↑↓ 选择↵ 打开⌫ 切换范围完整搜索

PG.CENTER 连接 PostgreSQL 文档、百科与生态知识。由 Pigsty 维护。

Wiki / 命令行工具

createuser

createuser — define a new PostgreSQL user account

当前阅读 PG 18·选择有来源记录的版本

此版本暂无所选语言的定义,以下显示原始英文内容。

Documented executable
createuser
Executable version
18.6
Reference inventory
Client applications
Option definition groups
30
environment
map[description:Default connection parameters name:PGHOST PGPORT PGUSER], map[description:Specifies whether to use color in diagnostic messages. Possible values are always , auto and never . name:PG_COLOR]
manual path
app-createuser.html
signature
createuser [ connection-option ...] [ option ...] [ username ]
synopsis
createuser [ connection-option ...] [ option ...] [ username ]

版本定义 PG 18

createuser

createuser — define a new PostgreSQL user account

Synopsis

createuser [connection-option...] [option...] [username]

Description

createuser creates a new PostgreSQL user (or more precisely, a role). Only superusers and users with CREATEROLE privilege can create new users, so createuser must be invoked by someone who can connect as a superuser or a user with CREATEROLE privilege.

If you wish to create a role with the SUPERUSER, REPLICATION, or BYPASSRLS privilege, you must connect as a superuser, not merely with CREATEROLE privilege. Being a superuser implies the ability to bypass all access permission checks within the database, so superuser access should not be granted lightly. CREATEROLE also conveys very extensive privileges.

createuser is a wrapper around the SQL command CREATE ROLE. There is no effective difference between creating users via this utility and via other methods for accessing the server.

Options

createuser accepts the following command-line arguments:

username

Specifies the name of the PostgreSQL user to be created. This name must be different from all existing roles in this PostgreSQL installation.

-a role
--with-admin=role

Specifies an existing role that will be automatically added as a member of the new role with admin option, giving it the right to grant membership in the new role to others. Multiple existing roles can be specified by writing multiple -a switches.

-c number
--connection-limit=number

Set a maximum number of connections for the new user. The default is to set no limit.

-d
--createdb

The new user will be allowed to create databases.

-D
--no-createdb

The new user will not be allowed to create databases. This is the default.

-e
--echo

Echo the commands that createuser generates and sends to the server.

-E
--encrypted

This option is obsolete but still accepted for backward compatibility.

-g role
--member-of=role
--role=role (deprecated)

Specifies the new role should be automatically added as a member of the specified existing role. Multiple existing roles can be specified by writing multiple -g switches.

-i
--inherit

The new role will automatically inherit privileges of roles it is a member of. This is the default.

-I
--no-inherit

The new role will not automatically inherit privileges of roles it is a member of.

--interactive

Prompt for the user name if none is specified on the command line, and also prompt for whichever of the options -d/-D, -r/-R, -s/-S is not specified on the command line. (This was the default behavior up to PostgreSQL 9.1.)

-l
--login

The new user will be allowed to log in (that is, the user name can be used as the initial session user identifier). This is the default.

-L
--no-login

The new user will not be allowed to log in. (A role without login privilege is still useful as a means of managing database permissions.)

-m role
--with-member=role

Specifies an existing role that will be automatically added as a member of the new role. Multiple existing roles can be specified by writing multiple -m switches.

-P
--pwprompt

If given, createuser will issue a prompt for the password of the new user. This is not necessary if you do not plan on using password authentication.

-r
--createrole

The new user will be allowed to create, alter, drop, comment on, change the security label for other roles; that is, this user will have CREATEROLE privilege. See role creation for more details about what capabilities are conferred by this privilege.

-R
--no-createrole

The new user will not be allowed to create new roles. This is the default.

-s
--superuser

The new user will be a superuser.

-S
--no-superuser

The new user will not be a superuser. This is the default.

-v timestamp
--valid-until=timestamp

Set a date and time after which the role's password is no longer valid. The default is to set no password expiry date.

-V
--version

Print the createuser version and exit.

--bypassrls

The new user will bypass every row-level security (RLS) policy.

--no-bypassrls

The new user will not bypass row-level security (RLS) policies. This is the default.

--replication

The new user will have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE.

--no-replication

The new user will not have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE. This is the default.

-?
--help

Show help about createuser command line arguments, and exit.

createuser also accepts the following command-line arguments for connection parameters:

-h host
--host=host

Specifies the host name of the machine on which the server is running. If the value begins with a slash, it is used as the directory for the Unix domain socket.

-p port
--port=port

Specifies the TCP port or local Unix domain socket file extension on which the server is listening for connections.

-U username
--username=username

User name to connect as (not the user name to create).

