Upgrade of PostgreSQL Flexible Server from v16.10 to v17 Failed

Guy Light 55 Reputation points
2025-07-25T13:17:37.87+00:00

I'm unable to upgrade an Azure PostgreSQL Flexible Server from 16.10 to 17. I have found the issue in the upgrade logs.

Since the permissions needed to be granted require azuresu I have no way to work around this, what needs to be configured to make this work?

(1 row)

CREATE ROLE "replication";

CREATE ROLE

ALTER ROLE "replication" WITH NOSUPERUSER INHERIT NOCREATEROLE NOCREATEDB LOGIN REPLICATION NOBYPASSRLS;

ALTER ROLE

ALTER ROLE "azuresu" SET "search_path" TO 'pg_catalog';

ALTER ROLE

GRANT "azure_pg_admin" TO "cleverAdmin" WITH ADMIN OPTION, INHERIT TRUE GRANTED BY "azuresu";

GRANT ROLE

GRANT "azure_pg_admin" TO "cleverAdmin" WITH INHERIT TRUE GRANTED BY "cleverAdmin";

psql:/datadrive/pg/17/pg_upgrade_output.d/20250725T021056.418/dump/pg_upgrade_dump_globals.sql:80: ERROR: permission denied to grant privileges as role "cleverAdmin"

DETAIL: The grantor must have the ADMIN option on role "azure_pg_admin".

Azure Database for PostgreSQL

Answer accepted by question author
Saraswathi Devadula 16,040 Reputation points Microsoft External Staff Moderator
2025-07-25T16:45:00.9266667+00:00

Hello Guy Light

I have discussed with internal product team, and they confirmed that the error you're getting is related to a known permissions issue introduced with PostgreSQL 16, where role grants with ADMIN OPTION can fail during major version upgrades due to stricter role validation. 

 

This is being addressed in the current rollout train, and scheduled for global deployment in the coming weeks. Your server will receive the fix during its next scheduled maintenance in next few weeks.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.