Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Managed Service for PostgreSQL
  • Getting started
    • Resource relationships
    • Planning a cluster topology
    • High availability clusters
    • Networking in Managed Service for PostgreSQL
    • Quotas and limits
    • Storage in Managed Service for PostgreSQL
    • Backups
    • Assigning roles
    • Managing connections
    • Load balancer for hosts
    • Replication
    • Maintenance
    • Supported clients
    • PostgreSQL settings
    • Indexes
    • SQL command limits
    • Upgrading the PostgreSQL major version
    • PostgreSQL versioning policy
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Public materials
  • Release notes

In this article:

  • mdb_superuser
  • mdb_admin
  • mdb_monitor
  • mdb_replication
  1. Concepts
  2. Assigning roles

Assigning roles PostgreSQL

Written by
Yandex Cloud
Updated at July 8, 2026
View in Markdown
  • mdb_superuser
  • mdb_admin
  • mdb_monitor
  • mdb_replication

With Managed Service for PostgreSQL, you cannot access predefined roles. Instead, this service provides the following special roles:

  • mdb_superuser: For users who are not database owners but need to manage privileges as owners.
  • mdb_admin: For users who are not database owners but need administrative privileges.
  • mdb_monitor: For users who need to be able to read various configuration parameters, statistics, and other system information.
  • mdb_replication: For users who need to be able to perform logical replication.

Note

PostgreSQL supports nested roles. A user, i.e., a role allowed to authenticate in a database, may be a member of one or multiple other roles and inherit their permissions. Learn more about role membership.

To assign a role to a user, use the Yandex Cloud interfaces: roles assigned by a GRANT request are revoked with the next database operation.

Note

You cannot create custom roles in Managed Service for PostgreSQL. A user’s permissions are determined by the combination of granted privileges.

mdb_superusermdb_superuser

The mdb_superuser role enables you to manage privileges for objects in a database.

mdb_adminmdb_admin

The mdb_admin role includes the following privileges:

  • Predefined role privileges:
    • pg_monitor
    • pg_signal_backend
      Learn more about predefined roles in this PostgreSQL guide.
  • Subscription for logical replication (CREATE | DROP | ALTER SUBSCRIPTION).
  • Extensions:
    • dblink
    • pg_repack
    • postgres_fdw
    • pg_cron
  • Extension-specific functions:
    • pg_stat_kcache_reset() from the pg_stat_kcache extension.
    • pg_stat_reset() and pg_stat_statements_reset() from the pg_stat_statements extension.

mdb_monitormdb_monitor

The mdb_monitor role includes the following privileges:

  • Reading and executing various views and functions for monitoring.
  • Extensions:
    • pg_stat_statements
  • Functions for working with ordinary files:
    • pg_ls_logdir()
    • pg_ls_waldir()
    • pg_ls_archive_statusdir()
    • pg_ls_tmpdir ()

mdb_replicationmdb_replication

The mdb_replication role includes the following privileges:

  • Connecting to a cluster using the logical replication protocol (replication=database).
  • Replication functions:
    • pg_create_logical_replication_slot()
    • pg_drop_replication_slot()

Was the article helpful?

Previous
Backups
Next
Managing connections
© 2026 Direct Cursus Technology L.L.C.