Security and Roles¶
Beyond basic package installation and configuration, HARP itself does require Postgres permissions to operate. These allow it to gather information about Postgres or BDR as necessary to maintain node status within the Consensus Layer.
Postgres Permissions¶
The role specified in the node.dsn parameter must have been created
one of the following ways:
CREATE USER ...CREATE ROLE ... WITH LOGIN
This ensures the role is capable of logging into the database in order to gather diagnostic information.
Similarly, an entry must exist in pg_hba.conf for this role. This
can be done many ways. As an example, consider a VPN subnet where all
database hosts are located somewhere in 10.10.*. In such a case, the
easiest approach is to add a specific line:
# TYPE DATABASE USER ADDRESS METHOD
hostssl all harp_user 10.10.1.1/16 scram-sha-256
Note
In this case we’ve used the more modern scram-sha-256 authentication rather than md5 which is now deprecated. We’ve also elected to require SSL authentication by specifying hostssl.
BDR Permissions¶
BDR nodes have metadata and views that are only visible when certain roles are granted to the HARP-enabled user. In this case, the HARP user requires the following:
GRANT bdr_monitor TO harp_user;
The bdr_monitor BDR role is meant for status monitoring tools to
maintain ongoing information on cluster operation, thus is perfectly
suited to HARP.
BDR Consensus Permissions¶
When the dcs.driver configuration parameter is set to bdr, HARP
will utilize BDR itself as the Consensus Layer. As such, it requires
access to API methods that are currently only available to the
bdr_superuser role. This means the HARP-enabled user requires the
following:
GRANT bdr_superuser TO foobar;
This may change in future versions of BDR, but currently access to the BDR consensus model does require superuser equivalent permission.
Important
BDR Superusers are not Postgres superusers. The bdr_superuser role is merely granted elevated privileges within BDR itself, such as access to restricted functions, tables, views, and other objects.