mirror of
https://github.com/EnterpriseDB/repmgr.git
synced 2026-03-23 15:16:29 +00:00
Compare commits
1 Commits
fix-local-
...
dev/FS-704
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
89f1936004 |
7
.github/CODEOWNERS
vendored
7
.github/CODEOWNERS
vendored
@@ -1,7 +0,0 @@
|
|||||||
# Each line is a file pattern followed by one or more owners.
|
|
||||||
|
|
||||||
# These owners will be the default owners for everything in
|
|
||||||
# the repo. Unless a later match takes precedence,
|
|
||||||
# @global-owner1 and @global-owner2 will be requested for
|
|
||||||
# review when someone opens a pull request.
|
|
||||||
* @EnterpriseDB/repmgr-dev
|
|
||||||
77
.github/workflows/sonarqube-scan.yml
vendored
Normal file
77
.github/workflows/sonarqube-scan.yml
vendored
Normal file
@@ -0,0 +1,77 @@
|
|||||||
|
###
|
||||||
|
# Foundation-security SonarQube workflow
|
||||||
|
# version: 2.1
|
||||||
|
###
|
||||||
|
name: Foundation-Security/SonarQube Scan
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
tags:
|
||||||
|
- "**"
|
||||||
|
branches:
|
||||||
|
- "*main*"
|
||||||
|
- "*master*"
|
||||||
|
- "*STABLE*"
|
||||||
|
pull_request:
|
||||||
|
types: [opened, synchronize, reopened]
|
||||||
|
branches:
|
||||||
|
- "**"
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
ref:
|
||||||
|
description: "Branch to scan"
|
||||||
|
required: true
|
||||||
|
default: "main"
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
SonarQube-Scan:
|
||||||
|
name: SonarQube Scan Job
|
||||||
|
if: ${{ github.actor != 'dependabot[bot]' }}
|
||||||
|
permissions:
|
||||||
|
id-token: write
|
||||||
|
contents: read
|
||||||
|
runs-on: ubuntu-22.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout source repository for dispatch runs
|
||||||
|
id: checkout-source-dispatch
|
||||||
|
if: github.event_name == 'workflow_dispatch'
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: ${{ github.repository }}
|
||||||
|
ref: ${{ inputs.ref }}
|
||||||
|
path: source
|
||||||
|
token: ${{ secrets.GH_SLONIK }}
|
||||||
|
|
||||||
|
- name: Checkout source repository for non-dispatch runs
|
||||||
|
id: checkout-source
|
||||||
|
if: github.event_name != 'workflow_dispatch'
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: ${{ github.repository }}
|
||||||
|
ref: ${{ github.ref }}
|
||||||
|
path: source
|
||||||
|
token: ${{ secrets.GH_SLONIK }}
|
||||||
|
|
||||||
|
- name: Checkout foundation-security repository
|
||||||
|
id: checkout-foundation-security
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
repository: EnterpriseDB/foundation-security
|
||||||
|
ref: v2
|
||||||
|
path: foundation-security
|
||||||
|
token: ${{ secrets.GH_SLONIK }}
|
||||||
|
|
||||||
|
- name: SonarQube Scan
|
||||||
|
id: call-sq-composite
|
||||||
|
uses: ./foundation-security/actions/sonarqube
|
||||||
|
with:
|
||||||
|
github-token: ${{ secrets.GH_SLONIK }}
|
||||||
|
github-ref: ${{ github.ref_name }}
|
||||||
|
sonarqube-url: ${{ vars.SQ_URL }}
|
||||||
|
sonarqube-token: ${{ secrets.SONARQUBE_TOKEN }}
|
||||||
|
project-name: ${{ github.event.repository.name }}
|
||||||
|
pull-request-key: ${{ github.event.number }}
|
||||||
|
pull-request-branch: ${{ github.head_ref }}
|
||||||
|
pull-request-base-branch: ${{ github.base_ref }}
|
||||||
|
foundation-security-sonarqube-token: ${{ secrets.FOUNDATION_SECURITY_SONARQUBE_TOKEN }}
|
||||||
|
cloudsmith-token: ${{ secrets.CLOUDSMITH_READ_ALL }}
|
||||||
14
README.md
14
README.md
@@ -7,8 +7,8 @@ replication capabilities with utilities to set up standby servers, monitor
|
|||||||
replication, and perform administrative tasks such as failover or switchover
|
replication, and perform administrative tasks such as failover or switchover
|
||||||
operations.
