-- Idempotent controls not expressible in the installed CNPG managed.roles CRD. -- Apply as the controlled apps-pg cluster administrator only after notifying -- bound consumers of the published limits in docs/s3-consumer-interfaces.md. -- The third consumer is scoped separately in helm/vergabe-demo-company-controls.sql; -- do not reuse this historical file to onboard it. ALTER ROLE vergabe SET statement_timeout = '15s'; ALTER ROLE vergabe SET idle_in_transaction_session_timeout = '15s'; ALTER ROLE coulomb_social SET statement_timeout = '15s'; ALTER ROLE coulomb_social SET idle_in_transaction_session_timeout = '15s'; -- PostgreSQL grants CONNECT and TEMPORARY to PUBLIC by default. A database per -- consumer is not an isolation boundary until those defaults are removed. REVOKE CONNECT, TEMPORARY ON DATABASE apps_meta FROM PUBLIC; REVOKE CONNECT, TEMPORARY ON DATABASE vergabe_db FROM PUBLIC; REVOKE CONNECT, TEMPORARY ON DATABASE coulomb_social_db FROM PUBLIC; GRANT CONNECT, TEMPORARY ON DATABASE vergabe_db TO vergabe; GRANT CONNECT, TEMPORARY ON DATABASE coulomb_social_db TO coulomb_social;