Hi all, Sorry for the late reply.
The v1 patch was mainly intended to discuss whether `RELOAD` belongs under `ALTER SYSTEM`, so I did not cover the privilege design in detail. I had in mind a separate ACL for `ALTER SYSTEM` operations, allowing privileges to be granted per operation. If we add more operations, predefined roles may be too broad to allow fine-grained control. > I'm pretty down on this proposal even without the privilege question. > "There's more than one way to do it" isn't a great thing for > security-relevant operations, and this surely is one. > > Also, I don't like the loss of an explainable scope for what > ALTER SYSTEM does. I agree with Tom's concerns about adding a second interface and blurring the scope of the command. I also agree with Andreas about the maintenance cost. `pg_reload_conf()` already provides the reload operation, and the `ALTER SYSTEM` documentation explains how to request a reload. > This lack of intellectual consistency would get ten times worse > if we followed through on the idea of overloading ALTER SYSTEM > with unrelated actions like log rotation and promotion. Agreed. Log rotation and promotion were simply the first operations that came to mind as possible fits for a broader command family. Adding just those two would not give ALTER SYSTEM a coherent scope. Oracle has a much broader ALTER SYSTEM command family, though. If PostgreSQL developed a similarly broad family of instance-level operations, could that give the command a clearer scope? But still, it would increase the overlap with existing functions that concerns Tom, as well as the maintenance cost Andreas noted. Thanks everyone for the reviews. Best regards, Yuhang Qiu