|
operations.
|
||||||
|
|
||||||
The most recent `repmgr` version (5.4.1) supports all PostgreSQL versions from
|
The most recent `repmgr` version (5.3.2) supports all PostgreSQL versions from
|
||||||
10 to 16.
|
9.5 to 15. PostgreSQL 9.4 is also supported, with some restrictions.
|
||||||
|
|
||||||
`repmgr` is distributed under the GNU GPL 3 and maintained by EnterpriseDB.
|
`repmgr` is distributed under the GNU GPL 3 and maintained by EnterpriseDB.
|
||||||
|
|
||||||
@@ -56,6 +56,8 @@ There is a mailing list/forum to discuss contributions or issues:
|
|||||||
|
|
||||||
* https://groups.google.com/group/repmgr
|
* https://groups.google.com/group/repmgr
|
||||||
|
|
||||||
|
The IRC channel #repmgr is registered with freenode.
|
||||||
|
|
||||||
Please report bugs and other issues to:
|
Please report bugs and other issues to:
|
||||||
|
|
||||||
* https://github.com/EnterpriseDB/repmgr
|
* https://github.com/EnterpriseDB/repmgr
|
||||||
@@ -67,14 +69,6 @@ news are always welcome.
|
|||||||
|
|
||||||
Thanks from the repmgr core team.
|
Thanks from the repmgr core team.
|
||||||
|
|
||||||
* Ian Barwick
|
|
||||||
* Israel Barth
|
|
||||||
* Mario González
|
|
||||||
* Martín Marqués
|
|
||||||
* Gianni Ciolli
|
|
||||||
|
|
||||||
Past contributors:
|
|
||||||
|
|
||||||
* Jaime Casanova
|
* Jaime Casanova
|
||||||
* Abhijit Menon-Sen
|
* Abhijit Menon-Sen
|
||||||
* Simon Riggs
|
* Simon Riggs
|
||||||
|
|||||||
102
dbutils.c
102
dbutils.c
@@ -1852,51 +1852,6 @@ get_wal_receiver_pid(PGconn *conn)
|
|||||||
/* =============================== */
|
/* =============================== */
|
||||||
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Determine if the user associated with the current connection can execute CHECKPOINT command.
|
|
||||||
* User must be a supersuer or a member of the pg_checkpoint default role (available from PostgreSQL 15).
|
|
||||||
*/
|
|
||||||
bool
|
|
||||||
can_execute_checkpoint(PGconn *conn)
|
|
||||||
{
|
|
||||||
PQExpBufferData query;
|
|
||||||
PGresult *res;
|
|
||||||
bool has_pg_checkpoint_role = false;
|
|
||||||
|
|
||||||
/* superusers can do anything, no role check needed */
|
|
||||||
if (is_superuser_connection(conn, NULL) == true)
|
|
||||||
return true;
|
|
||||||
|
|
||||||
/* pg_checkpoint available from PostgreSQL 15 */
|
|
||||||
if (PQserverVersion(conn) < 150000)
|
|
||||||
return false;
|
|
||||||
|
|
||||||
initPQExpBuffer(&query);
|
|
||||||
appendPQExpBufferStr(&query,
|
|
||||||
" SELECT pg_catalog.pg_has_role('pg_checkpoint','USAGE') ");
|
|
||||||
|
|
||||||
res = PQexec(conn, query.data);
|
|
||||||
|
|
||||||
if (PQresultStatus(res) != PGRES_TUPLES_OK)
|
|
||||||
{
|
|
||||||
log_db_error(conn, query.data,
|
|
||||||
_("can_execute_checkpoint(): unable to query user roles"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
has_pg_checkpoint_role = atobool(PQgetvalue(res, 0, 0));
|
|
||||||
}
|
|
||||||
termPQExpBuffer(&query);
|
|
||||||
PQclear(res);
|
|
||||||
|
|
||||||
return has_pg_checkpoint_role;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Determine if the user associated with the current connection
|
|
||||||
* has sufficient permissions to use pg_promote function
|
|
||||||
*/
|
|
||||||
bool
|
bool
|
||||||
can_execute_pg_promote(PGconn *conn)
|
can_execute_pg_promote(PGconn *conn)
|
||||||
{
|
{
|
||||||
@@ -1958,47 +1913,15 @@ can_disable_walsender(PGconn *conn)
|
|||||||
if (is_superuser_connection(conn, NULL) == true)
|
if (is_superuser_connection(conn, NULL) == true)
|
||||||
return true;
|
return true;
|
||||||
|
|
||||||
PQExpBufferData query;
|
/*
|
||||||
PGresult *res;
|
* As of PostgreSQL 14, it is not possible for a non-superuser
|
||||||
bool has_alter_system_priv = false;
|
* to execute ALTER SYSTEM, so further checks are superfluous.
