CannotModifyUsersOrRoles
Last updated: January 30, 2026
CannotModifyUsersOrRoles is a custom policy check that prevents the following statements from occurring for users and roles:
Do not allow the following statements for USER:
CREATE [OR REPLACE] USER DROP USER ALTER USER RENAME USER Do not allow the following statements for ROLE:
CREATE [OR REPLACE] ROLE DROP ROLE SET ROLE regex: (?is)(?=.*\b(create|replace|drop|alter|rename|set)\b)(?=.*\b(user|role)\b).*
This example utilizes MariaDB. You can use this check as it is or customize it further to fit your needs in your SQL database. All Regex Custom Policy Checks can only run against the changelog, not against the database.
Before you begin
Scope | Database |
changelog | MariaDB |
Liquibase 4.29.0+
Configure a valid Liquibase Pro license key
Ensure the Liquibase Checks extension is installed. In Liquibase 4.31.0+, it is already installed in the
/liquibase/internal/libdirectory, so no action is needed.If the checks JAR is not installed, download
liquibase-checks-<version>.jarand put it in theliquibase/libdirectory.Maven users only: Add this dependency to your
pom.xmlfile:<dependency> <groupId>org.liquibase.ext</groupId> <artifactId>liquibase-checks</artifactId> <version>2.0.0</version> </dependency>Java Development Kit 17+ (available for Open JDK and Oracle JDK)
Linux, macOS, or Windows operating system
Procedure
These steps describe how to create the Custom Policy Check. It does not exist by default in Liquibase Pro.
Run this command in the CLI:
liquibase checks customize --check-name=SqlUserDefinedPatternCheckGive your check a short name for easy identification
Use up to 64 alpha-numeric characters only.
CannotModifyUsersOrRolesSet the Severity to return a code of 0-4 when triggered.
These severity codes allow you to determine if the job moves forward or stops when this check triggers.
Learn more here: Use Policy Checks in Automation: Severity and Exit Code
options: 'INFO'=0, 'MINOR'=1, 'MAJOR'=2, 'CRITICAL'=3, 'BLOCKER'=4
Set the SEARCH_STRING to this valid regular expression:
Regular expression search string
(?is)(?=.*\b(create|replace|drop|alter|rename|set)\b)(?=.*\b(user|role)\b).*Set the MESSAGE to display when a match for the regular expression <SEARCH_STRING> is found in a Changeset.
In this example we will use:
Modifying USER or ROLE is prohibited.Set STRIP_COMMENTS to true if you want to remove the comments from the output.
Sample Failing Scripts for USER
CREATE [OR REPLACE] USER lb_user
IDENTIFIED BY L!QU!B@S3
DEFAULT TABLESPACE lb_tbsp
QUOTA 10M ON lb_tbsp
QUOTA 5M ON system
PROFILE app_user
PASSWORD EXPIRE;
DROP USER lb_user;
ALTER USER lb_user
IDENTIFIED BY L1QU1B@&3
DEFAULT TABLESPACE lb_tbsp;
RENAME USER 'lb_user' TO 'liquibase';
Sample Failing Scripts for ROLE
CREATE [OR REPLACE] ROLE lb_role;
DROP ROLE lb_role;
SET ROLE lb_role;
Sample Error Message
CHANGELOG CHECKS
----------------
Checks completed validation of the changelog and found the following issues:
Check Name: Check for specific patterns in sql (CannotModifyUsersOrRoles)
Changeset ID: 01
Changeset Filepath: sql/main/100_ddl/97_alter_user.sql
Check Severity: MAJOR (Return code: 2)
Message: Modifying USER or ROLE is prohibited.