DO $bootstrap$ DECLARE runtime_password text := trim(both E'\r\n' from pg_read_file('/run/secrets/catalog_runtime_password')); BEGIN IF runtime_password = '' THEN RAISE EXCEPTION 'catalog runtime password is empty'; END IF; IF NOT EXISTS ( SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = 'thothii_catalog_runtime' ) THEN EXECUTE format( 'CREATE ROLE thothii_catalog_runtime LOGIN PASSWORD %L', runtime_password ); END IF; END $bootstrap$; GRANT CONNECT ON DATABASE thothii_catalog TO thothii_catalog_runtime; GRANT USAGE ON SCHEMA public TO thothii_catalog_runtime; ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO thothii_catalog_runtime; ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT USAGE, SELECT ON SEQUENCES TO thothii_catalog_runtime;