For AI agents: the complete documentation index is at llms.txt. Every page is also available as markdown by appending .md to its URL, or by sending an Accept: text/markdown request header.

ALTER GROUP reference

Enterprise

RBAC provides fine-grained database permissions management.

Learn more

ALTER GROUP modifies group settings.

For full documentation of the Access Control List and Role-based Access Control, see the RBAC operations page.


Syntax

Set or clear memory limit
ALTER GROUP groupName SET MEMORY LIMIT { size | UNLIMITED };
Add or remove external alias
ALTER GROUP groupName { WITH | DROP } EXTERNAL ALIAS externalAlias;

Description

  • ALTER GROUP groupName SET MEMORY LIMIT size - caps the native memory that each query run by a member of the group may allocate. size is a byte count or a size with a K, M, or G suffix, such as 512M or 2G.
  • ALTER GROUP groupName SET MEMORY LIMIT UNLIMITED - clears the group's limit. Members then fall back to their own limit, another group's limit, or the workload limit. SET MEMORY LIMIT 0 does the same.
  • ALTER GROUP groupName WITH EXTERNAL ALIAS externalAlias - maps an external OIDC or LDAP group to this group.
  • ALTER GROUP groupName DROP EXTERNAL ALIAS externalAlias - removes an external group mapping.

Adding an alias requires the ADD EXTERNAL ALIAS permission and removing one requires REMOVE EXTERNAL ALIAS.

A group limit applies to a member only when that member has no limit of its own. When several of a user's groups set a limit, the most restrictive one applies. Setting a group limit requires the SET MEMORY LIMIT permission. See memory limits for how a group limit interacts with the cairo.query.memory.limit.bytes workload limit.

For external group mapping with OIDC or LDAP, see the OpenID Connect (OIDC) integration guide.

Examples

Set memory limit

-- cap queries of the group's members at 2 GiB of native memory
ALTER GROUP analysts SET MEMORY LIMIT 2G;
-- remove the limit
ALTER GROUP analysts SET MEMORY LIMIT UNLIMITED;

The configured value can be verified with SHOW GROUPS, which reports it in the memory_limit column.

Map an external group

ALTER GROUP analysts WITH EXTERNAL ALIAS 'CN=Analysts,OU=Users,DC=example,DC=com';
ALTER GROUP analysts DROP EXTERNAL ALIAS 'CN=Analysts,OU=Users,DC=example,DC=com';