RLS sounds great until it isn't — PlanetScale
PostgreSQL's Row Level Security sounds like a clean way to enforce access control at the database layer, but the foot-guns, pooling incompatibilities, and performance traps often make it more trouble than it's worth.
RLS sounds great until it isn't Josh Brown [ @ 0ximjosh ] | April 30, 2026 When you leave your house, go to sleep, or go do work in the yard, you lock your door. Maybe you have a gate or fence you lock too. Without these, anyone can waltz into your house and snoop around. Row Level Security (RLS) can be attractive to developers for numerous reasons, but the foot-guns and gotchas in RLS often outweigh the benefits. You probably want to keep your doors locked. Friends and family: Managing access RLS for Postgres lets administrators define security policies in their database, instead of the appli
Explore this link on the map →saved by
related reading
- Row Level Security | Supabase Docssupabase.com
- Scaling PostgreSQL to power 800 million ChatGPT users | OpenAIopenai.com
- Nine ways to shoot yourself in the foot with PostgreSQLphilbooth.me
- An Overview of Distributed PostgreSQL... | Crunchy Data Blogcrunchydata.com
- State of RL for reasoning LLMs | A. Weersaweers.de
- Databases are Fucking Stupid | Probably Danceprobablydance.com
- pthorpe92.devpthorpe92.dev
- Explaining The Postgres Memeavestura.dev
- PostgreSQL rocks, except when it blocks: Understanding locks - Citus Datacitusdata.com
- Databases in 2024: A Year in Review // Blog // Andy Pavlo - Carnegie Mellon Universitycs.cmu.edu
- Against SQLscattered-thoughts.net
- Scaling RAG from POC to Production | Towards Data Sciencetowardsdatascience.com