|
||||||
|
* This will need modifying for PostgreSQL 15.
|
||||||
|
*/
|
||||||
|
log_warning(_("\"standby_disconnect_on_failover\" specified, but repmgr user is not a superuser"));
|
||||||
|
log_detail(_("superuser permission required to disable standbys on failover"));
|
||||||
|
|
||||||
/* GRANT ALTER SYSTEM available from PostgreSQL 15 */
|
return false;
|
||||||
if (PQserverVersion(conn) >= 150000)
|
|
||||||
{
|
|
||||||
initPQExpBuffer(&query);
|
|
||||||
appendPQExpBufferStr(&query,
|
|
||||||
" SELECT pg_catalog.has_parameter_privilege('wal_retrieve_retry_interval', 'ALTER SYSTEM') ");
|
|
||||||
|
|
||||||
res = PQexec(conn, query.data);
|
|
||||||
|
|
||||||
if (PQresultStatus(res) != PGRES_TUPLES_OK)
|
|
||||||
{
|
|
||||||
log_db_error(conn, query.data,
|
|
||||||
_("can_disable_walsender(): unable to query user parameter privileges"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
has_alter_system_priv = atobool(PQgetvalue(res, 0, 0));
|
|
||||||
}
|
|
||||||
termPQExpBuffer(&query);
|
|
||||||
PQclear(res);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (has_alter_system_priv == false)
|
|
||||||
{
|
|
||||||
log_warning(_("\"standby_disconnect_on_failover\" specified, but repmgr user is not authorized to perform ALTER SYSTEM wal_retrieve_retry_interval"));
|
|
||||||
|
|
||||||
if (PQserverVersion(conn) >= 150000)
|
|
||||||
{
|
|
||||||
log_detail(_("superuser or ALTER SYSTEM wal_retrieve_retry_interval permission required to disable standbys on failover"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
log_detail(_("superuser permission required to disable standbys on failover"));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return has_alter_system_priv;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -2024,13 +1947,13 @@ connection_has_pg_monitor_role(PGconn *conn, const char *subrole)
|
|||||||
initPQExpBuffer(&query);
|
initPQExpBuffer(&query);
|
||||||
appendPQExpBufferStr(&query,
|
appendPQExpBufferStr(&query,
|
||||||
" SELECT CASE "
|
" SELECT CASE "
|
||||||
" WHEN pg_catalog.pg_has_role('pg_monitor','USAGE') "
|
" WHEN pg_catalog.pg_has_role('pg_monitor','MEMBER') "
|
||||||
" THEN TRUE ");
|
" THEN TRUE ");
|
||||||
|
|
||||||
if (subrole != NULL)
|
if (subrole != NULL)
|
||||||
{
|
{
|
||||||
appendPQExpBuffer(&query,
|
appendPQExpBuffer(&query,
|
||||||
" WHEN pg_catalog.pg_has_role('%s','USAGE') "
|
" WHEN pg_catalog.pg_has_role('%s','MEMBER') "
|
||||||
" THEN TRUE ",
|
" THEN TRUE ",
|
||||||
subrole);
|
subrole);
|
||||||
}
|
}
|
||||||
@@ -2537,10 +2460,7 @@ get_repmgr_extension_status(PGconn *conn, t_extension_versions *extversions)
|
|||||||
/* node management functions */
|
/* node management functions */
|
||||||
/* ========================= */
|
/* ========================= */
|
||||||
|
|
||||||
/*
|
/* assumes superuser connection */
|
||||||
* Assumes the connection can execute CHECKPOINT command.
