フェールオーバーマネージャーの権限の拡張

During the |variable_prod_name| installation, the installer creates a user named efm. efm does not have sufficient privileges to perform management functions that are normally limited to the database owner or operating system superuser.

  • データベースのスーパーユーザー権限を必要とする管理機能を実行する場合、 efm は efm_db_functions スクリプトを呼び出します。

  • オペレーティングシステムのスーパーユーザー権限を必要とする管理機能を実行する場合、 efm は efm_root_functions スクリプトを呼び出します。

  • 仮想IPアドレスを割り当てまたは解放するとき、efmは efm_address script を呼び出します。

efm_db_functions または efm_root_functions スクリプトは、 efm ユーザーに代わって管理機能を実行します。

The sudoers file contains entries that allow the user efm to control the |variable_prod_name| service for clusters owned by postgres or enterprisedb. You can modify a copy of the sudoers file to grant permission to manage Postgres clusters owned by other users to efm.

efm-310 ファイルは /etc/sudoers.d にあり、以下のエントリを含んでいます:

# Copyright EnterpriseDB Corporation, 2014-2020. All Rights Reserved.
#
# Do not edit this file. Changes to the file may be overwritten
# during an upgrade.
#
# This file assumes you are running your efm cluster as user
# 'efm'. If not, then you will need to copy this file.
# Allow user 'efm' to sudo efm_db_functions as either 'postgres'
# or 'enterprisedb'. If you run your db service under a
# non-default account, you will need to copy this file to grant
# the proper permissions and specify the account in your efm
# cluster properties file by changing the 'db.service.owner'
# property.

efm ALL=(postgres) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_db_functions
efm ALL=(enterprisedb) NOPASSWD: /usr/edb/efm-|variable_prod_version|
/bin/efm_db_functions

# Allow user 'efm' to sudo efm_root_functions as 'root' to
# write/delete the PID file, validate the db.service.owner
# property, etc.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_root_functions
# Allow user 'efm' to sudo efm_address as root for VIP tasks.
efm ALL=(ALL) NOPASSWD: /usr/edb/efm-|variable_prod_version| /bin/efm_address
# relax tty requirement for user 'efm'
Defaults:efm !requiretty

|variable_prod_name|を使用している場合 postgres または enterprisedb 以外のユーザーが所有するクラスターを監視し、 efm-310 ファイルのコピーを作成し、ユーザーが efm_functions にアクセスできるようにコンテンツを変更するクラスタを管理するスクリプト。

パーミッションの問題のためにエージェントを起動できない場合は、デフォルトの /etc/sudoers ファイルの最後に次の行が含まれていることを確認してください:

## Read drop-in files from /etc/sudoers.d (the # here does not # mean a comment)

#includedir /etc/sudoers.d

sudoを使用せずにフェイルオーバーマネージャーを実行する

デフォルトでは、|variable_prod_name|sudoを使用して、システム機能へのアクセスを安全に管理します。|variable_prod_name|を設定する場合sudoアクセスなしで実行するには、rootアクセスが次のことを行うために必要であることに注意してください。

  • |variable_prod_name|をインストールしますRPM。

  • |variable_prod_name|を実行するセットアップタスク。

|variable_prod_name|を実行するにはsudoを使用しない場合、|variable_prod_name|に代わって管理機能を実行する権限を持つデータベースプロセスの所有者を選択する必要があります。ユーザーは、デフォルトのデータベーススーパーユーザー(たとえば、enterprisedbやpostgres)または別の特権ユーザーである可能性があります。ユーザーを選択した後:

  1. 次のコマンドを使用して、ユーザーを efm グループに追加します。

    usermod -a -G efm enterprisedb

    これにより、ユーザーは /var/run/efm-3.10 および /var/lock/efm-3.10 に書き込むことができます。

  2. クラスター名を再利用する場合は、以前に作成したログファイルを削除してください。新しいユーザーは、デフォルト(または他の)所有者が作成したログファイルに書き込むことができません。

  3. クラスタプロパティテンプレートファイルとノードテンプレートファイルをコピーします。

su - enterprisedb

cp /etc/edb/efm-|variable_prod_version|/efm.properties.in <directory/cluster_name>.properties

cp /etc/edb/efm-|variable_prod_version|/efm.nodes.in <directory>/<cluster_name>.nodes

Then, modify the cluster properties file, providing the name of the
user in the db.service.owner property. You must also ensure that the
db.service.name property is blank; without sudo, you cannot run
services without root access.

構成を変更した後、新しいユーザーは次のコマンドでフェールオーバーマネージャーを制御できます。

/usr/edb/efm-|variable_prod_version|/bin/runefm.sh start|stop <directory/cluster_name>.properties

ここで、 <directory/cluster_name.properties> は、クラスタープロパティファイルの完全パスと名前を指定します。デフォルト以外のユーザーがエージェントを制御している場合、またはefmスクリプトを使用している場合は常に、ユーザーがプロパティファイルへのフルパスを提供する必要があることに注意してください。

新しいユーザーが|variable_prod_name|を管理できるようにするにはサービスとして、カスタムスクリプトまたはユニットファイルを提供する必要があります。

|variable_prod_name| /usr/edb/efm-3.10/bin/secure/ に常駐するmanage-vipという名前のバイナリを使用して、sudo権限なしでVIP管理操作を実行します。このスクリプトは、setuidを使用して、仮想IPアドレスの管理に必要な特権を取得します。

  • このディレクトリはrootと efm グループのユーザーのみがアクセスできます。

  • バイナリはrootと efm グループによってのみ実行可能です。

セキュリティ上の理由から、 /usr/edb/efm-3.10/bin/secure/ ディレクトリまたは manage-vip スクリプトのアクセス権限を変更しないことをお勧めします。

|variable_prod_name|の使用に関する詳細情報sudoなしで、訪問:

https://www.enterprisedb.com/blog/running-edb-postgres-failover-manager-without-sudo