フェールオーバーマネージャーの権限の拡張¶
During the |variable_prod_name| installation, the installer creates a user
named efm. efm does not have sufficient privileges to perform management
functions that are normally limited to the database owner or operating
system superuser.
データベースのスーパーユーザー権限を必要とする管理機能を実行する場合、
efmはefm_db_functionsスクリプトを呼び出します。オペレーティングシステムのスーパーユーザー権限を必要とする管理機能を実行する場合、
efmはefm_root_functionsスクリプトを呼び出します。仮想IPアドレスを割り当てまたは解放するとき、efmは
efm_address scriptを呼び出します。
efm_db_functions または efm_root_functions スクリプトは、 efm ユーザーに代わって管理機能を実行します。
The sudoers file contains entries that allow the user efm to control the
|variable_prod_name| service for clusters owned by postgres or enterprisedb.
You can modify a copy of the sudoers file to grant permission to manage
Postgres clusters owned by other users to efm.
efm-310 ファイルは /etc/sudoers.d にあり、以下のエントリを含んでいます:
# Copyright EnterpriseDB Corporation, 2014-2020. All Rights Reserved.
#
# Do not edit this file. Changes to the file may be overwritten
# during an upgrade.
#
# This file assumes you are running your efm cluster as user
# 'efm'. If not, then you will need to copy this file.
# Allow user 'efm' to sudo efm_db_functions as either 'postgres'
# or 'enterprisedb'. If you run your db service under a
# non-default account, you will need to copy this file to grant
# the proper permissions and specify the account in your efm
# cluster properties file by changing the 'db.service.owner'
# property.
efm ALL=(postgres) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_db_functions
efm ALL=(enterprisedb) NOPASSWD: /usr/edb/efm-|variable_prod_version|
/bin/efm_db_functions
# Allow user 'efm' to sudo efm_root_functions as 'root' to
# write/delete the PID file, validate the db.service.owner
# property, etc.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_root_functions
# Allow user 'efm' to sudo efm_address as root for VIP tasks.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_address
# relax tty requirement for user 'efm'
Defaults:efm !requiretty
|variable_prod_name|を使用している場合 postgres または enterprisedb 以外のユーザーが所有するクラスターを監視し、 efm-310 ファイルのコピーを作成し、ユーザーが efm_functions にアクセスできるようにコンテンツを変更するクラスタを管理するスクリプト。
パーミッションの問題のためにエージェントを起動できない場合は、デフォルトの /etc/sudoers ファイルの最後に次の行が含まれていることを確認してください:
## Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)
#includedir /etc/sudoers.d
sudoを使用せずにフェイルオーバーマネージャーを実行する¶
デフォルトでは、|variable_prod_name|sudoを使用して、システム機能へのアクセスを安全に管理します。|variable_prod_name|を設定する場合sudoアクセスなしで実行するには、rootアクセスが次のことを行うために必要であることに注意してください。
|variable_prod_name|を実行するにはsudoを使用しない場合、|variable_prod_name|に代わって管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザー(たとえば、enterprisedbやpostgres)または別の特権ユーザーである可能性があります。ユーザーを選択した後:
次のコマンドを使用して、ユーザーを
efmグループに追加します。usermod -a -G efm enterprisedbこれにより、ユーザーは
/var/run/efm-3.10および/var/lock/efm-3.10に書き込むことができます。クラスター名を再利用する場合は、以前に作成したログファイルを削除してください。新しいユーザーは、デフォルト(または他の)所有者が作成したログファイルに書き込むことができません。
クラスタプロパティテンプレートファイルとノードテンプレートファイルをコピーします。
su - enterprisedb cp /etc/edb/efm-|variable_prod_version|/efm.properties.in <directory/cluster_name>.properties cp /etc/edb/efm-|variable_prod_version|/efm.nodes.in <directory>/<cluster_name>.nodes Then, modify the cluster properties file, providing the name of the user in thedb.service.ownerproperty. You must also ensure that thedb.service.nameproperty is blank; without sudo, you cannot run services without root access.
構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。
/usr/edb/efm-|variable_prod_version|/bin/runefm.sh start|stop <directory/cluster_name>.properties
ここで、 <directory/cluster_name.properties> は、クラスタープロパティファイルの完全パスと名前を指定します。デフォルト以外のユーザーがエージェントを制御している場合、またはefmスクリプトを使用している場合は常に、ユーザーがプロパティファイルへのフルパスを提供する必要があることに注意してください。
新しいユーザーが|variable_prod_name|を管理できるようにするにはサービスとして、カスタムスクリプトまたはユニットファイルを提供する必要があります。
|variable_prod_name| /usr/edb/efm-3.10/bin/secure/ に常駐するmanage-vipという名前のバイナリを使用して、sudo権限なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。
このディレクトリはrootと
efmグループのユーザーのみがアクセスできます。バイナリはrootと
efmグループによってのみ実行可能です。
セキュリティ上の理由から、 /usr/edb/efm-3.10/bin/secure/ ディレクトリまたは manage-vip スクリプトのアクセス権限を変更しないことをお勧めします。
|variable_prod_name|の使用に関する詳細情報sudoなしで、訪問:
https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo