-- ThothII — ruolo DWH read-only (schema datawarehouse). -- Eseguire sulla stessa istanza Postgres usata da ThothII (porta 5438, accesso diretto). -- Sostituire :PWD con un secret forte al momento dell'esecuzione: -- psql -h localhost -p 5438 -U postgres -d postgres -v PWD='' -f 10-dwh-roles.sql DO $$ BEGIN IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'thoth_dwh_reader') THEN CREATE ROLE thoth_dwh_reader LOGIN; END IF; END $$; -- :'PWD' va fuori dal DO (psql non interpola nelle stringhe dollar-quoted) ALTER ROLE thoth_dwh_reader PASSWORD :'PWD'; GRANT USAGE ON SCHEMA datawarehouse TO thoth_dwh_reader; GRANT SELECT ON ALL TABLES IN SCHEMA datawarehouse TO thoth_dwh_reader; ALTER DEFAULT PRIVILEGES IN SCHEMA datawarehouse GRANT SELECT ON TABLES TO thoth_dwh_reader;