Why can't I create a superuser in AWS Postgresql instance? The 2019 Stack Overflow Developer Survey Results Are InPostgres database post-expiration of user password unable to loginWhy can't user login on PostgresAWS RDS CLI: AccessDenied on CreateDBSnapshotCannot SSH to my AWS Linux instance after rebooting itAWS RDS db.t2 instance performance thresholds & monitoringHow to store a login path for psql?Why do I need an IAM user when I can create an Instance from main account?Creating a read only account for AWS RDS PostgreSQLHow can my client give me access to his AWS account?Unknown Database when trying to connect to an AWS RDS instance
Why is Grand Jury testimony secret?
How can I fix this gap between bookcases I made?
Realistic Alternatives to Dust: What Else Could Feed a Plankton Bloom?
What do the Banks children have against barley water?
Extreme, unacceptable situation and I can't attend work tomorrow morning
aging parents with no investments
Does it makes sense to buy a new cycle to learn riding?
What is the motivation for a law requiring 2 parties to consent for recording a conversation
Manuscript was "unsubmitted" because the manuscript was deposited in Arxiv Preprints
Is "plugging out" electronic devices an American expression?
Geography at the pixel level
Lethal sonic weapons
Unbreakable Formation vs. Cry of the Carnarium
What do hard-Brexiteers want with respect to the Irish border?
Springs with some finite mass
On the insanity of kings as an argument against Monarchy
"To split hairs" vs "To be pedantic"
How to create dashed lines/arrows in Illustrator
How was Skylab's orbit inclination chosen?
Could JWST stay at L2 "forever"?
"What time...?" or "At what time...?" - what is more grammatically correct?
Carnot-Caratheodory metric
How to make payment on the internet without leaving a money trail?
Idiomatic way to prevent slicing?
Why can't I create a superuser in AWS Postgresql instance?
The 2019 Stack Overflow Developer Survey Results Are InPostgres database post-expiration of user password unable to loginWhy can't user login on PostgresAWS RDS CLI: AccessDenied on CreateDBSnapshotCannot SSH to my AWS Linux instance after rebooting itAWS RDS db.t2 instance performance thresholds & monitoringHow to store a login path for psql?Why do I need an IAM user when I can create an Instance from main account?Creating a read only account for AWS RDS PostgreSQLHow can my client give me access to his AWS account?Unknown Database when trying to connect to an AWS RDS instance
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have an AWS EC2 instance connecting to an RDS instance (Postgresql). When I created the RDS instance, I told it the DB root's username was: my_user1
and the password was password1
. Now I'm attempting to create a role and a super-user. But it fails:
$ createuser -P -d -s -e my_user2 --host myhost.com -U my_user1
Enter password for new role: XXXYYYZZZ
Enter it again: XXXYYYZZZ
Password: password1
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f999c' SUPERUSER CREATEDB CREATEROLE INHERIT LOGIN;
createuser: creation of new role failed: ERROR: must be superuser to create superusers
$
When I repeat the command without the -s
flag, it works:
$ createuser -P -d -e my_user2 --host myhost.com -U my_user1
Enter password for new role:
Enter it again:
Password:
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f888c' NOSUPERUSER CREATEDB NOCREATEROLE INHERIT LOGIN;
$
So clearly, my_user1
doesn't have permissions to create a super-user. But this is the user I told RDS was my admin user! If my_user1
doesn't have permissions to create a super-user, who does? And how do I get their username/password from AWS?
amazon-web-services postgresql amazon-rds
add a comment |
I have an AWS EC2 instance connecting to an RDS instance (Postgresql). When I created the RDS instance, I told it the DB root's username was: my_user1
and the password was password1
. Now I'm attempting to create a role and a super-user. But it fails:
$ createuser -P -d -s -e my_user2 --host myhost.com -U my_user1
Enter password for new role: XXXYYYZZZ
Enter it again: XXXYYYZZZ
Password: password1
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f999c' SUPERUSER CREATEDB CREATEROLE INHERIT LOGIN;
createuser: creation of new role failed: ERROR: must be superuser to create superusers
$
When I repeat the command without the -s
flag, it works:
$ createuser -P -d -e my_user2 --host myhost.com -U my_user1
Enter password for new role:
Enter it again:
Password:
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f888c' NOSUPERUSER CREATEDB NOCREATEROLE INHERIT LOGIN;
$
So clearly, my_user1
doesn't have permissions to create a super-user. But this is the user I told RDS was my admin user! If my_user1
doesn't have permissions to create a super-user, who does? And how do I get their username/password from AWS?
amazon-web-services postgresql amazon-rds
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51
add a comment |
I have an AWS EC2 instance connecting to an RDS instance (Postgresql). When I created the RDS instance, I told it the DB root's username was: my_user1
and the password was password1
. Now I'm attempting to create a role and a super-user. But it fails:
$ createuser -P -d -s -e my_user2 --host myhost.com -U my_user1
Enter password for new role: XXXYYYZZZ
Enter it again: XXXYYYZZZ
Password: password1
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f999c' SUPERUSER CREATEDB CREATEROLE INHERIT LOGIN;
createuser: creation of new role failed: ERROR: must be superuser to create superusers
$
When I repeat the command without the -s
flag, it works:
$ createuser -P -d -e my_user2 --host myhost.com -U my_user1
Enter password for new role:
Enter it again:
Password:
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f888c' NOSUPERUSER CREATEDB NOCREATEROLE INHERIT LOGIN;
$
So clearly, my_user1
doesn't have permissions to create a super-user. But this is the user I told RDS was my admin user! If my_user1
doesn't have permissions to create a super-user, who does? And how do I get their username/password from AWS?
amazon-web-services postgresql amazon-rds
I have an AWS EC2 instance connecting to an RDS instance (Postgresql). When I created the RDS instance, I told it the DB root's username was: my_user1
and the password was password1
. Now I'm attempting to create a role and a super-user. But it fails:
$ createuser -P -d -s -e my_user2 --host myhost.com -U my_user1
Enter password for new role: XXXYYYZZZ
Enter it again: XXXYYYZZZ
Password: password1
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f999c' SUPERUSER CREATEDB CREATEROLE INHERIT LOGIN;
createuser: creation of new role failed: ERROR: must be superuser to create superusers
$
When I repeat the command without the -s
flag, it works:
$ createuser -P -d -e my_user2 --host myhost.com -U my_user1
Enter password for new role:
Enter it again:
Password:
CREATE ROLE my_user2 PASSWORD 'md5999999c0101a1d64afd57575e06f888c' NOSUPERUSER CREATEDB NOCREATEROLE INHERIT LOGIN;
$
So clearly, my_user1
doesn't have permissions to create a super-user. But this is the user I told RDS was my admin user! If my_user1
doesn't have permissions to create a super-user, who does? And how do I get their username/password from AWS?
amazon-web-services postgresql amazon-rds
amazon-web-services postgresql amazon-rds
edited Jan 22 '15 at 20:45
Saqib Ali
asked Jan 22 '15 at 19:52
Saqib AliSaqib Ali
1941317
1941317
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51
add a comment |
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51
add a comment |
2 Answers
2
active
oldest
votes
RDS instances are managed by Amazon. As such, to prevent you from breaking things like replication, your users - even the root user you set up when you create the instance - will not have full superuser privileges.
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.PostgreSQL.CommonDBATasks.html
When you create a DB instance, the master user system account that you create is assigned to the rds_superuser role. The rds_superuser role is a pre-defined Amazon RDS role similar to the PostgreSQL superuser role (customarily named postgres in local instances), but with some restrictions. As with the PostgreSQL superuser role, the rds_superuser role has the most privileges on your DB instance and you should not assign this role to users unless they need the most access to the DB instance.
1
i can't backup my database without the super user flag usingpg_dump
. Is there a way around this with rds on aws?
– chovy
Nov 18 '18 at 5:57
add a comment |
If you list your current permissions with du+
or dg+
, you will notice you are not a superuser but only allowed permissions Create role, Create DB. As such you are not allowed to assign yourself permissions higher from the ones you are currently assigned with.
Normally you are not given root or superuser permissions in any hosted environment. I suggest you spin up a custom EC2 instance and install PostgreSQL locally for complete control.
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f661661%2fwhy-cant-i-create-a-superuser-in-aws-postgresql-instance%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
2 Answers
2
active
oldest
votes
2 Answers
2
active
oldest
votes
active
oldest
votes
active
oldest
votes
RDS instances are managed by Amazon. As such, to prevent you from breaking things like replication, your users - even the root user you set up when you create the instance - will not have full superuser privileges.
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.PostgreSQL.CommonDBATasks.html
When you create a DB instance, the master user system account that you create is assigned to the rds_superuser role. The rds_superuser role is a pre-defined Amazon RDS role similar to the PostgreSQL superuser role (customarily named postgres in local instances), but with some restrictions. As with the PostgreSQL superuser role, the rds_superuser role has the most privileges on your DB instance and you should not assign this role to users unless they need the most access to the DB instance.
1
i can't backup my database without the super user flag usingpg_dump
. Is there a way around this with rds on aws?
– chovy
Nov 18 '18 at 5:57
add a comment |
RDS instances are managed by Amazon. As such, to prevent you from breaking things like replication, your users - even the root user you set up when you create the instance - will not have full superuser privileges.
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.PostgreSQL.CommonDBATasks.html
When you create a DB instance, the master user system account that you create is assigned to the rds_superuser role. The rds_superuser role is a pre-defined Amazon RDS role similar to the PostgreSQL superuser role (customarily named postgres in local instances), but with some restrictions. As with the PostgreSQL superuser role, the rds_superuser role has the most privileges on your DB instance and you should not assign this role to users unless they need the most access to the DB instance.
1
i can't backup my database without the super user flag usingpg_dump
. Is there a way around this with rds on aws?
– chovy
Nov 18 '18 at 5:57
add a comment |
RDS instances are managed by Amazon. As such, to prevent you from breaking things like replication, your users - even the root user you set up when you create the instance - will not have full superuser privileges.
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.PostgreSQL.CommonDBATasks.html
When you create a DB instance, the master user system account that you create is assigned to the rds_superuser role. The rds_superuser role is a pre-defined Amazon RDS role similar to the PostgreSQL superuser role (customarily named postgres in local instances), but with some restrictions. As with the PostgreSQL superuser role, the rds_superuser role has the most privileges on your DB instance and you should not assign this role to users unless they need the most access to the DB instance.
RDS instances are managed by Amazon. As such, to prevent you from breaking things like replication, your users - even the root user you set up when you create the instance - will not have full superuser privileges.
http://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.PostgreSQL.CommonDBATasks.html
When you create a DB instance, the master user system account that you create is assigned to the rds_superuser role. The rds_superuser role is a pre-defined Amazon RDS role similar to the PostgreSQL superuser role (customarily named postgres in local instances), but with some restrictions. As with the PostgreSQL superuser role, the rds_superuser role has the most privileges on your DB instance and you should not assign this role to users unless they need the most access to the DB instance.
answered Jan 22 '15 at 21:38
ceejayozceejayoz
27.1k66392
27.1k66392
1
i can't backup my database without the super user flag usingpg_dump
. Is there a way around this with rds on aws?
– chovy
Nov 18 '18 at 5:57
add a comment |
1
i can't backup my database without the super user flag usingpg_dump
. Is there a way around this with rds on aws?
– chovy
Nov 18 '18 at 5:57
1
1
i can't backup my database without the super user flag using
pg_dump
. Is there a way around this with rds on aws?– chovy
Nov 18 '18 at 5:57
i can't backup my database without the super user flag using
pg_dump
. Is there a way around this with rds on aws?– chovy
Nov 18 '18 at 5:57
add a comment |
If you list your current permissions with du+
or dg+
, you will notice you are not a superuser but only allowed permissions Create role, Create DB. As such you are not allowed to assign yourself permissions higher from the ones you are currently assigned with.
Normally you are not given root or superuser permissions in any hosted environment. I suggest you spin up a custom EC2 instance and install PostgreSQL locally for complete control.
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
add a comment |
If you list your current permissions with du+
or dg+
, you will notice you are not a superuser but only allowed permissions Create role, Create DB. As such you are not allowed to assign yourself permissions higher from the ones you are currently assigned with.
Normally you are not given root or superuser permissions in any hosted environment. I suggest you spin up a custom EC2 instance and install PostgreSQL locally for complete control.
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
add a comment |
If you list your current permissions with du+
or dg+
, you will notice you are not a superuser but only allowed permissions Create role, Create DB. As such you are not allowed to assign yourself permissions higher from the ones you are currently assigned with.
Normally you are not given root or superuser permissions in any hosted environment. I suggest you spin up a custom EC2 instance and install PostgreSQL locally for complete control.
If you list your current permissions with du+
or dg+
, you will notice you are not a superuser but only allowed permissions Create role, Create DB. As such you are not allowed to assign yourself permissions higher from the ones you are currently assigned with.
Normally you are not given root or superuser permissions in any hosted environment. I suggest you spin up a custom EC2 instance and install PostgreSQL locally for complete control.
edited Apr 5 at 18:20
Dennis
1094
1094
answered Jan 18 '17 at 13:49
Gorazd ZagarGorazd Zagar
513
513
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
add a comment |
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
1
1
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
is there really no way to backup an amazon rds database with pg_dump otherwise?
– chovy
Nov 18 '18 at 5:58
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f661661%2fwhy-cant-i-create-a-superuser-in-aws-postgresql-instance%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
does the pg_hba.conf say the authentication scheme is peer for local users ?
– drookie
Jan 22 '15 at 20:19
Drookie, is this file on the RDS instance itself? I haven't even SSHed onto that machine yet.
– Saqib Ali
Jan 22 '15 at 20:42
@SaqibAli You can't SSH into a RDS instance.
– ceejayoz
Jan 22 '15 at 21:51