クラスタープロパティファイル¶
フェールオーバーマネージャークラスターの各ノードには、それが存在する個々のノードのプロパティを含むプロパティファイル(デフォルトでは efm.properties という名前)があります。 Failover Managerインストーラーは、 /etc/edb/efm-3.9 ディレクトリに efm.properties.in という名前のプロパティファイルのファイルテンプレートを作成します。
フェールオーバーマネージャーのインストールが完了したら、ファイルの内容を変更する前に、テンプレートの作業用コピーを作成する必要があります。
# cp /etc/edb/efm-3.9/efm.properties.in /etc/edb/efm-3.9/efm.properties
テンプレートファイルをコピーした後、ファイルの所有者を efm に変更します。
# chown efm:efm efm.properties
注:既定では、フェールオーバーマネージャーはクラスタープロパティファイルの名前が efm.properties であると想定しています。プロパティファイルに efm.properties 以外の名前を付ける場合は、サービススクリプトまたはユニットファイルを変更して、フェールオーバーマネージャーに別の名前を使用するように指示する必要があります。
クラスタープロパティファイルを作成したら、必要に応じて構成パラメーター値を追加(または変更)します。各プロパティの詳細については、`` クラスタープロパティの指定``を参照してください。 。
プロパティファイルは root によって所有されています。 Failover Managerサービススクリプトは、 /etc/edb/efm-3.9 directory 内のファイルを見つけることを想定しています。プロパティファイルを別の場所に移動する場合は、新しい場所を指定するシンボリックリンクを作成する必要があります。
プロパティファイルで参照されるすべてのユーザースクリプトは、Failover Managerユーザーとして呼び出されることに注意してください。
クラスタプロパティの指定¶
クラスタープロパティファイルにリストされているプロパティを使用して、Failover Managerクラスターの接続プロパティと動作を指定できます。プロパティ設定の変更は、フェールオーバーマネージャーの起動時に適用されます。プロパティ値を変更した場合は、フェールオーバーマネージャーを再起動して変更を適用する必要があります。
プロパティ値では大文字と小文字が区別されます。 Postgresはパラメーター値に引用符付き文字列を使用しますが、Failover Managerではプロパティ値に引用符付き文字列を使用できないことに注意してください。たとえば、Postgres構成パラメーターでIPアドレスを次のように指定できます。
listen_addresses='192.168.2.47'
フェールオーバーマネージャーでは、値を引用符で囲まないでください。
bind.address=192.168.2.54:7800
efm.properties ファイルのプロパティを使用して、Failover Managerの接続、管理、および操作の詳細を指定します。
次のプロパティを使用して、フェールオーバーマネージャークラスターの接続の詳細を指定します。
# The value for the password property should be the output from
# 'efm encrypt' -- do not include a cleartext password here. To
# prevent accidental sharing of passwords among clusters, the
# cluster name is incorporated into the encrypted password. If
# you change the cluster name (the name of this file), you must
# encrypt the password again with the new name.
# The db.port property must be the same for all nodes.
db.user=
db.password.encrypted=
db.port=
db.database=
指定した db.user には、フェールオーバーマネージャーに代わって選択したPostgreSQLコマンドを呼び出すための十分な権限が必要です。詳細については、 前提条件を参照してください 。
データベースユーザーのパスワードの暗号化については、 データベースパスワードの暗号化を参照してください。 。
db.service.owner プロパティを使用して、フェールオーバーマネージャーによって管理されているクラスターを所有しているオペレーティングシステムユーザーの名前を指定します。このプロパティは、専用の監視ノードでは必要ありません。
# This property tells EFM which OS user owns the $PGDATA dir for
# the 'db.database'. By default, the owner is either 'postgres'
# for PostgreSQL or 'enterprisedb' for EDB Postgres Advanced
# Server. However, if you have configured your db to run as a
# different user, you will need to copy the /etc/sudoers.d/efm-XX
# conf file to grant the necessary permissions to your db owner.
#
# This username must have write permission to the
# 'db.data.dir' specified below.
db.service.owner=
サービスを開始または停止するときにserviceまたはsystemctlコマンドを使用する場合、 db.service.name プロパティでデータベースサービスの名前を指定します。
# Specify the proper service name in order to use service commands rather
# than pg_ctl to start/stop/restart a database. For example, if this property
# is set, then 'service <name> restart' or 'systemctl restart <name>'
# (depending on OS version) will be used to restart the database rather than pg_ctl.
# This property is required if running the database as a service.
db.service.name=
データベースサービスを開始または停止するたびに、同じサービス制御メカニズム(pg_ctl、service、またはsystemctl)を使用する必要があります。 pg_ctl プログラムを使用してサービスを制御する場合は、 db.bin プロパティで pg_ctl プログラムの場所を指定します。
# Specify the directory containing the pg_controldata/pg_ctl commands, for example:
# /usr/edb/as11/bin. Unless the db.service.name property is used, the pg_ctl
# command is used to start/stop/restart databases as needed after a
# failover or switchover. This property is required.
db.bin=
db.data.dir プロパティを使用して、クラスターのマスターノードで回復ファイルが書き込まれる場所を指定し、トリガーファイルがスタンバイで書き込まれます。このプロパティは、マスターノードとスタンバイノードで必要です。専用の監視ノードでは必要ありません。
# For database version 12 and up, this is the directory where a standby.signal
# file will exist for a standby node. For previous versions, this is the
# location of the db recovery.conf file on the node. On a standby node,
# the trigger file location is read from the file in this directory.
# After a failover, the recovery.conf files on remaining standbys are changed
# to point to the new master db (a copy of the original is made first). On a
# master node, a recovery.conf file will be written during failover and
# promotion to ensure that the master node can not be restarted as the
# master database.
# This corresponds to database environment variable PGDATA and should be same
# as the output of query 'show data_directory;' on respective database.
db.data.dir=
recovery.conf または standby.signal ファイルと同じディレクトリに保存されていない場合は、 db.config.dir プロパティを使用してデータベース設定ファイルの場所を指定します。これは、Advanced ServerまたはPostgreSQLインストールの config_file パラメーターディレクトリで指定された値である必要があります。この値は、データベースを停止、起動、または再起動するときにPostgresの data ディレクトリの場所として使用されます。
# Specify the location of database configuration files if they are not contained
# in the same location as the recovery.conf or standby.signal file. This is most
# likely the case for Debian installations. The location specified will be used as
# the -D value (the location of the data directory for the cluster)
# when calling pg_ctl to start or stop the database. If this property is blank,
# the db.data.dir location specified by the db.data.dir property will be used.
# This corresponds to the output of query 'show config_file;' on respective database.
db.config.dir=
データベース設定ファイルの詳細については、 `PostgreSQLウェブサイトをご覧ください<https://www.postgresql.org/docs/12/runtime-config-file-locations.html>`_
jdbc.sslmode プロパティを使用して、フェールオーバーマネージャーにSSL接続を使用するよう指示します。デフォルトでは、SSLは無効になっています。
# Use the jdbc.sslmode property to enable ssl for EFM
# connections. Setting this property to anything but 'disable'
# will force the agents to use 'ssl=true' for all JDBC database
# connections (to both local and remote databases).
# Valid values are:
#
# disable - Do not use ssl for connections.
# verify-ca - EFM will perform CA verification before allowing
# the certificate.
# require - Verification will not be performed on the server
# certificate.
jdbc.sslmode=disable
SSLの構成と使用の詳細については、以下を参照してください。
https://www.postgresql.org/docs/12/static/ssl-tcp.html
と
https://jdbc.postgresql.org/documentation/head/ssl.html
user.email プロパティを使用して、Failover Managerから送信された通知を受信する電子メールアドレス(または複数の電子メールアドレス)を指定します。
# Email address(es) for notifications. The value of this
# property must be the same across all agents. Multiple email
# addresses must be separated by space. If using a notification
# script instead, this property can be left blank.
user.email=
from.email プロパティは、Failover Managerからの電子メール通知で送信者のアドレスとして使用される値を指定します。次のことができます。
デフォルト値(
efm@localhost)を使用するには、from.emailを空白のままにします。メールアドレスのカスタム値を指定します。
%hプレースホルダーを使用してノードホストの名前を表すカスタムメールアドレスを指定します(例:example @%h)。プレースホルダーは、Linuxホスト名ユーティリティによって返されるホストの名前に置き換えられます。
通知の詳細については、 通知を参照してください 。
# Use the from.email property to specify the from email address that
# will be used for email notifications. Use the %h placeholder to
# represent the name of the node host (e.g. example@%h). The
# placeholder will be replaced with the name of the host as returned
# by the hostname command.
# Leave blank to use the default, efm@localhost.
from.email=
notification.level プロパティを使用して、フェールオーバーマネージャーがユーザー通知を送信する最小の重大度レベル、または通知スクリプトが呼び出されるタイミングを指定します。通知の完全なリストについては、 通知を参照してください 。
# Minimum severity level of notifications that will be sent by
# the agent. The minimum level also applies to the notification
# script (below). Valid values are INFO, WARNING, and SEVERE.
# A list of notifications is grouped by severity in the user's
# guide.
notification.level=INFO
script.notification プロパティを使用して、通知サービスとして機能するユーザー指定のスクリプトへのパスを指定します。スクリプトには、メッセージの件名とメッセージ本文が渡されます。このスクリプトは、フェールオーバーマネージャーがユーザー通知を生成するたびに呼び出されます。