-w
--no-password

Never issue a password prompt. If the server requires password authentication and a password is not available by other means such as a .pgpass file, the connection attempt will fail. This option can be useful in batch jobs and scripts where no user is present to enter a password.

-W
--password

Force createuser to prompt for a password (for connecting to the server, not for the password of the new user).

This option is never essential, since createuser will automatically prompt for a password if the server demands password authentication. However, createuser will waste a connection attempt finding out that the server wants a password. In some cases it is worth typing -W to avoid the extra connection attempt.

Environment

PGHOST
PGPORT
PGUSER

Default connection parameters

PG_COLOR

Specifies whether to use color in diagnostic messages. Possible values are always, auto and never.

This utility, like most other PostgreSQL utilities, also uses the environment variables supported by libpq (see Section 32.15).

Diagnostics

In case of difficulty, see CREATE ROLE and psql for discussions of potential problems and error messages. The database server must be running at the targeted host. Also, any default connection settings and environment variables used by the libpq front-end library will apply.

Examples

To create a user joe on the default database server:

$ createuser joe

To create a user joe on the default database server with prompting for some additional attributes:

$ createuser --interactive joe
Shall the new role be a superuser? (y/n) n
Shall the new role be allowed to create databases? (y/n) n
Shall the new role be allowed to create more new roles? (y/n) n

To create the same user joe using the server on host eden, port 5000, with attributes explicitly specified, taking a look at the underlying command:

$ createuser -h eden -p 5000 -S -D -R -e joe
CREATE ROLE joe NOSUPERUSER NOCREATEDB NOCREATEROLE INHERIT LOGIN;

To create the user joe as a superuser, and assign a password immediately:

$ createuser -P -s -e joe
Enter password for new role: xyzzy
Enter it again: xyzzy
CREATE ROLE joe PASSWORD 'SCRAM-SHA-256$4096:44560wPMLfjqiAzyPDZ/eQ==$4CA054rZlSFEq8Z3FEhToBTa2X6KnWFxFkPwIbKoDe0=:L/nbSZRCjp6RhOhKK56GoR1zibCCSePKshCJ9lnl3yw=' SUPERUSER CREATEDB CREATEROLE INHERIT LOGIN NOREPLICATION NOBYPASSRLS;

In the above example, the new password isn't actually echoed when typed, but we show what was typed for clarity. As you see, the password is encrypted before it is sent to the client.

Documented options

Option and argumentsDescription
-a role --with-admin= roleSpecifies an existing role that will be automatically added as a member of the new role with admin option, giving it the right to grant membership in the new role to others. Multiple existing roles can be specified by writing multiple -a switches.
-c number --connection-limit= numberSet a maximum number of connections for the new user. The default is to set no limit.
-d --createdbThe new user will be allowed to create databases.
-D --no-createdbThe new user will not be allowed to create databases. This is the default.
-e --echoEcho the commands that createuser generates and sends to the server.
-E --encryptedThis option is obsolete but still accepted for backward compatibility.
-g role --member-of= role --role= role (deprecated)Specifies the new role should be automatically added as a member of the specified existing role. Multiple existing roles can be specified by writing multiple -g switches.
-i --inheritThe new role will automatically inherit privileges of roles it is a member of. This is the default.
-I --no-inheritThe new role will not automatically inherit privileges of roles it is a member of.
--interactivePrompt for the user name if none is specified on the command line, and also prompt for whichever of the options -d / -D , -r / -R , -s / -S is not specified on the command line. (This was the default behavior up to PostgreSQL 9.1.)
-l --loginThe new user will be allowed to log in (that is, the user name can be used as the initial session user identifier). This is the default.
-L --no-loginThe new user will not be allowed to log in. (A role without login privilege is still useful as a means of managing database permissions.)
-m role --with-member= roleSpecifies an existing role that will be automatically added as a member of the new role. Multiple existing roles can be specified by writing multiple -m switches.
-P --pwpromptIf given, createuser will issue a prompt for the password of the new user. This is not necessary if you do not plan on using password authentication.
-r --createroleThe new user will be allowed to create, alter, drop, comment on, change the security label for other roles; that is, this user will have CREATEROLE privilege. See role creation for more details about what capabilities are conferred by this privilege.
-R --no-createroleThe new user will not be allowed to create new roles. This is the default.
-s --superuserThe new user will be a superuser.
-S --no-superuserThe new user will not be a superuser. This is the default.
-v timestamp --valid-until= timestampSet a date and time after which the role's password is no longer valid. The default is to set no password expiry date.
-V --versionPrint the createuser version and exit.
--bypassrlsThe new user will bypass every row-level security (RLS) policy.
--no-bypassrlsThe new user will not bypass row-level security (RLS) policies. This is the default.
--replicationThe new user will have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE .
--no-replicationThe new user will not have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE . This is the default.
-? --helpShow help about createuser command line arguments, and exit.
-h host --host= hostSpecifies the host name of the machine on which the server is running. If the value begins with a slash, it is used as the directory for the Unix domain socket.
-p port --port= portSpecifies the TCP port or local Unix domain socket file extension on which the server is listening for connections.
-U username --username= usernameUser name to connect as (not the user name to create).
-w --no-passwordNever issue a password prompt. If the server requires password authentication and a password is not available by other means such as a .pgpass file, the connection attempt will fail. This option can be useful in batch jobs and scripts where no user is present to enter a password.
-W --passwordForce createuser to prompt for a password (for connecting to the server, not for the password of the new user).

