Skip to content
supautils

supautils

supautils : Extension that secures a cluster on a cloud environment

Overview

ID Extension Package Version Category License Language
7010
supautils
supautils
3.2.1
SEC
Apache-2.0
C
Attribute Has Binary Has Library Need Load Has DDL Relocatable Trusted
--sL---
No
Yes
Yes
No
no
no
Relationships
See Also
passwordcheck_cracklib
pgsodium
supabase_vault
pg_session_jwt
anon
pg_tde
pgsmcrypto
pgaudit

Packages

Type Repo Version PG Major Compatibility Package Pattern Dependencies
EXT
PIGSTY
3.2.1
18
17
16
15
14
supautils -
RPM
PIGSTY
3.2.1
18
17
16
15
14
supautils_$v -
DEB
PIGSTY
3.2.1
18
17
16
15
14
postgresql-$v-supautils -
Linux / PG PG18 PG17 PG16 PG15 PG14
el8.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
el8.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
el9.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
el9.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
el10.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
el10.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
d12.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
d12.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
d13.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
d13.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u22.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u22.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u24.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u24.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u26.x86_64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
u26.aarch64
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
PIGSTY 3.2.1
Package Version OS ORG SIZE File URL
supautils_18 3.2.1 el8.x86_64 pigsty 32.3 KiB supautils_18-3.2.1-1PIGSTY.el8.x86_64.rpm
supautils_18 3.2.1 el8.aarch64 pigsty 31.4 KiB supautils_18-3.2.1-1PIGSTY.el8.aarch64.rpm
supautils_18 3.2.1 el9.x86_64 pigsty 30.5 KiB supautils_18-3.2.1-1PIGSTY.el9.x86_64.rpm
supautils_18 3.2.1 el9.aarch64 pigsty 29.3 KiB supautils_18-3.2.1-1PIGSTY.el9.aarch64.rpm
supautils_18 3.2.1 el10.x86_64 pigsty 30.9 KiB supautils_18-3.2.1-1PIGSTY.el10.x86_64.rpm
supautils_18 3.2.1 el10.aarch64 pigsty 29.8 KiB supautils_18-3.2.1-1PIGSTY.el10.aarch64.rpm
postgresql-18-supautils 3.2.1 d12.x86_64 pigsty 25.3 KiB postgresql-18-supautils_3.2.1-1PIGSTY~bookworm_amd64.deb
postgresql-18-supautils 3.2.1 d12.aarch64 pigsty 24.1 KiB postgresql-18-supautils_3.2.1-1PIGSTY~bookworm_arm64.deb
postgresql-18-supautils 3.2.1 d13.x86_64 pigsty 25.5 KiB postgresql-18-supautils_3.2.1-1PIGSTY~trixie_amd64.deb
postgresql-18-supautils 3.2.1 d13.aarch64 pigsty 24.4 KiB postgresql-18-supautils_3.2.1-1PIGSTY~trixie_arm64.deb
postgresql-18-supautils 3.2.1 u22.x86_64 pigsty 26.7 KiB postgresql-18-supautils_3.2.1-1PIGSTY~jammy_amd64.deb
postgresql-18-supautils 3.2.1 u22.aarch64 pigsty 25.4 KiB postgresql-18-supautils_3.2.1-1PIGSTY~jammy_arm64.deb
postgresql-18-supautils 3.2.1 u24.x86_64 pigsty 26.2 KiB postgresql-18-supautils_3.2.1-1PIGSTY~noble_amd64.deb
postgresql-18-supautils 3.2.1 u24.aarch64 pigsty 25.2 KiB postgresql-18-supautils_3.2.1-1PIGSTY~noble_arm64.deb
postgresql-18-supautils 3.2.1 u26.x86_64 pigsty 26.4 KiB postgresql-18-supautils_3.2.1-1PIGSTY~resolute_amd64.deb
postgresql-18-supautils 3.2.1 u26.aarch64 pigsty 25.6 KiB postgresql-18-supautils_3.2.1-1PIGSTY~resolute_arm64.deb

Source

pig build pkg supautils;		# build rpm/deb

Install

Make sure PGDG and PIGSTY repo available:

pig repo add pgsql -u   # add both repo and update cache

Install this extension with pig:

pig install supautils;		# install via package name, for the active PG version

pig install supautils -v 18;   # install for PG 18
pig install supautils -v 17;   # install for PG 17
pig install supautils -v 16;   # install for PG 16
pig install supautils -v 15;   # install for PG 15
pig install supautils -v 14;   # install for PG 14

Config this extension to shared_preload_libraries:

shared_preload_libraries = 'supautils';

This extension does not need CREATE EXTENSION DDL command

Usage

Sources: README, homepage, releases

supautils is a loadable library that unlocks selected superuser-only PostgreSQL features for non-superusers through configuration. Upstream emphasizes that it adds no tables, functions, or security labels to the database.

Load it

Cluster-wide:

shared_preload_libraries = 'supautils'
supautils.privileged_role = 'your_privileged_role'

Per role:

ALTER ROLE role1 SET session_preload_libraries TO 'supautils';

Privileged role capabilities

The README documents a privileged proxy role that can create publications, foreign data wrappers, event triggers, and privileged extensions without granting SUPERUSER.

SET ROLE privileged_role;
CREATE PUBLICATION p FOR ALL TABLES;
DROP PUBLICATION p;

For event triggers, the README says privileged-role triggers run for non-superusers, skip superusers, and also skip reserved roles. It also documents one limitation: those triggers do not fire while creating publications, foreign data wrappers, or extensions.

Important configuration knobs

  • supautils.superuser
  • supautils.privileged_role
  • supautils.privileged_role_allowed_configs
  • supautils.privileged_extensions
  • supautils.extension_custom_scripts_path
  • supautils.constrained_extensions
  • supautils.extensions_parameter_overrides
  • supautils.policy_grants
  • supautils.drop_trigger_grants
  • supautils.reserved_roles
  • supautils.reserved_memberships
  • supautils.hint_roles
  • supautils.log_skipped_evtrigs

Useful examples

Allow a non-superuser to create specific privileged extensions:

supautils.privileged_extensions = 'hstore'

Allow a role to manage RLS policies on tables it does not own:

supautils.policy_grants = '{ "my_role": ["public.not_my_table"] }'

Force an extension into a specific schema on CREATE EXTENSION:

supautils.extensions_parameter_overrides = '{ "pg_cron": { "schema": "pg_catalog" } }'

Protect managed-service roles from CREATEROLE users:

supautils.reserved_roles = 'connector, storage_admin'
supautils.reserved_memberships = 'pg_read_server_files'

Release notes

  • v3.2.1 was released on 2026-04-02 and its published notes are maintenance-oriented; no new user-facing SQL surface is described there.
  • v3.2.0 added a hint when a GRANT privilege is missing.

Caveat

This extension is configuration-driven. When documenting it, prefer the GUCs and behavior guarantees in the README over implying database objects that upstream explicitly says it does not create.

Last updated on