# Absolute path to script run for user notifications.
#
# This is an optional user-supplied script that can be used for
# notifications instead of email. This is required if not using
# email notifications. Either/both can be used. The script will
# be passed two parameters: the message subject and the message
# body.
script.notification=
bind.address プロパティは、フェールオーバーマネージャークラスターの現在のノード上のエージェントのIPアドレスとポート番号を指定します。
# This property specifies the ip address and port that jgroups
# will bind to on this node. The value is of the form
# <ip>:<port>.
# Note that the port specified here is used for communicating
# with other nodes, and is not the same as the admin.port below,
# used only to communicate with the local agent to send control
# signals.
# For example, <provide_your_ip_address_here>:7800
bind.address=
admin.port プロパティを使用して、フェールオーバーマネージャーが管理コマンドをリッスンするポートを指定します。
# This property controls the port binding of the administration
# server which is used for some commands (ie cluster-status). The
# default is 7809; you can modify this value if the port is
# already in use.
admin.port=7809
is.witness プロパティをtrueに設定して、現在のノードが監視ノードであることを示します。 is.witnessがtrueの場合、ローカルエージェントはローカルデータベースが実行されているかどうかを確認しません。
# Specifies whether or not this is a witness node. Witness nodes
# do not have local databases running.
is.witness=
Postgresの pg_is_in_recovery() 関数は、データベースの回復状態を報告するブール関数です。この関数は、データベースが回復中の場合は true を返し、データベースが回復中でない場合はfalseを返します。エージェントが起動すると、ローカルデータベースに接続し、 pg_is_in_recovery() 関数を呼び出します。サーバーがtrueと応答すると、エージェントはスタンバイの役割を引き受けます。サーバーがfalseと応答した場合、エージェントはマスターの役割を引き継ぎます。ローカルデータベースがない場合、エージェントはアイドル状態になります。
注釈
is.witness が true の場合、フェイルオーバーマネージャーはリカバリ状態をチェックしません。
次のプロパティは、ローカルサーバーに適用されるプロパティを指定します。
local.periodプロパティは、データベースサーバーへの接続を試行する間隔を秒単位で指定します。local.timeout propertyは、ローカルデータベースサーバーからの肯定的な応答をエージェントが待つ時間を指定します。local.timeout.finalプロパティは、現在のノード上のデータベースサーバーへの最後の接続試行後にエージェントが待機する時間を指定します。 local.timeout.finalプロパティで指定された秒数内にデータベースから応答を受信しない場合、データベースは失敗したと見なされます。
たとえば、これらのプロパティのデフォルト値を指定すると、ローカルデータベースのチェックは10秒ごとに1回行われます。ローカルデータベースへの接続の試行が60秒以内に正に戻らない場合、フェールオーバーマネージャーはデータベースへの接続の最終試行を行います。応答が10秒以内に受信されない場合、Failover Managerはデータベース障害を宣言し、user.emailプロパティにリストされている管理者に通知します。これらのプロパティは、専用の監視ノードでは必要ありません。
# These properties apply to the connection(s) EFM uses to monitor
# the local database. Every 'local.period' seconds, a database
# check is made in a background thread. If the main monitoring
# thread does not see that any checks were successful in
# 'local.timeout' seconds, then the main thread makes a final
# check with a timeout value specified by the
# 'local.timeout.final' value. All values are in seconds.
# Whether EFM uses single or multiple connections for database
# checks is controlled by the 'db.reuse.connection.count'
# property.
local.period=10
local.timeout=60
local.timeout.final=10
必要に応じて、ビジネスモデルに合わせてこれらの値を変更する必要があります。
remote.timeout プロパティを使用して、エージェントがリモートデータベースサーバーからの応答を待機する秒数(つまり、フェールオーバーを実行する前にマスターデータベースが実際にダウンしていることを確認するためにスタンバイエージェントが待機する時間)を指定します。
# Timeout for a call to check if a remote database is responsive.
# For example, this is how long a standby would wait for a
# DB ping request from itself and the witness to the master DB
# before performing failover.
remote.timeout=10
node.timeout プロパティを使用して、ノードが失敗したかどうかを判断するときにエージェントがノードからの応答を待つ秒数を指定します。 node.timeoutプロパティ値は、エージェント間の通信のタイムアウト値を指定します。クラスタプロパティファイルの他のタイムアウトプロパティは、エージェントからデータベースへの通信の値を指定します。
# The total amount of time in seconds to wait before determining
# that a node has failed or been disconnected from this node.
#
# The value of this property must be the same across all agents.
node.timeout=50
stop.isolated.master プロパティを使用して、マスターエージェントが分離されていることを検出した場合、データベースをシャットダウンするようフェールオーバーマネージャーに指示します。 true(デフォルト)の場合、Failover Managerは script.master.isolated プロパティで指定されたスクリプトを呼び出す前にデータベースを停止します。
# Shut down the database after a master agent detects that it has
# been isolated from the majority of the efm cluster. If set to
# true, efm will stop the database before running the
# 'script.master.isolated' script, if a script is specified.
stop.isolated.master=true
stop.failed.master プロパティを使用して、マスターデータベースがデータベースに到達できない場合に、マスターデータベースのシャットダウンを試みるようフェールオーバーマネージャーに指示します。 true の場合、フェールオーバーマネージャーは、データベースをシャットダウンしようとした後、 script.db.failure プロパティで指定されたスクリプトを実行します。
# Attempt to shut down a failed master database after EFM can no
# longer connect to it. This can be used for added safety in the
# case a failover is caused by a failure of the network on the
# master node.
# If specified, a 'script.db.failure' script is run after this attempt.
stop.failed.master=true
master.shutdown.as.failure パラメーターを使用して、マスターノード上のFailover Managerエージェントのシャットダウンを障害として扱う必要があることを示します。このパラメーターが true に設定され、マスターエージェントが(何らかの理由で)停止した場合、クラスターはマスターノード上のデータベースが実行されているかどうかを確認しようとします。
