Sign inSign up

jabbermouth/sqlusercreator

By jabbermouth

Updated about 4 years ago

Image
0

493

jabbermouth/sqlusercreator repository overview

Overview

This allows a user account to be created in the specified database from the command line. TO use this an account with ALTER ANY LOGIN and either ALTER ANY ROLE or be in db_owner for the target database.

Purpose

This was developed to be used as part of a CI/CD process to generate a database account with a random and unknown to humans password. The specific use case would see it used along with Helm and Kubernetes.

From Docker

docker run --rm -e SQL_SERVER=your.sql.server -e SQL_DATABASE=YourDatabaseName -e SQL_USER=UserGenerator -e SQL_PASSWORD="ChangeToSecurePassword123!" -e ACCOUNT_USER="name-of-account-to-create" -e ACCOUNT_PASSWORD="SomethingRandom123!" jabbermouth/sqlusercreator

SQL_ prefixed variables are related to the target server and account with permission to create users

ACCOUNT_ prefixed variables are related to the new account to create

If running a high-availability setup, the variable of SQL_NODES can be passed as a comma-delimited list of each node name and it will create the login on each server.

Note: To support a consistent SID across servers, the login SID is generated using an MD5 hash of the ACCOUNT_USER field.

Account Setup

To create an account with the minimum required permissions across all databases, run the following:

CREATE LOGIN [UserGenerator] WITH PASSWORD='ChangeToSecurePassword123!'
GRANT ALTER ANY LOGIN TO [UserGenerator]
GRANT ALTER ANY ROLE TO [UserGenerator]

A sysadmin (e.g. sa) account will also work.

Tag summary

Content type

Image

Digest

sha256:5ba77cc86

Size

359.4 MB

Last updated

about 4 years ago

docker pull jabbermouth/sqlusercreator