|
|
||||||
* A check can be executed via 'can_execute_checkpoint' function.
|
|
||||||
*/
|
|
||||||
void
|
void
|
||||||
checkpoint(PGconn *conn)
|
checkpoint(PGconn *conn)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -453,7 +453,6 @@ TimeLineHistoryEntry *get_timeline_history(PGconn *repl_conn, TimeLineID tli);
|
|||||||
pid_t get_wal_receiver_pid(PGconn *conn);
|
pid_t get_wal_receiver_pid(PGconn *conn);
|
||||||
|
|
||||||
/* user/role information functions */
|
/* user/role information functions */
|
||||||
bool can_execute_checkpoint(PGconn *conn);
|
|
||||||
bool can_execute_pg_promote(PGconn *conn);
|
bool can_execute_pg_promote(PGconn *conn);
|
||||||
bool can_disable_walsender(PGconn *conn);
|
bool can_disable_walsender(PGconn *conn);
|
||||||
bool connection_has_pg_monitor_role(PGconn *conn, const char *subrole);
|
bool connection_has_pg_monitor_role(PGconn *conn, const char *subrole);
|
||||||
|
|||||||
@@ -79,10 +79,6 @@
|
|||||||
Alternatively the meta-role <varname>pg_monitor</varname> can be granted, which includes membership
|
Alternatively the meta-role <varname>pg_monitor</varname> can be granted, which includes membership
|
||||||
of the above predefined roles.
|
of the above predefined roles.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
|
||||||
PostgreSQL 15 introduced the <varname>pg_checkpoint</varname> predefined role which allows a
|
|
||||||
non-superuser &repmgr; database user to perform a CHECKPOINT command.
|
|
||||||
</para>
|
|
||||||
<para>
|
<para>
|
||||||
Membership of these roles can be granted with e.g. <command>GRANT pg_read_all_stats TO repmgr</command>.
|
Membership of these roles can be granted with e.g. <command>GRANT pg_read_all_stats TO repmgr</command>.
|
||||||
</para>
|
</para>
|
||||||
@@ -152,8 +148,6 @@
|
|||||||
<link linkend="repmgr-standby-switchover">repmgr standby switchover</link>. This can only
|
<link linkend="repmgr-standby-switchover">repmgr standby switchover</link>. This can only
|
||||||
be executed by a superuser; if the &repmgr; user is not a superuser,
|
be executed by a superuser; if the &repmgr; user is not a superuser,
|
||||||
the <option>-S</option>/<option>--superuser</option> should be used.
|
the <option>-S</option>/<option>--superuser</option> should be used.
|
||||||
From PostgreSQL 15 the <varname>pg_checkpoint</varname> predefined role removes the need of
|
|
||||||
superuser permissions to perform <command>CHECKPOINT</command> command.
|
|
||||||
</simpara>
|
</simpara>
|
||||||
<simpara>
|
<simpara>
|
||||||
If &repmgr; is not able to execute <command>CHECKPOINT</command>,
|
If &repmgr; is not able to execute <command>CHECKPOINT</command>,
|
||||||
@@ -165,10 +159,8 @@
|
|||||||
<simpara>
|
<simpara>
|
||||||
The <command>ALTER SYSTEM</command> is executed by &repmgrd; if
|
The <command>ALTER SYSTEM</command> is executed by &repmgrd; if
|
||||||
<varname>standby_disconnect_on_failover</varname> is set to <literal>true</literal> in
|
<varname>standby_disconnect_on_failover</varname> is set to <literal>true</literal> in
|
||||||
<filename>repmgr.conf</filename>. Until PostgreSQL 14 <command>ALTER SYSTEM</command> can only be executed by
|
<filename>repmgr.conf</filename>. <command>ALTER SYSTEM</command> can only be executed by
|
||||||
a superuser; if the &repmgr; user is not a superuser, this functionality will not be available.