データベースに到達すると、エージェントのステータスを通知する通知が送信されます。
データベースに到達しない場合、フェイルオーバーが発生します。
# Treat a master agent shutdown as a failure. This can be set to
# true to treat a master agent shutdown as a failure situation,
# e.g. during the shutdown of a node, accidental or otherwise.
# Caution should be used when using this feature, as it could
# cause an unwanted promotion in the case of performing master
# database maintenance.
# Please see the user's guide for more information.
master.shutdown.as.failure=false
master.shutdown.as.failure プロパティは、マスターノードの偶発的なシャットダウンなどの障害ではなく、ユーザーエラーをキャッチするためのものです。ユーザーがマスターフェールオーバーマネージャーエージェントを停止したように、ノードの適切なシャットダウンがクラスターの残りに表示されることがあります(たとえば、マスターデータベースのメンテナンスを実行するため)。 master.shutdown.as.failure プロパティを true に設定した場合、メンテナンスの実行時に注意が必要です。
master.shutdown.as.failure が true のときにmasterデータベースでメンテナンスを実行するには、マスターエージェントを停止し、マスターエージェントが失敗したがデータベースがまだ実行されているという通知を受信するまで待機する必要があります。その後、masterデータベースを停止しても安全です。または、 efm stop-cluster コマンドを使用して、障害チェックを実行せずにすべてのエージェントを停止できます。
ping.server.ip プロパティを使用して、フェールオーバーマネージャーがネットワーク接続に問題がないことを確認するために使用できるサーバーのIPアドレスを指定します。
# This is the address of a well-known server that EFM can ping
# in an effort to determine network reachability issues. It
# might be the IP address of a nameserver within your corporate
# firewall or another server that *should* always be reachable
# via a 'ping' command from each of the EFM nodes.
#
# There are many reasons why this node might not be considered
# reachable: firewalls might be blocking the request, ICMP might
# be filtered out, etc.
#
# Do not use the IP address of any node in the EFM cluster
# (master, standby, or witness) because this ping server is meant
# to provide an additional layer of information should the EFM
# nodes lose sight of each other.
#
# The installation default is Google's DNS server.
ping.server.ip=8.8.8.8
ping.server.command プロパティを使用して、ネットワーク接続のテストに使用するコマンドを指定します。
# This command will be used to test the reachability of certain
# nodes.
#
# Do not include an IP address or hostname on the end of
# this command - it will be added dynamically at runtime with the
# values contained in 'virtual.ip' and 'ping.server.ip'.
#
# Make sure this command returns reasonably quickly - test it
# from a shell command line first to make sure it works properly.
ping.server.command=/bin/ping -q -c3 -w5
auto.allow.hosts プロパティを使用して、許可されたホストリストを更新するために開始された最初のノードの.nodesファイルで指定されたアドレスを使用するようにサーバーに指示します。このプロパティを有効にする(auto.allow.hostsをtrueに設定する)と、クラスターの起動を簡素化できます。
# Have the first node started automatically add the addresses
# from its .nodes file to the allowed host list. This will make
# it faster to start the cluster when the initial set of hosts
# is already known.
auto.allow.hosts=false
stable.nodes.file プロパティを使用して、ノードがクラスターに参加またはクラスターから離脱するときにノードファイルを書き換えないようにサーバーに指示します。このプロパティは、不変のIPアドレスを持つクラスターで最も役立ちます。
# When set to true, EFM will not rewrite the .nodes file whenever
# new nodes join or leave the cluster. This can help starting a
# cluster in the cases where it is expected for member addresses
# to be mostly static, and combined with 'auto.allow.hosts' makes
# startup easier when learning failover manager.
stable.nodes.file=false
db.reuse.connection.count プロパティを使用すると、管理者はフェールオーバーマネージャーが同じデータベース接続を再利用してデータベースの状態を確認する回数を指定できます。デフォルト値は0です。これは、Failover Managerが毎回新しい接続を作成することを示します。このプロパティは、専用の監視ノードでは必要ありません。
# This property controls how many times a database connection is
# reused before creating a new one. If set to zero, a new
# connection will be created every time an agent pings its local
# database.
db.reuse.connection.count=0
auto.failover プロパティは自動フェイルオーバーを有効にします。デフォルトでは、auto.failoverはtrueに設定されています。
# Whether or not failover will happen automatically when the master
# fails. Set to false if you want to receive the failover notifications
# but not have EFM actually perform the failover steps.
# The value of this property must be the same across all agents.
auto.failover=true
プライマリスタンバイがマスターに昇格した後、残りのスタンバイサーバーの自動再構成を有効または無効にするようにフェールオーバーマネージャーに指示するには、 auto.reconfigure プロパティを使用します。プロパティを true に設定して自動再構成を有効にし(デフォルト)、または false に設定して自動再構成を無効にします。このプロパティは、専用の監視ノードでは必要ありません。 Advanced ServerまたはPostgreSQLバージョン11以前を使用している場合、再構成プロセス中に recovery.conf ファイルがバックアップされます。
# After a standby is promoted, Failover Manager will attempt to
# update the remaining standbys to use the new master. For database
# versions before 12, Failover Manager will back up recovery.conf.
# Then it will change the host parameter of the primary_conninfo entry
# in recovery.conf or postgresql.auto.conf, and restart the database. The
# restart command is contained in either the efm_db_functions or
# efm_root_functions file; default when not running db as an os
# service is: "pg_ctl restart -m fast -w -t <timeout> -D <directory>"
# where the timeout is the local.timeout property value and the
# directory is specified by db.data.dir. To turn off
# automatic reconfiguration, set this property to false.
auto.reconfigure=true
注意: primary_conninfo は、スペースで区切られたkeyword = valueペアのリストです。
注:レプリケーションスロットを使用してWALセグメントを管理している場合、自動再構成はサポートされていません。 auto.reconfigure を false に設定する必要があります。フェールオーバーが発生した場合は、スタンバイサーバーを手動で再構成する必要があります。
promotable プロパティを使用して、ノードを昇格させないことを示します。設定を上書きするには、実行時にefm set-priorityコマンドを使用します。 efm set-priorityコマンドの詳細については、 efmユーティリティの使用を参照してください 。
# A standby with this set to false will not be added to the
# failover priority list, and so will not be available for
# promotion. The property will be used whenever an agent starts
# as a standby or resumes as a standby after being idle. After
# startup/resume, the node can still be added or removed from the
# priority list with the 'efm set-priority' command. This
# property is required for all non-witness nodes.
promotable=true
同じ量のデータが複数のスタンバイノードに書き込まれ、フェールオーバーが発生した場合、use.replay.tiebreaker値によって、フェールオーバーマネージャーが置換マスターを選択する方法が決まります。 use.replay.tiebreaker プロパティを true に設定すると、ログシーケンス番号によって決定されるように、回復から早く出るノードにフェールオーバーするようにフェールオーバーマネージャーに指示します。ログのシーケンス番号を無視し、ユーザー設定に基づいてノードを昇格させるには、 use.replay.tiebreaker を false に設定します。
#フェイルオーバー優先順位を使用する前に、プロモートするスタンバイを選択するときに、タイブレーカーのリプレイLSN値を使用します。このプロパティをtrueに設定して、``最も先の``スタンバイを選択してプロモートするときに、再生場所をフェールオーバー優先順位(#cluster-statusコマンドで確認)よりも重要と見なします。 use.replay.tiebreaker = true
application.name プロパティを使用して、古いマスターノードをスタンバイとして再起動する前に primary_conninfo パラメーターにコピーされるアプリケーションの名前を指定できます。
# During a switchover, recovery settings are copied from a standby
# to the original master. If the application.name property is set,
# Failover Manager will replace the application_name portion of the
# primary_conninfo entry with this property value before starting
# the original master database as a standby. If this property is
# not set, Failover Manager will remove the parameter value
# from primary_conninfo.
application.name=
注意: マスターおよびプロモーション可能なスタンバイで application.name プロパティを設定する必要があります。フェールオーバー/スイッチオーバーのイベントでは、マスターノードが再びスタンバイノードになる可能性があります。
restore.command プロパティを使用して、新しいマスターが昇格したときに restore_command を更新するようにフェールオーバーマネージャーに指示します。 %h は新しいマスターのアドレスを表します。フェイルオーバーマネージャーは、 %h を新しいマスターのアドレスに置き換えます。 %f および %p はサーバーが使用するプレースホルダーです。プロパティが空白のままの場合、フェールオーバーマネージャーは、昇格後にスタンバイの restore_command 値を更新しません。
restore_commandの使用に関する詳細については、PostgreSQLのドキュメントを参照してください。 。
# If the restore_command on a standby restores directly from the master node, use this property
# to have Failover Manager change the command when a new master is promoted.
#
# Use the %h placeholder to represent the address of the new master. During promotion
# it will be replaced with the address of the new master.
#
# If not specified, failover manager will not change the restore_command value, if any,
# on standby nodes.
#
# Example:
# restore.command=scp <db service owner>@%h:/var/lib/edb/as12/data/archive/%f %p
restore.command=
マスターノードのsynchronous_standby_namesパラメーターは、データの受信を確認する同期スタンバイサーバーの名前と数を指定して、マスターノードが書き込みトランザクションを受け入れることができるようにします。 trueに設定すると、フェールオーバーマネージャーは同期スタンバイサーバーの数を減らし、マスターノードの構成を再読み込みして現在の値を反映します。
#同期スタンバイの数がmasterデータベースに必要な値を#下回ると、num_syncを減らします。 trueに設定されている場合、Failover Managerは、マスターのsynchronous_standby_namesプロパティに必要なスタンバイの数を減らし、マスター構成を再読み込みします。 #フェールオーバーマネージャーは、reconfigure.sync.masterプロパティもtrueに設定されていない限り、1未満の数を減らしてマスターを同期レプリケーションから除外しません。 reconfigure.num.sync = false
スタンバイノードの数が必要なレベルを下回った場合、マスターデータベースを同期レプリケーションモードから解除するには、 reconfigure.sync.master プロパティを true に設定します。スタンバイカウントが低下した場合に通知を送信し、同期レプリケーションを中断しないようにするには、 reconfigure.sync.master を false に設定します。
