Skip to main content
Version: 3.5 Stable

Native Authentication

Create and manage users using the native authentication within StarRocks through SQL commands.

StarRocks native authentication is a password-based authentication method. In addition to that, StarRocks also supports integrating with external authentication systems such as LDAP. For more instructions, see Authenticate with Security Integration.

note

Users with the system-defined role user_admin can create users, alter users, and drop users in StarRocks.

After a new cluster is deployed, an admin user is automatically created with the password defined during deployment. This admin user cannot be dropped, and has the system-defined roles user_admin and db_admin, effectively making it the default superuser for the cluster.

NOTE

  • The user used to log in to the cluster is different from the one used to log in to the PhoenixAI Cloud console.
  • Except for the admin user, all other cluster users must be created manually within the cluster by executing SQL statements.

Create user​

You can create a user by specifying the user identity, the authentication method, and optionally the default role. To enable the native authentication for the user, you need to explicitly specify the password in plaintext or ciphertext.

The following example creates the user jack, allows it to connect only from the IP address 172.10.1.10, enables the native authentication, sets the password to 12345 in plaintext, and assigns the role example_role to it as its default role:

CREATE USER jack@'172.10.1.10' IDENTIFIED BY '12345' DEFAULT ROLE 'example_role';
note
  • StarRocks encrypts users' passwords before storing them. You can get the encrypted password using the password() function.
  • A system-defined default role PUBLIC is assigned to a user if no default role is specified during user creation.

The default role of a user is automatically activated when the user connects to StarRocks. For instructions on how to enable all (default and granted) roles for a user after connection, see Enable all roles.

For more information and advanced instructions on creating a user, see CREATE USER.

Alter user​

You can alter the password, default role, or property for a user.

For instructions on how to alter the default role for a user, see Alter default role.

Alter the property of a user​

You can set the property of a user using ALTER USER.

The following example sets the maximum number of connections for user jack to 1000. User identities that have the same user name share the same property.

Therefore, you only need to set the property for jack and this setting takes effect for all the user identities with the user name jack.

ALTER USER 'jack' SET PROPERTIES ("max_user_connections" = "1000");

Reset password for a user​

You can reset the password for a user using SET PASSWORD or ALTER USER.

NOTE

  • Any user can reset their own passwords without needing any privileges.

Both the following examples reset the password of jack to 54321:

  • Reset the password using SET PASSWORD:

    SET PASSWORD FOR jack@'172.10.1.10' = PASSWORD('54321');
  • Reset the password using ALTER USER:

    ALTER USER jack@'172.10.1.10' IDENTIFIED BY '54321';

Reset password for admin user​

If you have lost the password of the admin user and cannot connect to the cluster, you can reset it only on the PhoenixAI Cloud console.

NOTE

Only PhoenixAI members with Edit cluster privilege on the cluster can reset the password for the cluster admin user.

Follow these steps:

  1. Sign in to the PhoenixAI Cloud console.

  2. On the Clusters page, click the cluster for which you want to reset the admin user password.

  3. On the cluster details page, click Manage and choose Reset password.

  4. On the dialog box that appears, enter a new password for the admin user, or generate a random password by clicking Generate password.

  5. Click Reset & Save to save the new password.

Drop a user​

You can drop a user using DROP USER.

The following example drops the user jack:

DROP USER jack@'172.10.1.10';

View users​

You can view all the users within the StarRocks cluster using SHOW USERS.

SHOW USERS;

View user property​

You can view the property of a user using SHOW PROPERTY.

The following example shows the property of the user jack:

SHOW PROPERTY FOR 'jack';

Or to view a specific property:

SHOW PROPERTY FOR 'jack' LIKE 'max_user_connections';