PGD predefined roles
====================

PGD predefined roles are created when the BDR extension is installed.
After BDR extension is dropped from a database, the roles continue to
exist. You need to drop them manually if dropping is required.

bdr_superuser
^^^^^^^^^^^^^

This role is for an admin user that can manage anything PGD related. It
allows you to separate management of the database and table access.
Using it allows you to have a user that can manage the PGD cluster
without giving them PostgreSQL superuser privileges.

Privileges
^^^^^^^^^^

- ALL PRIVILEGES ON ALL TABLES IN SCHEMA BDR

- ALL PRIVILEGES ON ALL ROUTINES IN SCHEMA BDR

bdr_read_all_stats
^^^^^^^^^^^^^^^^^^

This role provides read access to most of the tables, views, and
functions that users or applications may need to observe the statistics
and state of the PGD cluster.

.. _privileges-1:

Privileges
^^^^^^^^^^

``SELECT`` privilege on:

- `bdr.autopartition_partitions <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-internal#bdrautopartition_partitions>`_  

- `bdr.autopartition_rules <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-internal#bdrautopartition_rules>`_  

- `bdr.ddl_epoch <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-internal#bdrddl_epoch>`_  

- `bdr.ddl_replication <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/pgd-settings#bdrddl_replication>`_  

- `bdr.global_consensus_journal_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrglobal_consensus_journal_details>`_  

- `bdr.global_lock <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrglobal_lock>`_  

- `bdr.global_locks <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrglobal_locks>`_  

- `bdr.group_camo_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrgroup_camo_details>`_  

- `bdr.local_consensus_state <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrlocal_consensus_state>`_  

- `bdr.local_node_summary <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrlocal_node_summary>`_  

- `bdr.node <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode>`_  

- `bdr.node_catchup_info <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_catchup_info>`_  

- `bdr.node_catchup_info_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_catchup_info_details>`_  

- `bdr.node_conflict_resolvers <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_conflict_resolvers>`_  

- `bdr.node_group <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_group>`_  

- `bdr.node_local_info <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_local_info>`_  

- `bdr.node_peer_progress <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_peer_progress>`_  

- `bdr.node_replication_rates <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_replication_rates>`_  

- `bdr.node_slots <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_slots>`_  

- `bdr.node_summary <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrnode_summary>`_  

- `bdr.replication_sets <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrreplication_sets>`_  

- ``bdr.replication_status``

- `bdr.sequences <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrsequences>`_  

- `bdr.stat_activity <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrstat_activity>`_  

- `bdr.stat_relation <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrstat_relation>`_  

- `bdr.stat_subscription <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrstat_subscription>`_  _deprecated_ 

- 
`bdr.state_journal_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#>`_  

- `bdr.subscription <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrsubscription>`_  

- `bdr.subscription_summary <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrsubscription_summary>`_  

- `bdr.tables <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrtables>`_  

- `bdr.taskmgr_local_work_queue <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrtaskmgr_local_work_queue>`_  

- `bdr.taskmgr_work_queue <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrtaskmgr_work_queue>`_  

- 
`bdr.worker_errors <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#>`_  _deprecated_ 

- `bdr.workers <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrworkers>`_  

- `bdr.writers <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrwriters>`_  

- `bdr.xid_peer_progress`  

EXECUTE privilege on:

- `bdr.bdr_edition`  _deprecated_ 

- `bdr.bdr_version <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrbdr_version>`_  

- `bdr.bdr_version_num <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrbdr_version_num>`_  

- `bdr.decode_message_payload <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrdecode_message_payload>`_  

- `bdr.get_consensus_status <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_consensus_status>`_  

- `bdr.get_decoding_worker_stat <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_decoding_worker_stat>`_  

- `bdr.get_global_locks <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrget_global_locks>`_  

-  `bdr.get_min_required_replication_slots <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrget_min_required_replication_slots>`_  

-  `bdr.get_min_required_worker_processes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrget_min_required_worker_processes>`_  

- `bdr.get_raft_status <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_raft_status>`_  

- `bdr.get_relation_stats <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_relation_stats>`_  

- `bdr.get_slot_flush_timestamp <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrget_slot_flush_timestamp>`_  

- `bdr.get_sub_progress_timestamp`  

- `bdr.get_subscription_stats <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_subscription_stats>`_  

- `bdr.lag_control <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrlag_control>`_  

-  `bdr.lag_history <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrlag_history>`_  

- `bdr.node_catchup_state_name <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrnode_catchup_state_name>`_  

- `bdr.node_kind_name <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrnode_kind_name>`_  

- `bdr.peer_state_name <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrpeer_state_name>`_  

- `bdr.show_subscription_status <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrshow_subscription_status>`_  

- `bdr.show_workers <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrshow_workers>`_  

- `bdr.show_writers <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrshow_writers>`_  

-  `bdr.stat_get_activity <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrstat_get_activity>`_  

- `bdr.wal_sender_stats <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrwal_sender_stats>`_  

-  `bdr.worker_role_id_name <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrworker_role_id_name>`_  

bdr_monitor
^^^^^^^^^^^

This role provides read access to any tables, views, and functions that
users or applications may need to monitor the PGD cluster. It includes
all the privileges of the :ref:`bdr_read_all_stats <bdr_read_all_stats>`  role.

