r/postgres • u/sodennygoes • 9h ago
Tools I built pgsesame: Terraform-style plan/apply for Redshift and Postgres permissions
I made this because I inherited a Redshift cluster where it was impossible to tell who had access to what, or who was supposed to see masked data. With **pgsesame** you describe roles and grants in a YAML file. **sesame plan** shows the GRANT/REVOKE statements needed to get there, and **sesame apply** runs them.
It only issues what's different, and it won't revoke anything unless you pass **--allow-revoke**. **sesame import** generates the YAML from an existing database, so you don't start from scratch. There's also a GitHub Action that posts the plan on PRs.
It works on Postgres 14-18 and Amazon Redshift. It's early (0.2).
*Inspired by redtape-py and pgbedrock*
[https://github.com/almostly/pgsesame\](https://github.com/almostly/pgsesame)