raffadmin. Give each app or person its own user instead, read-only or read-write, so you can rotate or remove one without touching the others.
Before you start
- A running PostgreSQL, MySQL or ClickHouse database. Valkey and Kafka have the admin user only.
Add a user
1
Open Access
Open the database and go to the Access tab. Users lists every user, what it Can do and who uses it.
2
Create the user
Click Add user, enter a name (lowercase letters, digits and
_, 3 to 31 characters) and pick:- Read only:
SELECTon all tables. For reports, BI and dashboards. - Read & write:
SELECT,INSERT,UPDATE,DELETE. For application traffic.
3
Save the password
The password is shown once. Copy it; you can reveal or rotate it later from Users.
raffadmin, postgres, root, admin and others) cannot be taken.
On PostgreSQL, users get access to the public schema, including tables created later by raffadmin. On MySQL, to defaultdb.
Rotate a user’s password
In Users, click New password on the user’s row. The new password is shown once; the old one stops working at once, so update your app first or right after.Rotate the admin password
In Access, Credentials card, click Rotate password, then click again to confirm. The old password stops working now; every app usingraffadmin must reconnect with the new one.
Remove a user
Click Remove on the user’s row and confirm. The user loses access at once; what it created stays in the database.Do it from your tools
- API: Users, Rotate admin password
- CLI:
raff database users,raff database rotate-password - Terraform:
raff_database_user
Next steps
Connect to a database
Connect as the new user with As user.
Networking and security
TLS, the allowlist and certificates.