Non-superuser kamo_app role for all application workloads [skip ci]

OtherKlusterServices
Shipped
September 16, 2026 at 8:24 PM UTC
Author
Kamo
Commit
3767584

Services connected as the superuser kamo. Add an idempotent script that creates kamo_app (no superuser, not a member of kamo so it cannot SET ROLE back) with grants on every schema/table/sequence plus default privileges, and ownership of only the tables services alter at runtime; kamouniverse is owned outright. Grants rather than ownership because an owner change bumps DocDB schema versions. The superuser login moves to yugabytedb-admin-credentials.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing