Conflicts are visible only to table owners, so no extra
privileges are required to read the conflict history. If it’s useful to
have a user that can see conflicts for all tables, you can optionally
grant the role bdr_read_all_conflicts to that user.