Environment variables

VariableMeaning
PGHOST PGPORT PGUSERDefault connection parameters
PG_COLORSpecifies whether to use color in diagnostic messages. Possible values are always , auto and never .

比较版本

完整来源事实

options

map[description:Specifies an existing role that will be automatically added as a member of the new role with admin option, giving it the right to grant membership in the new role to others. Multiple existing roles can be specified by writing multiple -a switches. names:[-a role --with-admin= role] signature:-a role --with-admin= role source_url:/docs/18/app-createuser.html summary:Specifies an existing role that will be automatically added as a member of the new role with admin option, giving it the right to grant membership in the new role to others. Multiple existing roles can be specified by writing multiple -a switches.], map[description:Set a maximum number of connections for the new user. The default is to set no limit. names:[-c number --connection-limit= number] signature:-c number --connection-limit= number source_url:/docs/18/app-createuser.html summary:Set a maximum number of connections for the new user. The default is to set no limit.], map[description:The new user will be allowed to create databases. names:[-d --createdb] signature:-d --createdb source_url:/docs/18/app-createuser.html summary:The new user will be allowed to create databases.], map[description:The new user will not be allowed to create databases. This is the default. names:[-D --no-createdb] signature:-D --no-createdb source_url:/docs/18/app-createuser.html summary:The new user will not be allowed to create databases. This is the default.], map[description:Echo the commands that createuser generates and sends to the server. names:[-e --echo] signature:-e --echo source_url:/docs/18/app-createuser.html summary:Echo the commands that createuser generates and sends to the server.], map[description:This option is obsolete but still accepted for backward compatibility. names:[-E --encrypted] signature:-E --encrypted source_url:/docs/18/app-createuser.html summary:This option is obsolete but still accepted for backward compatibility.], map[description:Specifies the new role should be automatically added as a member of the specified existing role. Multiple existing roles can be specified by writing multiple -g switches. names:[-g role --member-of= role --role= role] signature:-g role --member-of= role --role= role (deprecated) source_url:/docs/18/app-createuser.html summary:Specifies the new role should be automatically added as a member of the specified existing role. Multiple existing roles can be specified by writing multiple -g switches.], map[description:The new role will automatically inherit privileges of roles it is a member of. This is the default. names:[-i --inherit] signature:-i --inherit source_url:/docs/18/app-createuser.html summary:The new role will automatically inherit privileges of roles it is a member of. This is the default.], map[description:The new role will not automatically inherit privileges of roles it is a member of. names:[-I --no-inherit] signature:-I --no-inherit source_url:/docs/18/app-createuser.html summary:The new role will not automatically inherit privileges of roles it is a member of.], map[description:Prompt for the user name if none is specified on the command line, and also prompt for whichever of the options -d / -D , -r / -R , -s / -S is not specified on the command line. (This was the default behavior up to PostgreSQL 9.1.) names:[--interactive] signature:--interactive source_url:/docs/18/app-createuser.html summary:Prompt for the user name if none is specified on the command line, and also prompt for whichever of the options -d / -D , -r / -R , -s / -S is not specified on the command line. (This was the default behavior up to PostgreSQL 9.1.)], map[description:The new user will be allowed to log in (that is, the user name can be used as the initial session user identifier). This is the default. names:[-l --login] signature:-l --login source_url:/docs/18/app-createuser.html summary:The new user will be allowed to log in (that is, the user name can be used as the initial session user identifier). This is the default.], map[description:The new user will not be allowed to log in. (A role without login privilege is still useful as a means of managing database permissions.) names:[-L --no-login] signature:-L --no-login source_url:/docs/18/app-createuser.html summary:The new user will not be allowed to log in. (A role without login privilege is still useful as a means of managing database permissions.)], map[description:Specifies an existing role that will be automatically added as a member of the new role. Multiple existing roles can be specified by writing multiple -m switches. names:[-m role --with-member= role] signature:-m role --with-member= role source_url:/docs/18/app-createuser.html summary:Specifies an existing role that will be automatically added as a member of the new role. Multiple existing roles can be specified by writing multiple -m switches.], map[description:If given, createuser will issue a prompt for the password of the new user. This is not necessary if you do not plan on using password authentication. names:[-P --pwprompt] signature:-P --pwprompt source_url:/docs/18/app-createuser.html summary:If given, createuser will issue a prompt for the password of the new user. This is not necessary if you do not plan on using password authentication.], map[description:The new user will be allowed to create, alter, drop, comment on, change the security label for other roles; that is, this user will have CREATEROLE privilege. See