Skip to content
Stackship documentation Svenska

SQL ServerUsers

Permissions

The actions that govern SQL Server instances, their connection strings, product keys and Data Explorer, and the roles that hold them.

Actions

Action Allows
sqlservercluster/read See instances, their configuration, revisions, snapshots, health and external address, and the text of the statements recently submitted in the Data Explorer
sqlservercluster/write Create and change instances; start, stop and restart them; schedule backups. Includes sqlservercluster/delete
sqlservercluster/delete Delete instances
sqlservercluster/scale Set the instance count through the scale route; only one instance is supported
sqlservercluster/createSnapshot Take a snapshot
sqlservercluster/restoreSnapshot Restore a snapshot in place
sqlservercluster/deleteSnapshot Delete a snapshot
sqlservercluster/readSecrets Reveal the connection strings, which carry the sa password
sqlservercluster/writeSecrets Nothing yet: no SQL Server route uses it
sqlservercluster/manageLicense Set or rotate the product key of a paid edition on the License section

sqlservercluster/readSecrets, sqlservercluster/writeSecrets, sqlservercluster/manageLicense and the Data Explorer actions below are data actions: a role grants them only when it lists them as such, so a role that can manage an instance does not by that alone read its credentials or its data.

Important

sqlservercluster/write can also supply a product key: the create and update routes accept a licenseKey field and store it without checking sqlservercluster/manageLicense.

Data Explorer

Action Allows
sqlservercluster/dataRead Open the Data Explorer and browse rows
sqlservercluster/dataWrite Add, change and delete rows on the Browse tab
sqlservercluster/schemaRead List schemas, tables and columns
sqlservercluster/queryExecute Run SELECT
sqlservercluster/queryExecuteWrite Run INSERT, UPDATE, DELETE and MERGE
sqlservercluster/schemaWrite Run CREATE and ALTER
sqlservercluster/schemaDrop Run DROP and TRUNCATE TABLE, together with sqlservercluster/schemaWrite

Each statement is checked against these before it runs, and running any statement also needs sqlservercluster/read. See What runs.

sqlservercluster/schemaWrite and sqlservercluster/schemaDrop are declared as data actions, but the Data Explorer checks them as ordinary actions. A role therefore grants them only when it lists them among its ordinary actions — as Owner, Contributor, Platform Owner and Platform Contributor do through */* — and not when it lists them as data actions, as Database Explorer does.

Roles

Role See Create, change Delete Snapshots Connection strings, product key Data Explorer
Reader, Databases Reader Yes No No See No No
Database Explorer Yes No No See No Browse and edit rows, run SELECT, INSERT, UPDATE, DELETE and MERGE; not create, change or drop objects
Databases Operator Yes Yes Yes Take, restore, delete Yes No
Contributor Yes Yes Yes Take Yes Everything
Owner Yes Yes Yes Take, restore, delete Yes Everything

Platform Owner and Platform Contributor hold every action in every boundary, the Data Explorer included; Platform Reader can see instances. On SQL Server, unlike PostgreSQL, the Data Explorer actions come with Owner and Contributor, so the Database Explorer role is needed only by people who should query without managing the instance — see Database Explorer.

Assign roles on the boundary, the resource group or the instance itself — see Role assignments. An action you lack can be requested as temporary access — see Request access.