|
a superuser; if the &repmgr; user is not a superuser, this functionality will not be available.
|
||||||
From PostgreSQL 15 a specific ALTER SYSTEM privilege can be granted with e.g.
|
|
||||||
<command>GRANT ALTER SYSTEM ON PARAMETER wal_retrieve_retry_interval TO repmgr</command>.
|
|
||||||
</simpara>
|
</simpara>
|
||||||
</listitem>
|
</listitem>
|
||||||
</itemizedlist>
|
</itemizedlist>
|
||||||
|
|||||||
@@ -77,8 +77,7 @@
|
|||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
Note that a superuser connection is required to be able to execute the
|
Note that a superuser connection is required to be able to execute the
|
||||||
<command>CHECKPOINT</command> command. From PostgreSQL 15 the <varname>pg_checkpoint</varname>
|
<command>CHECKPOINT</command> command.
|
||||||
predefined role removes the need for superuser permissions to perform <command>CHECKPOINT</command> command.
|
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|||||||
@@ -79,8 +79,7 @@
|
|||||||
<para>
|
<para>
|
||||||
Note that <command>CHECKPOINT</command> requires database superuser permissions to execute.
|
Note that <command>CHECKPOINT</command> requires database superuser permissions to execute.
|
||||||
If the <literal>repmgr</literal> user is not a superuser, the name of a superuser should be
|
If the <literal>repmgr</literal> user is not a superuser, the name of a superuser should be
|
||||||
provided with the <option>-S</option>/<option>--superuser</option> option. From PostgreSQL 15 the <varname>pg_checkpoint</varname>
|
provided with the <option>-S</option>/<option>--superuser</option> option.
|
||||||
predefined role removes the need for superuser permissions to perform <command>CHECKPOINT</command> command.
|
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
If &repmgr; is unable to execute the <command>CHECKPOINT</command> command, the switchover
|
If &repmgr; is unable to execute the <command>CHECKPOINT</command> command, the switchover
|
||||||
|
|||||||
@@ -279,9 +279,7 @@
|
|||||||
<note>
|
<note>
|
||||||
<para>
|
<para>
|
||||||
<option>standby_disconnect_on_failover</option> is available with PostgreSQL 9.5 and later.
|
<option>standby_disconnect_on_failover</option> is available with PostgreSQL 9.5 and later.
|
||||||
Until PostgreSQL 14 this requires that the <literal>repmgr</literal> database user is a superuser.
|
Additionally this requires that the <literal>repmgr</literal> database user is a superuser.
|
||||||
From PostgreSQL 15 a specific ALTER SYSTEM privilege can be granted to the <literal>repmgr</literal> database
|
|
||||||
user with e.g. <command>GRANT ALTER SYSTEM ON PARAMETER wal_retrieve_retry_interval TO repmgr</command>.
