Skip to content

Roles

The extension creates two roles, server-wide. PUBLIC gets nothing.

role can
nobody (PUBLIC) nothing
pgbx_viewer status(), backups, history, config, overview(), doctor(), rowless_tables(), pitr_status(), pitr_state
pgbx_admin viewer + configure(), set_schedule(), set_retention(), pause(), resume(), backup_now(), restore(), verify_now(), set_verify_schedule(), download_url(), set_data_scope()

Admin functions run as SECURITY DEFINER, so admins never need write access to the tables. pitr_backup_now() is for superusers only. Your application’s own roles are kept with every backup: see Roles with every backup.

GRANT pgbx_admin TO my_migrator; -- migrations can call configure()
GRANT pgbx_viewer TO grafana;

overview() and doctor() run only in the admin database (pgbx.admin_db, default postgres).