Skip to main content

MC privileges

  • March 19, 2018
  • 5 replies
  • 2 views

sreeblr
Forum|alt.badge.img+2

I have set of users who monitor environment performance and want graphs that are in MC. I created Database read only user and given privileges MC configuration- IT and MC's Database Access=Associate. However the user is still able to start/stop nodes. Can this privilege be restricted?

5 replies

Jim_Knicely
Forum|alt.badge.img+2
  • Participating Frequently
  • March 21, 2018

Hmm. According to the doc, only the MC role "ADMIN" should have the ability to "Start/stop a node":

https://my.vertica.com/docs/9.0.x/HTML/index.htm#Authoring/ManagementConsole/ManagingUsersandPrivileges/MCDatabasePrivileges.htm


sreeblr
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • March 22, 2018

unfortunately even associate role has


Jim_Knicely
Forum|alt.badge.img+2
  • Participating Frequently
  • March 23, 2018

Verify what GRANTS the DB user has...

select grantor, privileges_description, object_schema, object_name, object_type from grants where grantee = '<<USER_NAME>>';


sreeblr
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • March 23, 2018

the user has only read privilege on some tables. i gave DB user sysmonitor privilege since user need to run reports


sreeblr
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • March 23, 2018

grantor privileges_description object_schema object_name object_type
dbadmin USAGE (null) general RESOURCEPOOL
dbadmin (null) test_RO ROLE
dbadmin USAGE (null) public SCHEMA
dbadmin SELECT public v_dcalloc_pool_stat_by_second VIEW
dbadmin USAGE (null) test SCHEMA
dbadmin (null) sysmonitor ROLE