|
|
||||||
</para>
|
</para>
|
||||||
</note>
|
</note>
|
||||||
<para>
|
<para>
|
||||||
|
|||||||
@@ -2365,25 +2365,18 @@ do_node_service(void)
|
|||||||
conn = establish_db_connection_by_params(&source_conninfo, true);
|
conn = establish_db_connection_by_params(&source_conninfo, true);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (can_execute_checkpoint(conn) == false)
|
if (is_superuser_connection(conn, NULL) == false)
|
||||||
{
|
{
|
||||||
if (runtime_options.dry_run == true)
|
if (runtime_options.dry_run == true)
|
||||||
{
|
{
|
||||||
log_warning(_("a CHECKPOINT would be issued here but no authorized connection is available"));
|
log_warning(_("a CHECKPOINT would be issued here but no superuser connection is available"));
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
log_warning(_("an authorized connection is required to issue a CHECKPOINT"));
|
log_warning(_("a superuser connection is required to issue a CHECKPOINT"));
|
||||||
}
|
}
|
||||||
|
|
||||||
if (PQserverVersion(conn) >= 150000)
|
log_hint(_("provide a superuser with -S/--superuser"));
|
||||||
{
|
|
||||||
log_hint(_("provide a superuser with -S/--superuser or grant pg_checkpoint role to repmgr user"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
log_hint(_("provide a superuser with -S/--superuser"));
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -5288,7 +5288,7 @@ do_standby_switchover(void)
|
|||||||
checkpoint_conn = superuser_conn;
|
checkpoint_conn = superuser_conn;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (can_execute_checkpoint(checkpoint_conn) == true)
|
if (is_superuser_connection(checkpoint_conn, NULL) == true)
|
||||||
{
|
{
|
||||||
log_notice(_("issuing CHECKPOINT on node \"%s\" (ID: %i) "),
|
log_notice(_("issuing CHECKPOINT on node \"%s\" (ID: %i) "),
|
||||||
config_file_options.node_name,
|
config_file_options.node_name,
|
||||||
@@ -5297,16 +5297,7 @@ do_standby_switchover(void)
|
|||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
log_warning(_("no authorized connection available, unable to issue CHECKPOINT"));
|
log_warning(_("no superuser connection available, unable to issue CHECKPOINT"));
|
||||||
|
|
||||||
if (PQserverVersion(local_conn) >= 150000)
|
|
||||||
{
|
|
||||||
log_hint(_("provide a superuser with -S/--superuser or grant pg_checkpoint role to repmgr user"));
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
log_hint(_("provide a superuser with -S/--superuser"));
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
#
|
#
|
||||||
# For details on the configuration file format see the documentation at:
|
# For details on the configuration file format see the documentation at:
|
||||||
#
|
#
|
||||||
# https://repmgr.org/docs/current/configuration-file.html#CONFIGURATION-FILE-FORMAT
|
# https://repmgr.org/docs/current/configuration-file.html#CONFIGURATION-FILE-FORMAT
|
||||||
#
|
#
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
# Required configuration items
|
# Required configuration items
|
||||||
@@ -76,7 +76,7 @@
|
|||||||
#location='default' # An arbitrary string defining the location of the node; this
|
#location='default' # An arbitrary string defining the location of the node; this
|
||||||
# is used during failover to check visibility of the
|
# is used during failover to check visibility of the
|
||||||
# current primary node. For further details see:
|
# current primary node. For further details see:
|
||||||
# https://repmgr.org/docs/current/repmgrd-network-split.html
|
# https://repmgr.org/docs/current/repmgrd-network-split.html
|
||||||
|
|
||||||
#use_replication_slots=no # whether to use physical replication slots
|
#use_replication_slots=no # whether to use physical replication slots
|
||||||
# NOTE: when using replication slots,
|
# NOTE: when using replication slots,
|
||||||
@@ -181,8 +181,8 @@
|
|||||||
|
|
||||||
#pg_ctl_options='' # Options to append to "pg_ctl"
|
#pg_ctl_options='' # Options to append to "pg_ctl"
|
||||||
#pg_basebackup_options='' # Options to append to "pg_basebackup"
|
#pg_basebackup_options='' # Options to append to "pg_basebackup"
|
||||||
# (Note: when cloning from Barman, repmgr will honour any
|
# (Note: when cloning from Barman, repmgr will honour any
|
||||||
# --waldir/--xlogdir setting present in "pg_basebackup_options"
|
# --waldir/--xlogdir setting present in "pg_basebackup_options"
|
||||||
#rsync_options='' # Options to append to "rsync"
|
#rsync_options='' # Options to append to "rsync"
|
||||||
ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
||||||
|
|
||||||
@@ -212,8 +212,8 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
|
|
||||||
#recovery_min_apply_delay= # If provided, "recovery_min_apply_delay" will be set to
|
#recovery_min_apply_delay= # If provided, "recovery_min_apply_delay" will be set to