# Take the master database out of synchronous replication mode when needed.
# If set to true, Failover Manager will clear the synchronous_standby_names
# configuration parameter on the master if the number of synchronous
# standbys drops below the required level for the master to accept writes.
# If set to false, Failover Manager will detect the situation but will only
# send a notification if the standby count drops below the required level.
#
# CAUTION: TAKING THE MASTER DATABASE OUT OF SYNCHRONOUS MODE MEANS THERE
# MAY ONLY BE ONE COPY OF DATA. DO NOT MAKE THIS CHANGE UNLESS YOU ARE SURE
# THIS IS OK.
reconfigure.sync.master=false
minimum.standbys プロパティを使用して、クラスターに保持されるスタンバイノードの最小数を指定します。スタンバイカウントが指定された最小値に低下した場合、マスターノードに障害が発生してもレプリカノードは昇格されません。
# Instead of setting specific standbys as being unavailable for
# promotion, this property can be used to set a minimum number
# of standbys that will not be promoted. Set to one, for
# example, promotion will not happen if it will drop the number
# of standbys below this value. This property must be the same on
# each node.
minimum.standbys=0
recovery.check.period プロパティを使用して、データベースが復旧していないかどうかを確認する前にFailover Managerが待機する秒数を指定します。
# Time in seconds between checks to see if a promoting database
# is out of recovery.
recovery.check.period=2
restart.connection.timeout プロパティを使用して、フェールオーバーマネージャーが新しく再構成されたマスターノードまたはスタンバイノードへの接続を試行する秒数を指定します。
# Time in seconds to keep trying to connect to a database after a
# start or restart command returns successfully but the database
# is not ready to accept connections yet (a rare occurance). This
# applies to standby databases that are restarted when being
# reconfigured for a new master, and to master databases that
# are stopped and started as standbys during a switchover.
# This retry mechanism is unrelated to the auto.resume.period parameter.
restart.connection.timeout=60
auto.resume.period プロパティを使用して、エージェントがそのデータベースの監視を再開しようとする秒数(監視対象データベースが失敗し、エージェントがアイドル状態になった後、またはIDLEモードで起動したとき)を指定します。
# Period in seconds for IDLE agents to try to resume monitoring
# after a database failure or when starting in IDLE mode. Set to
# 0 for agents to not try to resume (in which case the
# 'efm resume <cluster>' command is used after bringing a
# database back up).
auto.resume.period=0
フェールオーバーマネージャーは、仮想IPを使用するクラスターのサポートを提供します。クラスターが仮想IPを使用する場合、 virtual.ip プロパティにホスト名またはIPアドレスを入力します。 virtual.ip.prefix プロパティに対応するプレフィックスを指定します。 virtual.ip を空白のままにすると、仮想IPサポートが無効になります。
VIPが使用するネットワークインターフェイスを提供するには、 virtual.ip.interface プロパティを使用します。
指定された仮想IPアドレスは、クラスターのマスターノードにのみ割り当てられます。 virtual.ip.single=true を指定すると、フェイルオーバーの発生時に新しいマスターで同じVIPアドレスが使用されます。 falseの値を指定して、クラスターの各ノードに一意のIPアドレスを提供します。
仮想IPアドレスの使用については、`` 仮想IPアドレスでのフェールオーバーマネージャーの使用``を参照してください。 。
# These properties specify the IP and prefix length that will be
# remapped during failover. If you do not use a VIP as part of
# your failover solution, leave the virtual.ip property blank to
# disable Failover Manager support for VIP processing (assigning,
# releasing, testing reachability, etc).
#
# If you specify a VIP, the interface and prefix are required.
#
# If you specify a host name, it will be resolved to an IP address
# when acquiring or releasing the VIP. If the host name resolves
# to more than one IP address, there is no way to predict which
# address Failover Manager will use.
#
# By default, the virtual.ip and virtual.ip.prefix values must be
# the same across all agents. If you set virtual.ip.single to
# false, you can specify unique values for virtual.ip and
# virtual.ip.prefix on each node.
#
# If you are using an IPv4 address, the virtual.ip.interface value
# should not contain a secondary virtual ip id (do not include
# ":1", etc).
virtual.ip=
virtual.ip.interface=
virtual.ip.prefix=
virtual.ip.single=true
注:マスターエージェントが起動され、ノードに現在VIPがない場合、EFMエージェントはそれを取得します。マスターエージェントを停止しても、ノードからVIPは削除されません。
check.vip.before.promotion プロパティをfalseに設定して、Failover Managerが、VIPが使用中かどうかを確認してから障害が発生した場合、新しいマスターに割り当てる前に確認しないことを示します。これにより、複数のノードが同じVIPアドレスでブロードキャストする可能性があることに注意してください。マスターノードが分離されているか、別のプロセスでシャットダウンできない場合を除き、このプロパティをtrueに設定する必要があります。
# Whether to check if the VIP (when used) is still in use before
# promoting after a master failure. Turning this off may allow
# the new master to have the VIP even though another node is also
# broadcasting it. This should only be used in environments where
# it is known that the failed master node will be isolated or
# shut down through other means.
check.vip.before.promotion=true
次のプロパティを使用して、スイッチオーバーまたはマスター障害のシナリオでロードバランサーを再構成するスクリプトへのパスを提供します。スクリプトは、スタンバイに失敗した場合にも呼び出されます。これらのプロパティを使用している場合は、クラスターのすべてのノード(マスター、スタンバイ、および監視)でそれらを提供して、データベースノードに障害が発生した場合に、別のノードが障害ノードのアドレスでdetachスクリプトを呼び出すようにします。
script.load.balancer.attach プロパティの後にスクリプト名を指定して、ノードをロードバランサーにアタッチする必要があるときに呼び出されるスクリプトを識別します。 script.load.balancer.detach プロパティを使用して、ノードをロードバランサーからデタッチする必要があるときに呼び出されるスクリプトの名前を指定します。クラスターに接続またはクラスターから削除されるノードのIPアドレスを表す %h プレースホルダーを含めます。文字列にm(マスターノードの場合)またはs(スタンバイノードの場合)を含めるようにフェールオーバーマネージャーに指示するには、 %t プレースホルダーを含めます。
# Absolute path to load balancer scripts
# The attach script is called when a node should be attached to
# the load balancer, for example after a promotion. The detach
# script is called when a node should be removed, for example
# when a database has failed or is about to be stopped. Use %h to
# represent the IP/hostname of the node that is being
# attached/detached. Use %t to represent the type of node being
# attached or detached: the letter m will be passed in for master nodes
#and the letter s for standby nodes.
