role_mappings
The role_mappings table lists role mappings, their associated authentication integrations, rule definitions, and creation and modification details.
Note:
Supported since VeloDB Enterprise 4.1.4.
Database
information_schema
Columns
| Column | Type | Description |
|---|---|---|
NAME | varchar(256) | Role mapping name. |
INTEGRATION_NAME | varchar(256) | Authentication integration associated with the mapping. |
RULES | string | Formatted rule definitions. |
COMMENT | string | Role mapping comment. |
CREATE_USER | string | User who created the mapping. |
CREATE_TIME | string | Creation time. |
ALTER_USER | string | User who most recently modified the mapping. |
MODIFY_TIME | string | Most recent modification time. |
Access control
Only users with ADMIN_PRIV can view data in this table. Other users can query the table, but the result is empty.
Examples
List all role mappings:
SELECT * FROM information_schema.role_mappings;
Find a mapping by authentication integration:
SELECT name, integration_name, rules, comment
FROM information_schema.role_mappings
WHERE integration_name = 'corp_oidc';
Find a mapping by name:
SELECT name, integration_name, rules, create_user, create_time, modify_time
FROM information_schema.role_mappings
WHERE name = 'corp_oidc_roles';
Usage notes
RULEScontains a formatted rule string rather than the original SQL statement.- A rule is formatted as
RULE (USING CEL '...' GRANT ROLE role1, role2). Multiple rules are separated by;. - Each authentication integration can have at most one role mapping, so a query filtered by
INTEGRATION_NAMEreturns at most one row. - This table shows saved definitions. It does not indicate whether a rule matched a particular login. Verify the rules by logging in and checking the session roles.