Skip to main content

dbwarden-ch-rbac

Python PyPI CI

ClickHouse RBAC object handlers for DBWarden.

Teaches DBWarden's schema diff to manage ClickHouse access control the same way it manages tables: extracted from a live snapshot, diffed against your models, and emitted as reversible migration SQL.

Object types

Object type Manages
ch_settings_profile CREATE/ALTER/DROP SETTINGS PROFILE
ch_role CREATE/ALTER/DROP ROLE
ch_user CREATE/ALTER/DROP USER, including auth, host, and default roles
ch_quota CREATE/ALTER/DROP QUOTA
ch_row_policy CREATE/ALTER/DROP ROW POLICY
ch_named_collection CREATE/ALTER/DROP NAMED COLLECTION, with secret values redacted in snapshots
ch_grant GRANT / REVOKE

Handlers register in ClickHouse's RBAC dependency order (profiles, then roles, then users, then everything that references them) so a single migration applies cleanly in one pass.

Installation

dbwarden plugin add dbwarden-ch-rbac

Trust tier

This is an official DBWarden plugin. Its distribution name is classified before any of its code is imported, and dbwarden plugin add verifies the PyPI Trusted-Publishing attestation (PEP 740) against dbwarden-org/dbwarden-ch-rbac before installing. It loads automatically once installed, with no dbwarden plugin trust step.

Development

uv venv && uv pip install -e . -e ../dbwarden pytest
pytest -q

The tests/test_conformance.py suite runs DBWarden's shared conformance harness (dbwarden.plugin_conformance): entry point resolution, no import-time side effects, hook signatures, public-API-only imports, and idempotent setup().

License

MIT

Release files for dbwarden-ch-rbac 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dbwarden-ch-rbac 0.2.0
File Size Uploaded
dbwarden_ch_rbac-0.2.0.tar.gz 12.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dbwarden-ch-rbac 0.2.0
File Interpreter ABI Platform
dbwarden_ch_rbac-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 29.0 kB

Release files / dbwarden_ch_rbac-0.2.0.tar.gz

Download URL dbwarden_ch_rbac-0.2.0.tar.gz
Size 12.7 kB
Tags Source
SHA-256 checksum
How to use checksums
380b73842e7e8e1211c68c83e2e1198d3ed003f0e68776126dd46ea1b6652ca6
BLAKE2b-256 checksum
How to use checksums
ca7d1f0a97ba4b84adae04fc69d3a2b880ed5ca006c4f30491800bdc0704cded
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 6, 2026.

Transparency log

Release files / dbwarden_ch_rbac-0.2.0-py3-none-any.whl

Download URL dbwarden_ch_rbac-0.2.0-py3-none-any.whl
Size 16.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6b022996136f1dc5757d7e01a7f0356dc25e5603bd47f0fa5d2a3aafe68b7456
BLAKE2b-256 checksum
How to use checksums
a74c1e463f468f8c15d7e2aab39d013e7fff30e047d9afd240880b05b0b9aef1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 6, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.1

2 release files

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page