|
||||||
# this value (PostgreSQL 9.4 and later). Value can be
|
# this value (PostgreSQL 9.4 and later). Value can be
|
||||||
# an integer representing milliseconds, or a string
|
# an integer representing milliseconds, or a string
|
||||||
# representing a period of time (e.g. '5 min').
|
# representing a period of time (e.g. '5 min').
|
||||||
|
|
||||||
|
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
@@ -299,7 +299,7 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
# a value of zero prevents the node being promoted to primary
|
# a value of zero prevents the node being promoted to primary
|
||||||
# (default: 100)
|
# (default: 100)
|
||||||
|
|
||||||
#connection_check_type='ping' # How to check availability of the upstream node; valid options:
|
#connection_check_type=ping # How to check availability of the upstream node; valid options:
|
||||||
# 'ping': use PQping() to check if the node is accepting connections
|
# 'ping': use PQping() to check if the node is accepting connections
|
||||||
# 'connection': attempt to make a new connection to the node
|
# 'connection': attempt to make a new connection to the node
|
||||||
# 'query': execute an SQL statement on the node via the existing connection
|
# 'query': execute an SQL statement on the node via the existing connection
|
||||||
@@ -340,31 +340,22 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
#repmgrd_exit_on_inactive_node=false # If "true", and the node record is marked as "inactive", abort repmgrd startup
|
#repmgrd_exit_on_inactive_node=false # If "true", and the node record is marked as "inactive", abort repmgrd startup
|
||||||
#standby_disconnect_on_failover=false # If "true", in a failover situation wait for all standbys to
|
#standby_disconnect_on_failover=false # If "true", in a failover situation wait for all standbys to
|
||||||
# disconnect their WAL receivers before electing a new primary
|
# disconnect their WAL receivers before electing a new primary
|
||||||
# Can be true in PostgreSQL 9.5 and later only. Until PostgreSQL 14 repmgr user must be a superuser to use this.
|
# (PostgreSQL 9.5 and later only; repmgr user must be a superuser for this)
|
||||||
# From PostgreSQL 15 repmgr must be a superuser or have 'ALTER SYSTEM wal_retrieve_retry_interval' privilege.
|
|
||||||
# (see: https://repmgr.org/docs/current/repmgrd-standby-disconnection-on-failover.html )
|
|
||||||
#sibling_nodes_disconnect_timeout=30 # If "standby_disconnect_on_failover" is true, the maximum length of time
|
#sibling_nodes_disconnect_timeout=30 # If "standby_disconnect_on_failover" is true, the maximum length of time
|
||||||
# (in seconds) to wait for other standbys to confirm they have disconnected their
|
# (in seconds) to wait for other standbys to confirm they have disconnected their
|
||||||
# WAL receivers
|
# WAL receivers
|
||||||
#primary_visibility_consensus=false # If "true", only continue with failover if no standbys have seen
|
#primary_visibility_consensus=false # If "true", only continue with failover if no standbys have seen
|
||||||
# the primary node recently. *Must* be the same on all nodes.
|
# the primary node recently. *Must* be the same on all nodes.
|
||||||
#always_promote=false # Always promote a node, even if repmgr metadata is outdated
|
#always_promote=false # Always promote a node, even if repmgr metadata is outdated
|
||||||
#failover_validation_command='' # Script to execute for an external mechanism to validate the failover
|
#failover_validation_command='' # Script to execute for an external mechanism to validate the failover
|
||||||
# decision made by repmgrd. Each of the following parameter placeholders
|
# decision made by repmgrd. One or both of the following parameter placeholders
|
||||||
# should be provided, which will be replaced by repmgrd with the appropriate value:
|
# should be provided, which will be replaced by repmgrd with the appropriate
|
||||||
# %n (node_id)
|
# value: %n (node_id), %a (node_name). *Must* be the same on all nodes.
|
||||||
# %a (node_name)
|
|
||||||
# %v (number of visible nodes)
|
|
||||||
# %u (number of shared upstream nodes)
|
|
||||||
# %t (total number of nodes)
|
|
||||||
# *Must* be the same on all nodes.
|
|
||||||
#election_rerun_interval=15 # if "failover_validation_command" is set, and the command returns
|
#election_rerun_interval=15 # if "failover_validation_command" is set, and the command returns
