{"Entry":{"collection":"guc","key":"allow_alter_system","name":"allow_alter_system","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Version and Platform Compatibility / Other Platforms and Clients","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"16","status":"added","to":"17"},{"documentation_changed":true,"fields":{},"from":"17","status":"changed","to":"18"}],"content_hash":"ac5d7f9c9a7be323b7fb1ca8f735ffd8296165af1aac8ab52c64f5ce8b1bc9e1","context":"","default_changed_in":[],"default_history":[{"from":"17","to":"19","value":"on"}],"editorial":{"advice":{"olap":"Use the same policy as OLTP. If batch tooling calls ALTER SYSTEM, migrate it to the declarative configuration interface first so jobs do not begin failing silently after reload.","oltp":"A managed environment whose configuration controller owns postgresql.conf/auto.conf may disable it to narrow the SQL administration surface. Audit existing auto.conf and still restrict filesystem and superuser access.","small":"A single-admin instance may keep the default, but ALTER SYSTEM is not a change-audit system; retain versioned configuration, rollback, and restart/reload records."},"mechanism":["Allows running the ALTER SYSTEM command. A configuration reload applies a new value; existing work already in flight is not retroactively changed.","When off, PostgreSQL rejects ALTER SYSTEM before it can rewrite postgresql.auto.conf. The switch neither erases existing auto.conf entries nor prevents an operating-system administrator from editing configuration files, so it is an SQL administration boundary rather than a filesystem security boundary.","Monitor and change allow_alter_system together with config_file, data_directory, hba_file. Validate on the relevant server role and real workload, then use its sighup context to choose session change, reload, or restart; a historical boot default is not the current effective value."],"pitfalls":["Keeping a compatibility switch permanently instead of fixing the client.","Testing in one session and deploying globally to unrelated applications.","Confusing parsing compatibility with data or security compatibility.","Forgetting to remove an override after the upgrade migration is complete."],"references":[{"title":"PostgreSQL 19 Beta 4: allow_alter_system","url":"https://www.postgresql.org/docs/19/runtime-config-compatible.html#GUC-ALLOW-ALTER-SYSTEM"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["config_file","data_directory","hba_file","ident_file","external_pid_file","transform_null_equals"],"summary":"allow_alter_system allows running the ALTER SYSTEM command. It is a sighup setting present in PG17–18; the latest recorded boot default is on."},"enumvals":[],"first_version":"17","group":"Version and Platform Compatibility","group_slug":"compatible","imported_at":"2026-09-27T17:57:30.734048+08:00","intro_commit":{"authored_at":"2024-03-29T08:44:45-04:00","discussion":["https://postgr.es/m/CA%2BVUV5rEKt2%2BCdC_KUaPoihMu%2Bi5ChT4WVNTr4CD5-xXZUfuQw%40mail.gmail.com"],"hash":"d3ae2a24f265a028f4b9e8df79ea7b075c6cf016","subject":"Add allow_alter_system GUC.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=d3ae2a24f265a028f4b9e8df79ea7b075c6cf016"},"key":"allow_alter_system","last_version":"20","max_val":"","min_val":"","name":"allow_alter_system","position":4,"present_in":["17","18","19","20"],"short_desc":"When allow_alter_system is set to off, an error is returned if the ALTER SYSTEM command is executed.","short_desc_zh":"","source_rev":"english-manuals:8cbc232a3b822f5054c6546a008adc3f5003829673e4a1fcd56880521e0b95ea","unit":"","vartype":"bool"}},"Definition":{"Collection":"guc","Key":"allow_alter_system","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"allow_alter_system","SourceRevision":"english-manuals:8cbc232a3b822f5054c6546a008adc3f5003829673e4a1fcd56880521e0b95ea","Facts":{"boot_val":"on","category":"Version and Platform Compatibility / Other Platforms and Clients","context":"sighup","description":"When allow_alter_system is set to off, an error is returned if the ALTER SYSTEM command is executed. This parameter can only be set in the postgresql.conf file or on the server command line. The default value is on. Note that this setting must not be regarded as a security feature. It only disables the ALTER SYSTEM command. It does not prevent a superuser from changing the configuration using other SQL commands. A superuser has many ways of executing shell commands at the operating system level, and can therefore modify postgresql.auto.conf regardless of the value of this setting. Turning this setting off is intended for environments where the configuration of PostgreSQL is managed by some external tool. In such environments, a well-intentioned superuser might mistakenly use ALTER SYSTEM to change the configuration instead of using the external tool. This might result in unintended behavior, such as the external tool overwriting the change at some later point in time when it updates the configuration. Setting this parameter to off can help avoid