Re: Whatcha' wanta have?????
Posted in 2004
Topics: Server Administration
Ronald Cole wrote: > > A "single user" mode... and I vote for the "informix" user instead of > DBA. Ummmmm, I don't. I try to convince all our teams/sites to use a specific application-administration account so that they do not use "informix" or (horror) "root" to administer the database. The principle is: 1) "root" administers the machine. It should not be used to configure the engine, the application, or do ordinary user work because it puts the machine in greater risk of accidental damage by sleepy brains. 2) "informix" administers the engine - space, configuration state. It should not be used to configure the engine, the application, or do ordinary user work because it puts the machine in greater risk of accidental damage by sleepy brains. 3) the application account administers the database - eg schema, mass data transformations, etc. It should not be used to do ordinary user work because it puts the machine in greater risk of accidental damage by sleepy brains. Sure, "informix" should be on the list of legal administrators, but perhaps we need a list of accounts that can connect whilst the engine is in the hypothetical administration mode.
Andrew Hamm wrote: > Ronald Cole wrote: > >>A "single user" mode... and I vote for the "informix" user instead of >>DBA. > > Ummmmm, I don't. > > I try to convince all our teams/sites to use a specific > application-administration account so that they do not use "informix" or > (horror) "root" to administer the database. The principle is: > > 1) "root" administers the machine. It should not be used to configure the > engine, the application, or do ordinary user work because it puts the > machine in greater risk of accidental damage by sleepy brains. > > 2) "informix" administers the engine - space, configuration state. It > should not be used to configure the engine, the application, or do ordinary > user work because it puts the machine in greater risk of accidental damage > by sleepy brains. I think the sentences of (2) contradict each other. Presumably, you meant "It should not be used to configure the database, the application, ..."? This user is the DBSA - database system administrator - a completely separate role from the DBA or database administrator who manages a single database within an instance. Note that it is possible to have users other than 'informix' who are the DBSA -- it's called role separation and is a major source of headaches (for me). If you ignore role separation and keep user informix as the only DBSA, it is much simpler everyone. You ignore the DBSA role separation by ensuring that user 'informix' is the only member of group 'informix' and by ensuring that $INFORMIXDIR/etc is owned by group 'informix'. > 3) the application account administers the database - eg schema, mass data > transformations, etc. It should not be used to do ordinary user work > because it puts the machine in greater risk of accidental damage by sleepy > brains. > > Sure, "informix" should be on the list of legal administrators, but perhaps > we need a list of accounts that can connect whilst the engine is in the > hypothetical administration mode. So, in this single-user mode, you want certain users - the separate DBA users - to be able to connect to the server and administer their respective databases? Obviously, DATABASE mine EXCLUSIVE partially achieves this, but it isn't as effective as a server-level maintenance mode. Andrew has exactly the right idea - different users have different jobs to do and the different roles should not be blindly conflated (but often are). In particular, the distinction between DBA and DBSA is usually overlooked, and a depressingly large number of databases seem to use 'informix' as both the DBSA and DBA. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2003.04 -- http://dbi.perl.org/
Jonathan Leffler wrote: > Andrew Hamm wrote: >> >> 2) "informix" administers the engine - space, configuration state. >> It should not be used to configure the engine, the application, or >> do ordinary user work because it puts the machine in greater risk of >> accidental damage by sleepy brains. > > I think the sentences of (2) contradict each other. Presumably, you > meant "It should not be used to configure the database, the > application, ..."? ahhh - yes. The dangers of cut-n-paste - and a chronically sleepy brain :-/ > This user is the DBSA - database system administrator - a completely > separate role from the DBA or database administrator who manages a > single database within an instance. > > Note that it is possible to have users other than 'informix' who are > the DBSA -- it's called role separation and is a major source of > headaches (for me). If you ignore role separation and keep user > informix as the only DBSA, it is much simpler everyone. You ignore > the DBSA role separation by ensuring that user 'informix' is the only > member of group 'informix' and by ensuring that $INFORMIXDIR/etc is > owned by group 'informix'. I've seen it that people in group informix start the engine and then mysteriously other people cannot connect. Perhaps that's platform-specific, but I tend to scream and shout until all users except informix are removed from the informix group :-) > So, in this single-user mode, you want certain users - the separate > DBA users - to be able to connect to the server and administer their > respective databases? Obviously, DATABASE mine EXCLUSIVE partially > achieves this, but it isn't as effective as a server-level maintenance > mode. Yes - that would be ideal for me, and i think a decent design. As you mention in your wrap-up, the people using "informix" for DBA - well, i guess they'll be happy anyway. The only sites that will be less able to use this admin mode are those who grant DBA to unsuitable accounts, especially if it's to "public". Which I've seen on sites where objects are owned by every man and his dog, then views based on tables owned by multiple people don't work unless everyone is given DBA, and general permissions are left in a forgotten heap behind the fridge. In other words, shambolic sites. There's not much you can do to help places that are in a mess.