#
# Example:
# script.load.balancer.attach=/somepath/attachscript %h %t
script.load.balancer.attach=
script.load.balancer.detach=
script.fence は、スタンバイノードからマスターノードへの昇格中に呼び出されるオプションのユーザー指定スクリプトへのパスを指定します。
# absolute path to fencing script run during promotion
#
# This is an optional user-supplied script that will be run
# during failover on the standby database node. If left blank,
# no action will be taken. If specified, EFM will execute this
# script before promoting the standby.
#
# Parameters can be passed into this script for the failed master
# and new primary node addresses. Use %p for new primary and %f
# for failed master. On a node that has just been promoted, %p
# should be the same as the node's efm binding address.
#
# Example:
# script.fence=/somepath/myscript %p %f
#
# NOTE: FAILOVER WILL NOT OCCUR IF THIS SCRIPT RETURNS A NON-ZERO EXIT CODE.
script.fence=
script.post.promotion プロパティを使用して、スタンバイノードがマスターに昇格した後に呼び出されるオプションのユーザー指定スクリプトへのパスを指定します。
# Absolute path to fencing script run after promotion
#
# This is an optional user-supplied script that will be run after
# failover on the standby node after it has been promoted and
# is no longer in recovery. The exit code from this script has
# no effect on failover manager, but will be included in a
# notification sent after the script executes.
#
# Parameters can be passed into this script for the failed master
# and new primary node addresses. Use %p for new primary and %f
# for failed master. On a node that has just been promoted, %p
# should be the same as the node's efm binding address.
#
# Example:
# script.post.promotion=/somepath/myscript %f %p
script.post.promotion=
script.resumed property を使用して、エージェントがデータベースの監視を再開するときに呼び出されるユーザー指定のスクリプトへのオプションのパスを指定します。
# Absolute path to resume script
#
# This script is run before an IDLE agent resumes
# monitoring its local database.
script.resumed=
script.db.failure プロパティを使用して、監視するデータベースが失敗したことをエージェントが検出した場合にフェールオーバーマネージャーが呼び出すオプションのユーザー指定スクリプトへの完全なパスを指定します。
# Absolute path to script run after database failure
# This is an optional user-supplied script that will be run after
# an agent detects that its local database has failed.
script.db.failure=
script.master.isolated プロパティを使用して、マスターデータベースを監視するエージェントがマスターがフェールオーバーマネージャークラスターの大部分から分離されていることを検出した場合にフェールオーバーマネージャーが呼び出すオプションのユーザー指定スクリプトへの完全なパスを指定します。このスクリプトは、VIPがリリースされた直後に呼び出されます(VIPが使用中の場合)。
# Absolute path to script run on isolated master
# This is an optional user-supplied script that will be run after
# a master agent detects that it has been isolated from the
# majority of the efm cluster.
script.master.isolated=
script.remote.pre.promotion プロパティを使用して、ノードがそのデータベースをマスターに昇格させようとしているときに昇格に関与しないエージェントノードで呼び出されるスクリプトのパスと名前を指定します。
%pプレースホルダーを含めて、新しいプライマリノードのアドレスを識別します。
# Absolute path to script invoked on non-promoting agent nodes
# before a promotion.
#
# This optional user-supplied script will be invoked on other
# agents when a node is about to promote its database. The exit
# code from this script has no effect on Failover Manager, but
# will be included in a notification sent after the script
# executes.
#
# Pass a parameter (%p) with the script to identify the new
# primary node address.
#
# Example:
# script.remote.pre.promotion=/path_name/script_name %p
script.remote.pre.promotion=
script.remote.post.promotion プロパティを使用して、昇格が発生した後に非マスターノードで呼び出されるスクリプトのパスと名前を指定します。
%pプレースホルダーを含めて、新しいプライマリノードのアドレスを識別します。
# Absolute path to script invoked on non-master agent nodes
# after a promotion.
#
# This optional user-supplied script will be invoked on nodes
# (except the new master) after a promotion occurs. The exit code
# from this script has no effect on Failover Manager, but will be
# included in a notification sent after the script executes.
#
# Pass a parameter (%p) with the script to identify the new
# primary node address.
#
# Example:
# script.remote.post.promotion=/path_name/script_name %p
script.remote.post.promotion=
script.custom.monitor プロパティを使用して、定期的な間隔( custom.monitor.interval プロパティで秒単位で指定)で呼び出されるオプションのスクリプトの名前と場所を指定します。
custom.monitor.timeout を使用して、スクリプトの実行を許可する最大時間を指定します。指定した時間内にスクリプトの実行が完了しない場合、フェールオーバーマネージャーは通知を送信します。
custom.monitor.safe.mode をtrueに設定すると、スクリプトからゼロ以外の終了コードを報告するようにフェールオーバーマネージャーに指示しますが、終了コードの結果としてスタンバイを昇格させません。