|
||||||
# an error, pause the specified amount of seconds before rerunning the election.
|
# an error, pause the specified amount of seconds before rerunning the election.
|
||||||
|
#
|
||||||
# The following items are relevant for repmgrd running on the primary,
|
# The following items are relevant for repmgrd running on the primary,
|
||||||
# and will be ignored on non-primary nodes.
|
# and will be ignored on non-primary nodes
|
||||||
# (see: https://repmgr.org/docs/current/repmgrd-primary-child-disconnection.html )
|
|
||||||
|
|
||||||
#child_nodes_check_interval=5 # Interval (in seconds) to check for attached child nodes (standbys)
|
#child_nodes_check_interval=5 # Interval (in seconds) to check for attached child nodes (standbys)
|
||||||
#child_nodes_connected_min_count=-1 # Minimum number of child nodes which must remain connected, otherwise
|
#child_nodes_connected_min_count=-1 # Minimum number of child nodes which must remain connected, otherwise
|
||||||
# disconnection command will be triggered
|
# disconnection command will be triggered
|
||||||
@@ -372,7 +363,6 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
# (ignored if "child_nodes_connected_min_count" set)
|
# (ignored if "child_nodes_connected_min_count" set)
|
||||||
#child_nodes_disconnect_timeout=30 # Interval between child node disconnection and disconnection command execution
|
#child_nodes_disconnect_timeout=30 # Interval between child node disconnection and disconnection command execution
|
||||||
#child_nodes_disconnect_command='' # Command to execute if child node disconnection detected
|
#child_nodes_disconnect_command='' # Command to execute if child node disconnection detected
|
||||||
#child_nodes_connected_include_witness=false # Whether to count the witness node (if in use) as a child node when determining whether to execute child_nodes_disconnect_command.
|
|
||||||
|
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# service control commands
|
# service control commands
|
||||||
@@ -395,20 +385,20 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
#
|
#
|
||||||
# For example, to use systemd, you can set
|
# For example, to use systemd, you can set
|
||||||
#
|
#
|
||||||
# service_start_command = 'sudo systemctl start postgresql-16'
|
# service_start_command = 'sudo systemctl start postgresql-9.6'
|
||||||
# (...)
|
# (...)
|
||||||
#
|
#
|
||||||
# and then use the following sudoers configuration:
|
# and then use the following sudoers configuration:
|
||||||
#
|
#
|
||||||
# # this is required when running sudo over ssh without -t:
|
# # this is required when running sudo over ssh without -t:
|
||||||
# Defaults:postgres !requiretty
|
# Defaults:postgres !requiretty
|
||||||
# postgres ALL = NOPASSWD: /usr/bin/systemctl stop postgresql-16, \
|
# postgres ALL = NOPASSWD: /usr/bin/systemctl stop postgresql-9.6, \
|
||||||
# /usr/bin/systemctl start postgresql-16, \
|
# /usr/bin/systemctl start postgresql-9.6, \
|
||||||
# /usr/bin/systemctl restart postgresql-16
|
# /usr/bin/systemctl restart postgresql-9.6
|
||||||
#
|
#
|
||||||
# Debian/Ubuntu users: use "sudo pg_ctlcluster" to execute service control commands.
|
# Debian/Ubuntu users: use "sudo pg_ctlcluster" to execute service control commands.
|
||||||
#
|
#
|
||||||
# For further details, see: https://repmgr.org/docs/current/configuration-file-service-commands.html
|
# For more details, see: https://repmgr.org/docs/current/configuration-file-service-commands.html
|
||||||
|
|
||||||
#service_start_command = ''
|
#service_start_command = ''
|
||||||
#service_stop_command = ''
|
#service_stop_command = ''
|
||||||
@@ -451,3 +441,4 @@ ssh_options='-q -o ConnectTimeout=10' # Options to append to "ssh"
|
|||||||
# "repmgr standby switchover" to warn about potential
|
# "repmgr standby switchover" to warn about potential
|
||||||
# issues with shutting down the demotion candidate.
|
# issues with shutting down the demotion candidate.
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user