role creation for more details about what capabilities are conferred by this privilege. names:[-r --createrole] signature:-r --createrole source_url:/docs/18/app-createuser.html summary:The new user will be allowed to create, alter, drop, comment on, change the security label for other roles; that is, this user will have CREATEROLE privilege. See role creation for more details about what capabilities are conferred by this privilege.], map[description:The new user will not be allowed to create new roles. This is the default. names:[-R --no-createrole] signature:-R --no-createrole source_url:/docs/18/app-createuser.html summary:The new user will not be allowed to create new roles. This is the default.], map[description:The new user will be a superuser. names:[-s --superuser] signature:-s --superuser source_url:/docs/18/app-createuser.html summary:The new user will be a superuser.], map[description:The new user will not be a superuser. This is the default. names:[-S --no-superuser] signature:-S --no-superuser source_url:/docs/18/app-createuser.html summary:The new user will not be a superuser. This is the default.], map[description:Set a date and time after which the role's password is no longer valid. The default is to set no password expiry date. names:[-v timestamp --valid-until= timestamp] signature:-v timestamp --valid-until= timestamp source_url:/docs/18/app-createuser.html summary:Set a date and time after which the role's password is no longer valid. The default is to set no password expiry date.], map[description:Print the createuser version and exit. names:[-V --version] signature:-V --version source_url:/docs/18/app-createuser.html summary:Print the createuser version and exit.], map[description:The new user will bypass every row-level security (RLS) policy. names:[--bypassrls] signature:--bypassrls source_url:/docs/18/app-createuser.html summary:The new user will bypass every row-level security (RLS) policy.], map[description:The new user will not bypass row-level security (RLS) policies. This is the default. names:[--no-bypassrls] signature:--no-bypassrls source_url:/docs/18/app-createuser.html summary:The new user will not bypass row-level security (RLS) policies. This is the default.], map[description:The new user will have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE . names:[--replication] signature:--replication source_url:/docs/18/app-createuser.html summary:The new user will have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE .], map[description:The new user will not have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE . This is the default. names:[--no-replication] signature:--no-replication source_url:/docs/18/app-createuser.html summary:The new user will not have the REPLICATION privilege, which is described more fully in the documentation for CREATE ROLE . This is the default.], map[description:Show help about createuser command line arguments, and exit. names:[-? --help] signature:-? --help source_url:/docs/18/app-createuser.html summary:Show help about createuser command line arguments, and exit.], map[description:Specifies the host name of the machine on which the server is running. If the value begins with a slash, it is used as the directory for the Unix domain socket. names:[-h host --host= host] signature:-h host --host= host source_url:/docs/18/app-createuser.html summary:Specifies the host name of the machine on which the server is running. If the value begins with a slash, it is used as the directory for the Unix domain socket.], map[description:Specifies the TCP port or local Unix domain socket file extension on which the server is listening for connections. names:[-p port --port= port] signature:-p port --port= port source_url:/docs/18/app-createuser.html summary:Specifies the TCP port or local Unix domain socket file extension on which the server is listening for connections.], map[description:User name to connect as (not the user name to create). names:[-U username --username= username] signature:-U username --username= username source_url:/docs/18/app-createuser.html summary:User name to connect as (not the user name to create).], map[description:Never issue a password prompt. If the server requires password authentication and a password is not available by other means such as a .pgpass file, the connection attempt will fail. This option can be useful in batch jobs and scripts where no user is present to enter a password. names:[-w --no-password] signature:-w --no-password source_url:/docs/18/app-createuser.html summary:Never issue a password prompt. If the server requires password authentication and a password is not available by other means such as a .pgpass file, the connection attempt will fail. This option can be useful in batch jobs and scripts where no user is present to enter a password.], map[description:Force createuser to prompt for a password (for connecting to the server, not for the password of the new user). This option is never essential, since createuser will automatically prompt for a password if the server demands password authentication. However, createuser will waste a connection attempt finding out that the server wants a password. In some cases it is worth typing -W to avoid the extra connection attempt. names:[-W --password] signature:-W --password source_url:/docs/18/app-createuser.html summary:Force createuser to prompt for a password (for connecting to the server, not for the password of the new user).]

来源引用

完整定义与证据 JSON

定义来源

center · PostgreSQL 18 · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8

正文语言: en · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8