such mistakes. This parameter only controls the use of ALTER SYSTEM. The settings stored in postgresql.auto.conf take effect even if allow_alter_system is set to off.","doc":{"anchor":"GUC-ALLOW-ALTER-SYSTEM","file":"runtime-config-compatible.html","lang":"en","sha256":"db2ecac1e62738d66a4932f4c8197976a349bcbf261c5b90fff740bc44867b8b","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Can be set to off for environments where global configuration changes should be made using a different method.","lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"allow_alter_system","short_desc":"Allows running the ALTER SYSTEM command.","source":"pg-settings-source-snapshot","unit":null,"vartype":"bool"},"ManualEvidence":{"doc":{"anchor":"GUC-ALLOW-ALTER-SYSTEM","file":"runtime-config-compatible.html","lang":"en","sha256":"db2ecac1e62738d66a4932f4c8197976a349bcbf261c5b90fff740bc44867b8b","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"allow_alter_system","SourceDatabase":"center","Version":"18","Locale":"en","Title":"allow_alter_system","Summary":"When allow_alter_system is set to off, an error is returned if the ALTER SYSTEM command is executed. This parameter can only be set in the postgresql.conf file or on the server command line. The default value is on. Note that this setting must not be regarded as a security feature. It only disables the ALTER SYSTEM command. It does not prevent a superuser from changing the configuration using other SQL commands. A superuser has many ways of executing shell commands at the operating system level, and can therefore modify postgresql.auto.conf regardless of the value of this setting. Turning this setting off is intended for environments where the configuration of PostgreSQL is managed by some external tool. In such environments, a well-intentioned superuser might mistakenly use ALTER SYSTEM to change the configuration instead of using the external tool. This might result in unintended behavior, such as the external tool overwriting the change at some later point in time when it updates the configuration. Setting this parameter to off can help avoid such mistakes. This parameter only controls the use of ALTER SYSTEM. The settings stored in postgresql.auto.conf take effect even if allow_alter_system is set to off.","BodyHTML":"\u003cp\u003eWhen allow_alter_system is set to off, an error is returned if the ALTER SYSTEM command is executed. This parameter can only be set in the postgresql.conf file or on the server command line. The default value is on. Note that this setting must not be regarded as a security feature. It only disables the ALTER SYSTEM command. It does not prevent a superuser from changing the configuration using other SQL commands. A superuser has many ways of executing shell commands at the operating system level, and can therefore modify postgresql.auto.conf regardless of the value of this setting. Turning this setting off is intended for environments where the configuration of PostgreSQL is managed by some external tool. In such environments, a well-intentioned superuser might mistakenly use ALTER SYSTEM to change the configuration instead of using the external tool. This might result in unintended behavior, such as the external tool overwriting the change at some later point in time when it updates the configuration. Setting this parameter to off can help avoid such mistakes. This parameter only controls the use of ALTER SYSTEM. The settings stored in postgresql.auto.conf take effect even if allow_alter_system is set to off.\u003c/p\u003e","SourceRevision":"english-manuals:8cbc232a3b822f5054c6546a008adc3f5003829673e4a1fcd56880521e0b95ea","ContentHash":"1581b41a0e096cbdaae9116d55f362f40264d03ad475e2df89024fcbf4ac7c51","Payload":{"description":"When allow_alter_system is set to off, an error is returned if the ALTER SYSTEM command is executed. This parameter can only be set in the postgresql.conf file or on the server command line. The default value is on. Note that this setting must not be regarded as a security feature. It only disables the ALTER SYSTEM command. It does not prevent a superuser from changing the configuration using other SQL commands. A superuser has many ways of executing shell commands at the operating system level, and can therefore modify postgresql.auto.conf regardless of the value of this setting. Turning this setting off is intended for environments where the configuration of PostgreSQL is managed by some external tool. In such environments, a well-intentioned superuser might mistakenly use ALTER SYSTEM to change the configuration instead of using the external tool. This might result in unintended behavior, such as the external tool overwriting the change at some later point in time when it updates the configuration. Setting this parameter to off can help avoid such mistakes. This parameter only controls the use of ALTER SYSTEM. The settings stored in postgresql.auto.conf take effect even if allow_alter_system is set to off."}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
