Grant, Update and delete roles in Cassandra Database
06:45 14 Nov 2025

I have a pipeline to grant roles access to Cassandra database. But it is not working if I remove any keyspace permission and the updated keyspace pernission in the code is not getting updated for the role. Same issue goes for deleting any roles from the code, it is not getting updated using this pipeline. Then I have to manually drop this role.

Code written for give_permission.cql.j2

{% for new in permissions %}
{% if new.keyspace == "ALL" %}
{% if new.permission == "ALL" %}
GRANT ALL PERMISSIONS ON ALL KEYSPACES TO {{username}};
{% else %}
GRANT {{new.permission}} ON ALL KEYSPACES TO {{username}};
{% endif %}
{% else %}
{% if new.permission == "ALL" %}
GRANT ALL PERMISSIONS ON KEYSPACE {{new.keyspace}} TO {{username}};
{% elif new.permission == "EXECUTE" %}
GRANT {{new.permission}} ON ALL FUNCTIONS IN KEYSPACE {{new.keyspace}} TO {{username}};
{% else %}
GRANT {{new.permission}} ON KEYSPACE {{new.keyspace}} TO {{username}};
{% endif %}
{% endif %}
{% endfor %}
EXIT;

rbac.yml file for the keypsace -

---
all:
  vars:
    apis_roles:                                      
      - name: "app1" 
        password: "__password__" 
        permissions: 
          - { keyspace: "keyspace1", permission: "DESCRIBE"}
          - { keyspace: "keyspace2", permission: "SELECT"}

      - name: "app2" 
        password: "__password__" 
        permissions: 
          - { keyspace: "keyspace3", permission: "DESCRIBE"}
          - { keyspace: "keyspace4", permission: "SELECT"}
cassandra cqlsh