.. _privileges-2:

Privileges
^^^^^^^^^^

All privileges from :ref:`bdr_read_all_stats <bdr_read_all_stats>`  plus the following additional
privileges:

``SELECT`` privilege on:

- `bdr.group_raft_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrgroup_raft_details>`_  

- `bdr.group_replslots_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrgroup_replslots_details>`_  

- `bdr.group_subscription_summary <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrgroup_subscription_summary>`_  

- `bdr.group_versions_details <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrgroup_versions_details>`_  

- `bdr.raft_instances`  

``EXECUTE`` privilege on:

-  `bdr.get_raft_instance_by_nodegroup <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrget_raft_instance_by_nodegroup>`_  

-  `bdr.monitor_camo_on_all_nodes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrmonitor_camo_on_all_nodes>`_  

- `bdr.monitor_group_raft <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrmonitor_group_raft>`_  

- `bdr.monitor_group_versions <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrmonitor_group_versions>`_  

- `bdr.monitor_local_replslots <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrmonitor_local_replslots>`_  

-  `bdr.monitor_raft_details_on_all_nodes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrmonitor_raft_details_on_all_nodes>`_  

-  `bdr.monitor_replslots_details_on_all_nodes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrmonitor_replslots_details_on_all_nodes>`_  

-  `bdr.monitor_subscription_details_on_all_nodes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrmonitor_subscription_details_on_all_nodes>`_  

-  `bdr.monitor_version_details_on_all_nodes <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrmonitor_version_details_on_all_nodes>`_  

-  `bdr.node_group_member_info <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrnode_group_member_info>`_  

bdr_application
^^^^^^^^^^^^^^^

This role is designed for applications that require access to PGD
features, objects, and functions such as sequences, CRDT datatypes, CAMO
status functions, or trigger management functions.

.. _privileges-3:

Privileges
^^^^^^^^^^

``EXECUTE`` privilege on:

- All functions for column_timestamps datatypes

- All functions for CRDT datatypes

- `bdr.alter_sequence_set_kind <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/sequences#bdralter_sequence_set_kind>`_  

- `bdr.create_conflict_trigger <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/interfaces#bdrcreate_conflict_trigger>`_  

- `bdr.create_transform_trigger <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/interfaces#bdrcreate_transform_trigger>`_  

- `bdr.drop_trigger <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/interfaces#bdrdrop_trigger>`_  

- `bdr.get_configured_camo_partner <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrget_configured_camo_partner>`_  

- `bdr.global_lock_table <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrglobal_lock_table>`_  

- `bdr.is_camo_partner_connected <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdris_camo_partner_connected>`_  

- `bdr.is_camo_partner_ready <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdris_camo_partner_ready>`_  

- `bdr.logical_transaction_status <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrlogical_transaction_status>`_  

- ``bdr.ri_fkey_trigger``

- `bdr.seq_nextval <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrseq_nextval>`_  

- `bdr.seq_currval <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrseq_currval>`_  

- `bdr.seq_lastval <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions-internal#bdrseq_lastval>`_  

- `bdr.trigger_get_committs <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_committs>`_  

- `bdr.trigger_get_conflict_type <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_conflict_type>`_  

- `bdr.trigger_get_origin_node_id <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_origin_node_id>`_  

- `bdr.trigger_get_row <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_row>`_  

- `bdr.trigger_get_type <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_type>`_  

- `bdr.trigger_get_xid <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/streamtriggers/rowfunctions#bdrtrigger_get_xid>`_  

- `bdr.wait_for_camo_partner_queue <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrwait_for_camo_partner_queue>`_  

- `bdr.wait_slot_confirm_lsn <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrwait_slot_confirm_lsn>`_  

- `bdr.wait_node_confirm_lsn <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/functions#bdrwait_node_confirm_lsn>`_  

Many of these functions require additional privileges before you can use
them. For example, you must be the table owner to successfully execute
``bdr.alter_sequence_set_kind`` . These additional rules are described
with each specific function.

bdr_read_all_conflicts
^^^^^^^^^^^^^^^^^^^^^^

PGD logs conflicts into the `bdr.conflict_history <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrconflict_history>`_ 

table. Conflicts are visible only to table owners, so no extra
privileges are required for the owners to read the conflict history.

However, if it’s useful to have a user that can see conflicts for all
tables, you can optionally grant the role ``bdr_read_all_conflicts`` to
that user.

.. _privileges-4:

Privileges
^^^^^^^^^^

An explicit policy is set on `bdr.conflict_history <https://www.enterprisedb.com/docs/pgd/latest/reference/tables-views-functions/catalogs-visible#bdrconflict_history>`_  that allows this role to
read the ``bdr.conflict_history`` table.
