PgBouncerの設定

PEMデータベースサーバーと連携するようにPgBouncerを構成する必要があります。この例では、enterprisedbシステムユーザーとしてPgBouncerを実行します。以下の手順は、pgBouncer(バージョン> = 1.9)を構成するプロセスの概要を示しています。

  1. ターミナルウィンドウを開き、pgBouncerディレクトリに移動します。

  2. pgBouncerのetcディレクトリの所有者( pgbouncer.ini が存在する場所)を enterprisedb に変更し、ディレクトリのアクセス権を 0700 に変更します。例:

$ chown enterprisedb:enterprisedb /etc/edb/pgbouncer1.9``
$ chmod 0700 /etc/edb/pgbouncer1.9``
  1. pgbouncer.ini または edb-pgbouncer.ini ファイルの内容を次のように変更します。

[databases]
;; Change the pool_size according to maximum connections allowed``
;; to the PEM database server as required.``
;; 'auth_user' will be used for authenticate the db user (proxy``
;; agent user in our case)``

pem = port=5444 host=/tmp dbname=pem auth_user=pgbouncer
pool_size=80 pool_mode=transaction
\* = port=5444 host=/tmp dbname=pem auth_user=pgbouncer
pool_size=10

[pgbouncer]
logfile = /var/log/edb/pgbouncer1.9/edb-pgbouncer-1.9.log
pidfile = /var/run/edb/pgbouncer1.9/edb-pgbouncer-1.9.pid
listen_addr = \*
;; Agent needs to use this port to connect the pem database now
listen_port = 6432
;; Require to support for the SSL Certificate authentications
;; for PEM Agents
client_tls_sslmode = require
;; These are the root.crt, server.key, server.crt files present
;; in the present under the data directory of the PEM database
;; server, used by the PEM Agents for connections.
client_tls_ca_file = /var/lib/edb/as11/data/root.crt
client_tls_key_file = /var/lib/edb/as11/data/server.key
client_tls_cert_file = /var/lib/edb/as11/data/server.crt
;; Use hba file for client connections
auth_type = hba
;; Authentication file, Reference:
;; https://pgbouncer.github.io/config.html#auth_file
auth_file = /etc/edb/pgbouncer1.9/userlist.txt
;; HBA file
auth_hba_file = /etc/edb/pgbouncer1.9/hba_file
;; Use pem.get_agent_pool_auth(TEXT) function to authenticate
;; the db user (used as a proxy agent user).
auth_query = SELECT \* FROM pem.get_agent_pool_auth($1)
;; DB User for administration of the pgbouncer
admin_users = pem_admin1
;; DB User for collecting the statistics of pgbouncer
stats_users = pem_admin1
server_reset_query = DISCARD ALL
;; Change based on the number of agents installed/required
max_client_conn = 500
;; Close server connection if its not been used in this time.
;; Allows to clean unnecessary connections from pool after peak.
server_idle_timeout = 60``
  1. 次のコマンドを使用して、PgBouncerの /etc/edb/pgbouncer1.9/userlist.txt 認証ファイルを作成および更新します。

pem=# COPY (
SELECT 'pgbouncer'::TEXT, 'pgbouncer_password'
UNION ALL
SELECT 'pem_admin1'::TEXT, 'pem_admin1_password'
TO '/etc/edb/pgbouncer1.9/userlist.txt'
WITH (FORMAT CSV, DELIMITER ' ', FORCE_QUOTE \*);

COPY 2

注:スーパーユーザーは、PEM認証クエリ関数 pem.get_proxy_auth(text) を呼び出すことはできません。 pem_admin ユーザーがスーパーユーザーの場合、パスワードを認証ファイル(上記の例ではenterprisedb)に追加する必要があります。

  1. 次のコンテンツを含むPgBouncer用のHBAファイル (/etc/edb/pgbouncer1.9/hba_file) を作成します。

# Use authentication method md5 for the local connections to
# connect pem database & pgbouncer (virtual) database.
local pgbouncer all md5
# Use authentication method md5 for the remote connections to
# connect to pgbouncer (virtual database) using enterprisedb
# user.

host pgbouncer,pem pem_admin1 0.0.0.0/0 md5
# Use authentication method cert for the TCP/IP connections to
# connect the pem database using pem_agent_user1

hostssl pem pem_agent_user1 0.0.0.0/0 cert``
  1. HBAファイルの所有者を (/etc/edb/pgbouncer1.9/hba_file) から enterprisedb に変更し、ディレクトリのアクセス権を 0600 に変更します。例:

$ chown enterprisedb:enterprisedb /etc/edb/pgbouncer1.9/hba_file
$ chmod 0600 /etc/edb/pgbouncer1.9/hba_file
  1. PgBouncerサービスを有効にして、サービスを開始します。例:

$ systemctl enable edb-pgbouncer-1.9

Created symlink from
/etc/systemd/system/multi-user.target.wants/edb-pgbouncer-1.9.service
to /usr/lib/systemd/system/edb-pgbouncer-1.9.service.

$ systemctl start edb-pgbouncer-1.9