RE: Whatcha' wanta have????? (single user maintenance mode)
Posted in 2004
And while we are talking about users. I would like to see a different "instance management" user for each instance. Using the informix account to manage one instance is OK, but when you get a site with 3 or 4 instances then they often have different teams of administrators for the different instances. Regards Malcolm -----Original Message----- From: owner-informix-list@iiug.org [mailto:owner-informix-list@iiug.org] On Behalf Of Jonathan Leffler Sent: 16 February 2004 06:15 To: informix-list@iiug.org Subject: Re: Whatcha' wanta have????? (single user maintenance mode) Andrew Hamm wrote: > Ronald Cole wrote: > >>A "single user" mode... and I vote for the "informix" user instead of >>DBA. > > Ummmmm, I don't. > > I try to convince all our teams/sites to use a specific > application-administration account so that they do not use "informix" > or > (horror) "root" to administer the database. The principle is: > > 1) "root" administers the machine. It should not be used to configure > the engine, the application, or do ordinary user work because it puts > the machine in greater risk of accidental damage by sleepy brains. > > 2) "informix" administers the engine - space, configuration state. It > should not be used to configure the engine, the application, or do > ordinary user work because it puts the machine in greater risk of > accidental damage by sleepy brains. I think the sentences of (2) contradict each other. Presumably, you meant "It should not be used to configure the database, the application, ..."? This user is the DBSA - database system administrator - a completely separate role from the DBA or database administrator who manages a single database within an instance. Note that it is possible to have users other than 'informix' who are the DBSA -- it's called role separation and is a major source of headaches (for me). If you ignore role separation and keep user informix as the only DBSA, it is much simpler everyone. You ignore the DBSA role separation by ensuring that user 'informix' is the only member of group 'informix' and by ensuring that $INFORMIXDIR/etc is owned by group 'informix'. > 3) the application account administers the database - eg schema, mass > data transformations, etc. It should not be used to do ordinary user > work because it puts the machine in greater risk of accidental damage > by sleepy brains. > > Sure, "informix" should be on the list of legal administrators, but > perhaps we need a list of accounts that can connect whilst the engine > is in the hypothetical administration mode. So, in this single-user mode, you want certain users - the separate DBA users - to be able to connect to the server and administer their respective databases? Obviously, DATABASE mine EXCLUSIVE partially achieves this, but it isn't as effective as a server-level maintenance mode. Andrew has exactly the right idea - different users have different jobs to do and the different roles should not be blindly conflated (but often are). In particular, the distinction between DBA and DBSA is usually overlooked, and a depressingly large number of databases seem to use 'informix' as both the DBSA and DBA. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/ sending to informix-list