Secure schema information
The schema information and corresponding operation information is stored in system and system_schema keyspaces.
By default when HCD Unified Authentication is enabled, roles are granted full access to the following tables.
| Keyspace | Table | Default access |
|---|---|---|
system |
local |
FULLNote |
peers |
FULLNote |
|
size_estimates |
Full |
|
available_ranges |
Full |
|
sstable_activity |
NONE |
|
IndexInfo |
NONE |
|
built_views |
NONE |
|
views_builds_in_progress |
NONE |
|
batches |
NONE |
|
paxos |
NONE |
|
peer_events |
NONE |
|
range_xfers |
NONE |
|
compaction_history |
NONE |
|
transferred_ranges |
NONE |
|
prepared_statements |
NONE |
|
repairs |
NONE |
|
nodesync_checkpoints |
NONE |
|
system_schema |
aggregates |
Full |
columns |
Full |
|
dropped_columns |
Full |
|
hidden_columns |
Full |
|
edges (Graph) |
Full |
|
functions |
Full |
|
indexes |
Full |
|
keyspaces |
Full |
|
tables |
Full |
|
triggers |
Full |
|
types |
Full |
|
vertices (Graph) |
Full |
|
views |
Full |
|
All roles have full access to the |
By default, roles do NOT have access to data in the system_auth, system_traces, and system_distributed keyspaces. To allow access grant SELECT permission on the keyspace or table.
Example
The following uses an internal non-superuser account, martin.
-
Create internal login role using
cqlsh:CREATE ROLE martin WITH LOGIN = true AND PASSWORD = 'password'; -
Login as martin:
LOGIN martin -
Count the number of tables in
system_schema.tablesthatmartincan list:SELECT count(*) FROM system_schema.tables;The results is the number of tables that exist cluster-wide.
count ------- 75 (1 rows)