# Needed postgresql user permissions for netdata monitoring?

**URL:** <https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606>\
**Category:** Help\
**Tags:** agent\
**Created:** [August 9, 2021, 1:16pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606 "2021-08-09T13:16:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![comete-geek](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/comete-geek/32/974_2.png) [@comete-geek](https://community.netdata.cloud/u/comete-geek)\
**Post date:** [August 9, 2021, 1:16pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606/1 "2021-08-09T13:16:10Z")

</div>

I’m trying to monitor Postgresql servers, so I’ve enabled the python.d/postgresql plugin but I want to create a dedicated postgresql user for this plugin.  
Could you tell me what are the needed permissions, to allow this plugin to work with all the features enabled ?

Thanks a lot.

Morgan

---

<div class="post-metadata">

**Author:** ![Ancairon](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/ancairon/32/1001_2.png) [@Ancairon](https://community.netdata.cloud/u/Ancairon)\
**Post date:** [August 12, 2021, 3:05pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606/2 "2021-08-12T15:05:59Z")

</div>

Hey Morgan 👋

I quickly deployed a test db and got the plugin working even with a user that didn’t have permissions (or rather attributes), created him with `CREATE USER fotis WITH PASSWORD 'test';`.

My `\du` results from within `psql` is:

```auto
 List of roles
 Role name | Attributes | Member of
-----------+------------------------------------------------------------+-----------
 fotis | | {}
 pi | Superuser, Create role, Create DB | {}
 postgres | Superuser, Create role, Create DB, Replication, Bypass RLS | {}

```

And my `postgres.conf` file is like this:

```auto
socket:
  name : 'socket'
  user : 'postgres'
  database : 'postgres'

tcp:
    name : 'local'
    database : 'fotisdb'
    user : 'fotis'
    password : 'test'
    host : 'localhost'
    port : 5432

```

And the plugin works as intended!

---

<div class="post-metadata">

**Author:** ![comete-geek](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/comete-geek/32/974_2.png) [@comete-geek](https://community.netdata.cloud/u/comete-geek)\
**Post date:** [August 12, 2021, 3:22pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606/3 "2021-08-12T15:22:49Z")

</div>

Hi @Ancairon,  
thanks for your answer. I’m ok with you but you’ll see some new charts (like Replication Delta and Archive WAL) if the user has more permissions (tested with ‘postgres’ user), especially for a cluster with replication.

Thanks

Morgan

---

<div class="post-metadata">

**Author:** ![Ancairon](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/ancairon/32/1001_2.png) [@Ancairon](https://community.netdata.cloud/u/Ancairon)\
**Post date:** [August 12, 2021, 5:44pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606/4 "2021-08-12T17:44:32Z")

</div>

I did some searching on the Postgresql documentation and on Netdata’s own code, the charts `Wal` and `Archive Wal` _for example_ seem to be made only if you are a `superuser`. Snippet of the source code:

```auto
1244 if self.is_superuser:
1245 self.queries[query_factory(QUERY_NAME_ARCHIVE, self.server_version)] = METRICS[QUERY_NAME_ARCHIVE]
1246
1247 if self.server_version >= 90400:
1248 self.queries[query_factory(QUERY_NAME_WAL, self.server_version)] = METRICS[QUERY_NAME_WAL]

```

This comes from [this file](https://github.com/netdata/netdata/blob/master/collectors/python.d.plugin/postgres/postgres.chart.py).  
I could be wrong but it seems as to get these kind of charts you need to make the new user a superuser, defying probably your needs because a superuser is like the `postgres` user.

_(there may be no default role to include all of the functions Netdata needs to run, and to grant the permition you should need a list of all these functions to give them `execute` access to the new user… But even that user probably wouldn’t pass the checks mentioned above)_

I hope this helps,  
Fotis

---

<div class="post-metadata">

**Author:** ![comete-geek](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/comete-geek/32/974_2.png) [@comete-geek](https://community.netdata.cloud/u/comete-geek)\
**Post date:** [August 16, 2021, 1:20pm UTC](https://community.netdata.cloud/t/needed-postgresql-user-permissions-for-netdata-monitoring/1606/5 "2021-08-16T13:20:15Z")

</div>

Ok, thanks for your help and your time !