# Absolute path to a custom monitoring script.
#
# Use script.custom.monitor to specify the location and name of
# an optional user-supplied script that will be invoked
# periodically to perform custom monitoring tasks. A non-zero
# exit value means that a check has failed; this will be treated
# as a database failure. On a master node, script failure will
# cause a promotion. On a standby node script failure will
# generate a notification and the agent will become IDLE.
#
# The custom.monitor.\* properties are required if a custom
# monitoring script is specified:
#
# custom.monitor.interval is the time in seconds between executions of the script.
#
# custom.monitor.timeout is a timeout value in seconds for how
# long the script will be allowed to run. If script execution
# exceeds the specified time, the task will be stopped and a
# notification sent. Subsequent runs will continue.
#
# If custom.monitor.safe.mode is set to true, non-zero exit codes
# from the script will be reported but will not cause a promotion
# or be treated as a database failure. This allows testing of the
# script without affecting EFM.
#
script.custom.monitor=
custom.monitor.interval=
custom.monitor.timeout=
custom.monitor.safe.mode=
sudo.command プロパティを使用して、拡張アクセス許可が必要なタスクを実行するときにフェールオーバーマネージャーによって呼び出されるコマンドを指定します。このオプションを使用して、システム認証に固有のコマンドオプションを含めます。
sudo.user.command プロパティを使用して、データベース所有者が実行するコマンドを実行するときにフェールオーバーマネージャーによって呼び出されるコマンドを指定します。
# Command to use in place of 'sudo' if desired when efm runs
# the efm_db_functions or efm_root_functions, or efm_address
# scripts.
# Sudo is used in the following ways by efm:
#
# sudo /usr/edb/efm-<version>/bin/efm_address <arguments>
# sudo /usr/edb/efm-<version>/bin/efm_root_functions <arguments>
# sudo -u <db service owner> /usr/edb/efm-<version>/bin/efm_db_functions <arguments>
#
# 'sudo' in the first two examples will be replaced by the value
# of the sudo.command property. 'sudo -u <db service owner>' will
# be replaced by the value of the sudo.user.command property.
# The '%u' field will be replaced with the db owner.
sudo.command=sudo
sudo.user.command=sudo -u %u
lock.dir プロパティを使用して、フェールオーバーマネージャーロックファイルの代替場所を指定します。このファイルにより、フェールオーバーマネージャーがノード上の単一クラスターに対して複数の(孤立している可能性のある)エージェントを起動できなくなります。
# Specify the directory of lock file on the node. Failover
# Manager creates a file named <cluster>.lock at this location to
# avoid starting multiple agents for same cluster. If the path
# does not exist, Failover Manager will attempt to create it. If
# not specified defaults to '/var/lock/efm-<version>'
lock.dir=
log.dir プロパティを使用して、エージェントログファイルが書き込まれる場所を指定します。ディレクトリが存在しない場合、Failover Managerはディレクトリを作成しようとします。
# Specify the directory of agent logs on the node. If the path
# does not exist, Failover Manager will attempt to create it. If
# not specified defaults to '/var/log/efm-<version>'. (To store
# Failover Manager startup logs in a custom location, modify the
# path in the service script to point to an existing, writable
# directory.)
# If using a custom log directory, you must configure
# logrotate separately. Use 'man logrotate' for more information.
log.dir=
Failover ManagerホストでUDPまたはTCPプロトコルを有効にした後、syslogへのロギングを有効にできます。プロトコルタイプ(UDPまたはTCP)を指定するには syslog.protocol パラメーターを使用し、syslogホストのリスナーポートを指定するには syslog.port パラメーターを使用します。 syslog.facility 値は、エントリを作成したプロセスの識別子として使用できます。値はLOCAL0とLOCAL7の間でなければなりません。
# Syslog information. The syslog service must be listening on
# the port for the given protocol, which can be UDP or TCP.
# The facilities supported are LOCAL0 through LOCAL7.
syslog.host=localhost
syslog.port=514
syslog.protocol=UDP
syslog.facility=LOCAL1
file.log.enabled および syslog.enabled プロパティを使用して、実装するロギングのタイプを指定します。 file.log.enabledをtrueに設定して、ファイルへのロギングを有効にします。 UDPプロトコルまたはTCPプロトコルを有効にし、syslog.enabledをtrueに設定して、syslogへのロギングを有効にします。ファイルとsyslogの両方へのロギングを有効にできます。
# Which logging is enabled.
file.log.enabled=true
syslog.enabled=false
syslogロギングの設定の詳細については、 syslogログファイルエントリの有効化を参照してください。 。
jgroups.loglevel および efm.loglevel パラメーターを使用して、Failover Managerによって記録される詳細レベルを指定します。デフォルト値はINFOです。ロギングの詳細については、 ロギングの制御を参照してください 。
# Logging levels for JGroups and EFM.
# Valid values are: TRACE, DEBUG, INFO, WARN, ERROR
# Default value: INFO
# It is not necessary to increase these values unless debugging a
# specific issue. If nodes are not discovering each other at
# startup, increasing the jgroups level to DEBUG will show
# information about the TCP connection attempts that may help
# diagnose the connection failures.
jgroups.loglevel=INFO
efm.loglevel=INFO
JVM関連の設定情報を渡すには、 jvm.options プロパティを使用します。デフォルト設定は、Failover Managerエージェントが使用できるメモリの量を指定します。
# Extra information that will be passed to the JVM when starting
# the agent.
jvm.options=-Xmx128m