Skip to main content

pgsesame

Declarative permission management for PostgreSQL and Amazon Redshift. Define roles, users, grants and ownership in YAML, then plan and apply changes like Terraform.

Status: 0.1, alpha. validate, plan, apply and change sets work for roles, users, groups, memberships and privileges on PostgreSQL and Redshift, tested against PostgreSQL 14 to 18, oblako's redshift-local and Redshift Serverless, on Python 3.10 to 3.13. Ownership (owns) and default privileges are validated but not yet planned; see the roadmap.

Why

Granting access by hand leaves a trail of GRANT statements nobody can review. pgsesame keeps the intended state in one file: changes go through pull requests, sesame plan shows exactly which statements a change needs, and sesame apply runs them. A second plan after apply is empty.

It is built on what went wrong with earlier tools (redtape for Redshift, pgbedrock for PostgreSQL): it reads the real catalog without crashing on what it doesn't model, issues only the difference instead of every grant on every run, and plans revokes and drops but applies them only when you ask.

Where it runs

PostgreSQL 14 to 18 and Amazon Redshift (provisioned or Serverless). PostgreSQL services work through the same connection: Supabase, Google's AlloyDB, Amazon RDS and Aurora, Cloud SQL, Neon; connect as the platform's admin role. Referring to a platform's built-in roles (authenticated, alloydbsuperuser, ...) without managing them, and Supabase's row-level security policies, are on the roadmap.

Install

uv tool install pgsesame               # installs the `sesame` command
uv tool install "pgsesame[redshift]"   # adds IAM credentials and the Data API for Redshift
uvx pgsesame --help                    # or try it without installing
pip install pgsesame                   # or into an environment

In CI without Python, use the image (amd64 and arm64):

docker run --rm -v "$PWD:/work" -e SESAME_DSN ghcr.io/almostly/pgsesame plan permissions.yaml

pgsesame connects the way you already do: a DSN or the standard PG* variables with a password (PostgreSQL and Redshift), temporary credentials from IAM for a Redshift cluster or Serverless workgroup, or the Redshift Data API when the database isn't reachable over the network.

A spec

version: 1
engine: redshift            # or postgres

principals:
  reader:
    type: role
    privileges:
      schemas:
        usage: [analytics]
      tables:
        select: [analytics.*]

  alice:
    type: user
    password_env: ALICE_PASSWORD
    member_of: [reader]
sesame validate permissions.yaml
sesame plan permissions.yaml       # exit code 2 when there are changes
sesame apply permissions.yaml      # revokes and drops need --allow-revoke / --allow-drop

sesame plan permissions.yaml -o changes.json   # save the plan as a change set
sesame show changes.json                       # review it, no database needed
sesame apply changes.json                      # run exactly that, or refuse if it's stale

Passwords never go in the spec: name an environment variable with password_env, use IAM, or set password: disabled.

A first plan creates the roles and grants the spec declares:

sesame plan: the roles and grants a spec needs

Later, two grants someone made by hand show up as drift; they are revoked only with --allow-revoke:

sesame plan: drift, planned as revokes

A saved change set can be reviewed without a database, then applied exactly:

sesame show: a saved change set

Testing locally

The integration tests run against PostgreSQL in Docker and against oblako's local Redshift, so a spec can be planned and applied in CI before it touches a real cluster.

License

Apache-2.0

Metadata

Release files for pgsesame 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pgsesame 0.1.0
File Size Uploaded
pgsesame-0.1.0.tar.gz 511.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pgsesame 0.1.0
File Interpreter ABI Platform
pgsesame-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 542.5 kB

Release files / pgsesame-0.1.0.tar.gz

Download URL pgsesame-0.1.0.tar.gz
Size 511.8 kB
Tags Source
SHA-256 checksum
How to use checksums
734b6efce58cf893e1f097fe2859447b28cb6d64435812f90b2ee25df64c6568
BLAKE2b-256 checksum
How to use checksums
98a78b114d6a8f30eba427719a3b9095048afa64f2544b39e444c6fc87e58f8a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / pgsesame-0.1.0-py3-none-any.whl

Download URL pgsesame-0.1.0-py3-none-any.whl
Size 30.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ee942955e952591a2a9a375c85d1ff59e960a857d9aad053ea007a658e6d2d54
BLAKE2b-256 checksum
How to use checksums
637bd935c477e0877c53f69e708b562b840d2e1b5736f6e92b59a9c29205c175
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page