Skip to content

resource_control: add dynamic privilege description for resource group admin and user #20083

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions privilege-management.md
Original file line number Diff line number Diff line change
Expand Up @@ -292,6 +292,8 @@ SHOW GRANTS FOR `rw_user`@`192.168.%`;
* `RESTRICTED_USER_ADMIN` 不允许在 SEM 打开的情况下使用 `SUPER` 用户撤销访问权限。
* `RESTRICTED_CONNECTION_ADMIN` 允许 KILL 属于 `RESTRICTED_USER_ADMIN` 用户的连接。该权限对 `KILL` 和 `KILL TIDB` 语句生效。
* `RESTRICTED_REPLICA_WRITER_ADMIN` 允许权限拥有者在 TiDB 集群开启了只读模式的情况下不受影响地执行写入或更新操作,详见 [`tidb_restricted_read_only` 配置项](/system-variables.md#tidb_restricted_read_only-从-v520-版本开始引入)。
* `RESOURCE_GROUP_ADMIN` 允许权限拥有者创建、修改和删除资源组 (Resource Group),详见[管理资源组](/tidb-resource-control-ru-groups.md#管理资源组)。
* `RESOURCE_GROUP_USER` 允许权限拥有者将当前连接绑定至其他资源组 (Resource Group),详见[绑定资源组](/tidb-resource-control-ru-groups.md#绑定资源组)。

若要查看全部的动态权限,请执行 `SHOW PRIVILEGES` 语句。由于用户可使用插件来添加新的权限,因此可分配的权限列表可能因用户的 TiDB 安装情况而异。

Expand Down